Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2r2c-rh3g-j33w

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script or HTML via a parameter, as demonstrated by the project_id parameter to search.php.

EPSS: Средний
github логотип

GHSA-2r2c-pw94-m93j

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce allows Reflected XSS. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through 1.7.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2r2c-prqv-cxp3

больше 3 лет назад

The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."

EPSS: Высокий
github логотип

GHSA-2r2c-hm8h-j2c6

больше 3 лет назад

Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the search input field of the search module.

EPSS: Низкий
github логотип

GHSA-2r2c-grqr-jcvc

почти 4 года назад

Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

EPSS: Низкий
github логотип

GHSA-2r2c-g63r-vccr

почти 4 года назад

Improper Verification of Cryptographic Signature in `node-forge`

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2r29-995v-5xhv

больше 3 лет назад

exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.

EPSS: Низкий
github логотип

GHSA-2r26-hfxw-87wc

11 месяцев назад

CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2r26-hc5x-pcmw

около 3 лет назад

IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 244109.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2r25-g38v-g635

3 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ido Kobelkowsky Simple Payment simple-payment.This issue affects Simple Payment: from n/a through <= 2.4.6.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2r25-66c8-224x

4 месяца назад

Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal.  The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2r24-q9c8-57g2

почти 4 года назад

Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.

EPSS: Низкий
github логотип

GHSA-2r24-78wj-92qx

больше 3 лет назад

Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.

EPSS: Средний
github логотип

GHSA-2r24-7795-jp6m

около 1 года назад

Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through 1.9.8.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2r24-5j8r-cf83

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permissions are options There's an inconsistency with the way permissions are handled in tracefs. Because the permissions are generated when accessed, they default to the root inode's permission if they were never set by the user. If the user sets the permissions, then a flag is set and the permissions are saved via the inode (for tracefs files) or an internal attribute field (for eventfs). But if a remount happens that specify the permissions, all the files that were not changed by the user gets updated, but the ones that were are not. If the user were to remount the file system with a given permission, then all files and directories within that file system should be updated. This can cause security issues if a file's permission was updated but the admin forgot about it. They could incorrectly think that remounting with permissions set would update all files, but miss so...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2r22-4xgm-wjg8

почти 4 года назад

Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.

EPSS: Высокий
github логотип

GHSA-2qxx-wjxw-fg87

больше 1 года назад

An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitrary code.  The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is processed by the system. Below are reported vulnerabilities in the Robot Ware versions. * IRC5- RobotWare 6 < 6.15.06 except 6.10.10, and 6.13.07 * OmniCore- RobotWare 7 < 7.14

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2qxx-8p5c-f68v

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments allows Reflected XSS. This issue affects Canonical Attachments: from n/a through 1.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2qxw-7fmx-gqfm

5 дней назад

foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2qxw-2g52-622j

больше 3 лет назад

The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2r2c-rh3g-j33w

Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script or HTML via a parameter, as demonstrated by the project_id parameter to search.php.

16%
Средний
больше 3 лет назад
github логотип
GHSA-2r2c-pw94-m93j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce allows Reflected XSS. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through 1.7.6.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-2r2c-prqv-cxp3

The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."

78%
Высокий
больше 3 лет назад
github логотип
GHSA-2r2c-hm8h-j2c6

Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the search input field of the search module.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r2c-grqr-jcvc

Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2r2c-g63r-vccr

Improper Verification of Cryptographic Signature in `node-forge`

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2r29-995v-5xhv

exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r26-hfxw-87wc

CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.

CVSS3: 9.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2r26-hc5x-pcmw

IBM Robotic Process Automation 20.12.0 through 21.0.2 defaults to HTTP in some RPA commands when the prefix is not explicitly specified in the URL. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 244109.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-2r25-g38v-g635

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ido Kobelkowsky Simple Payment simple-payment.This issue affects Simple Payment: from n/a through <= 2.4.6.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2r25-66c8-224x

Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal.  The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2r24-q9c8-57g2

Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2r24-78wj-92qx

Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.

64%
Средний
больше 3 лет назад
github логотип
GHSA-2r24-7795-jp6m

Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through 1.9.8.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2r24-5j8r-cf83

In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permissions are options There's an inconsistency with the way permissions are handled in tracefs. Because the permissions are generated when accessed, they default to the root inode's permission if they were never set by the user. If the user sets the permissions, then a flag is set and the permissions are saved via the inode (for tracefs files) or an internal attribute field (for eventfs). But if a remount happens that specify the permissions, all the files that were not changed by the user gets updated, but the ones that were are not. If the user were to remount the file system with a given permission, then all files and directories within that file system should be updated. This can cause security issues if a file's permission was updated but the admin forgot about it. They could incorrectly think that remounting with permissions set would update all files, but miss so...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2r22-4xgm-wjg8

Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.

77%
Высокий
почти 4 года назад
github логотип
GHSA-2qxx-wjxw-fg87

An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitrary code.  The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is processed by the system. Below are reported vulnerabilities in the Robot Ware versions. * IRC5- RobotWare 6 < 6.15.06 except 6.10.10, and 6.13.07 * OmniCore- RobotWare 7 < 7.14

CVSS3: 7.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-2qxx-8p5c-f68v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments allows Reflected XSS. This issue affects Canonical Attachments: from n/a through 1.7.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-2qxw-7fmx-gqfm

foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set

CVSS3: 8.1
0%
Низкий
5 дней назад
github логотип
GHSA-2qxw-2g52-622j

The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу