Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2v2m-jqm3-cq3x

около 4 лет назад

An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the server filesystems.

EPSS: Низкий
github логотип

GHSA-2v2m-h8mc-wjvq

около 1 года назад

Incorrect Privilege Assignment vulnerability in SSL Wireless SSL Wireless SMS Notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through 3.5.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2v2m-fh3w-x32m

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.

EPSS: Низкий
github логотип

GHSA-2v2m-7p9m-5v4v

больше 3 лет назад

Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2v2m-677r-5j24

больше 3 лет назад

There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may execute some specially crafted scripts in the affected products. Successful exploit will cause privilege escalation.

EPSS: Низкий
github логотип

GHSA-2v2m-4w84-733f

4 месяца назад

Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 2.8
EPSS: Низкий
github логотип

GHSA-2v2h-qr9f-cf9h

около 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-2v2h-p3pv-rrr5

около 4 лет назад

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The "Who are you" and "Website Name" fields are vulnerable.

EPSS: Низкий
github логотип

GHSA-2v2g-rr8c-cpwh

больше 3 лет назад

NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.

EPSS: Низкий
github логотип

GHSA-2v2g-7jx3-jq4g

почти 4 года назад

Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer methods.

EPSS: Средний
github логотип

GHSA-2v2f-rp8w-vrxh

больше 3 лет назад

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-2v2c-wv9c-g6cm

больше 1 года назад

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2v2c-pqx4-qvqc

больше 2 лет назад

TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2v28-q9qp-f3gx

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v28-fx5v-7xvj

больше 3 лет назад

Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2v26-h6g3-vrgj

больше 1 года назад

Information disclosure while sending implicit broadcast containing APP launch information.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2v26-7fm5-rmj8

около 1 года назад

Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2v26-28rg-whvc

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field If driver read val value sufficient for (val & 0x08) && (!(val & 0x80)) && ((val & 0x7) == ((val >> 4) & 0x7)) from device then Null pointer dereference occurs. (It is possible if tmp = 0b0xyz1xyz, where same literals mean same numbers) Also lm75[] does not serve a purpose anymore after switching to devm_i2c_new_dummy_device() in w83791d_detect_subclients(). The patch fixes possible NULL pointer dereference by removing lm75[]. Found by Linux Driver Verification project (linuxtesting.org). [groeck: Dropped unnecessary continuation lines, fixed multipline alignment]

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2v24-xp2p-2gfc

почти 4 года назад

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v24-jcvm-2w9j

больше 3 лет назад

In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139666480

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2v2m-jqm3-cq3x

An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the server filesystems.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2v2m-h8mc-wjvq

Incorrect Privilege Assignment vulnerability in SSL Wireless SSL Wireless SMS Notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through 3.5.0.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2v2m-fh3w-x32m

Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v2m-7p9m-5v4v

Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v2m-677r-5j24

There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may execute some specially crafted scripts in the affected products. Successful exploit will cause privilege escalation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v2m-4w84-733f

Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 2.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2v2h-qr9f-cf9h

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

около 2 лет назад
github логотип
GHSA-2v2h-p3pv-rrr5

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The "Who are you" and "Website Name" fields are vulnerable.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2v2g-rr8c-cpwh

NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v2g-7jx3-jq4g

Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer methods.

39%
Средний
почти 4 года назад
github логотип
GHSA-2v2f-rp8w-vrxh

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

CVSS3: 7.5
92%
Критический
больше 3 лет назад
github логотип
GHSA-2v2c-wv9c-g6cm

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v2c-pqx4-qvqc

TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2v28-q9qp-f3gx

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.4.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v28-fx5v-7xvj

Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v26-h6g3-vrgj

Information disclosure while sending implicit broadcast containing APP launch information.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v26-7fm5-rmj8

Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2v26-28rg-whvc

In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field If driver read val value sufficient for (val & 0x08) && (!(val & 0x80)) && ((val & 0x7) == ((val >> 4) & 0x7)) from device then Null pointer dereference occurs. (It is possible if tmp = 0b0xyz1xyz, where same literals mean same numbers) Also lm75[] does not serve a purpose anymore after switching to devm_i2c_new_dummy_device() in w83791d_detect_subclients(). The patch fixes possible NULL pointer dereference by removing lm75[]. Found by Linux Driver Verification project (linuxtesting.org). [groeck: Dropped unnecessary continuation lines, fixed multipline alignment]

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v24-xp2p-2gfc

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2v24-jcvm-2w9j

In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139666480

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу