Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2mp4-3r7m-mmg9

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php.

EPSS: Низкий
github логотип

GHSA-2mp3-mchr-79rx

больше 3 лет назад

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mp2-8rhv-p755

больше 3 лет назад

IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280.

EPSS: Низкий
github логотип

GHSA-2mmx-jx99-8cmf

3 месяца назад

HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mmx-5mfh-2536

больше 3 лет назад

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.

EPSS: Низкий
github логотип

GHSA-2mmx-452m-3qmq

больше 3 лет назад

Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mmw-g99r-5x3v

почти 2 года назад

Internet Shortcut Files Security Feature Bypass Vulnerability

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-2mmv-7rrp-g8xh

27 дней назад

Weblate command-line client susceptible to SSL verification skip

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-2mmr-w2qp-r5qp

2 месяца назад

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mmr-5x9x-4m97

больше 3 лет назад

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mmr-2hq6-5c3v

больше 3 лет назад

The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mmq-prpj-ww9q

3 месяца назад

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2mmq-f6mj-fwfx

около 3 лет назад

In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239415861

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mmp-4p76-vmrq

больше 3 лет назад

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663886

EPSS: Низкий
github логотип

GHSA-2mmm-qjp3-8j87

больше 2 лет назад

e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mmj-hgqm-x284

больше 3 лет назад

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.

EPSS: Низкий
github логотип

GHSA-2mmg-vhx9-xmqq

около 4 лет назад

An unspecified version of youtube-php-mirroring is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mmg-r5qc-hhcj

почти 4 года назад

archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.

EPSS: Средний
github логотип

GHSA-2mmf-rqvr-m9qr

около 2 лет назад

Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2mmf-r54m-7994

больше 3 лет назад

mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mp4-3r7m-mmg9

Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2mp3-mchr-79rx

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).

CVSS3: 8.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-2mp2-8rhv-p755

IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2mmx-jx99-8cmf

HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2mmx-5mfh-2536

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mmx-452m-3qmq

Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mmw-g99r-5x3v

Internet Shortcut Files Security Feature Bypass Vulnerability

CVSS3: 8.1
94%
Критический
почти 2 года назад
github логотип
GHSA-2mmv-7rrp-g8xh

Weblate command-line client susceptible to SSL verification skip

CVSS3: 2.5
0%
Низкий
27 дней назад
github логотип
GHSA-2mmr-w2qp-r5qp

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-2mmr-5x9x-4m97

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mmr-2hq6-5c3v

The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mmq-prpj-ww9q

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2mmq-f6mj-fwfx

In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239415861

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2mmp-4p76-vmrq

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663886

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mmm-qjp3-8j87

e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2mmj-hgqm-x284

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mmg-vhx9-xmqq

An unspecified version of youtube-php-mirroring is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-2mmg-r5qc-hhcj

archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.

13%
Средний
почти 4 года назад
github логотип
GHSA-2mmf-rqvr-m9qr

Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability

CVSS3: 8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2mmf-r54m-7994

mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу