Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2qx8-pgxq-5m4m

больше 3 лет назад

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect integrity via vectors related to Security.

EPSS: Низкий
github логотип

GHSA-2qx8-589j-gcpx

больше 7 лет назад

Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qx7-2cpx-52q5

больше 3 лет назад

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar but not identical to CVE-2021-42103.

EPSS: Низкий
github логотип

GHSA-2qx6-g25g-jpv2

больше 3 лет назад

The CBSharedReviewCloseDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.

EPSS: Низкий
github логотип

GHSA-2qx6-48vf-vq3c

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qx6-333j-9r92

почти 4 года назад

Directory traversal vulnerability in NukeFixes 3.1 for PHP-Nuke 7.8 allows remote attackers to include arbitrary files via the file parameter.

EPSS: Низкий
github логотип

GHSA-2qx5-mv7p-q62v

больше 3 лет назад

An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

EPSS: Низкий
github логотип

GHSA-2qx5-c394-4qm8

больше 3 лет назад

An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.

EPSS: Низкий
github логотип

GHSA-2qx5-723m-q6mc

около 3 лет назад

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2qx4-67q8-fwg5

больше 3 лет назад

The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin

EPSS: Низкий
github логотип

GHSA-2qx3-66fq-3wq2

почти 4 года назад

Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) Client-IP HTTP header in a request to the default URI under admin/.

EPSS: Низкий
github логотип

GHSA-2qx2-q2qf-89vq

больше 3 лет назад

The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted program.

EPSS: Низкий
github логотип

GHSA-2qwx-gxrj-p2mw

9 месяцев назад

Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2qwx-g2g4-pw3m

больше 2 лет назад

A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235051.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2qwx-3c7v-ppp5

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) header parameter to (a) conad/include/rootGui.inc.php and (b) include/rootGui.inc.php; (2) mysqlCall parameter to (c) conad/changeEmail.inc.php, (d) conad/changeUserDetails.inc.php, (e) conad/checkPasswd.inc.php, (f) conad/login.inc.php and (g) conad/logout.inc.php; (3) mysqlcall parameter to (h) include/listall.inc.php; (4) prefix parameter to (i) show/index.php; and (5) config parameter to (j) conad/include/mysqlCall.inc.php.

EPSS: Средний
github логотип

GHSA-2qww-mx2p-2v4m

около 1 года назад

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. An attacker with user privileges may be able to read kernel memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2qww-cm69-c4w4

почти 4 года назад

Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qwv-xp73-79cx

почти 3 года назад

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2qwv-78pj-mrp7

больше 1 года назад

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with a legacy form in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2qwv-4qw2-9pcq

около 2 лет назад

A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2qx8-pgxq-5m4m

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect integrity via vectors related to Security.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qx8-589j-gcpx

Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
github логотип
GHSA-2qx7-2cpx-52q5

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar but not identical to CVE-2021-42103.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qx6-g25g-jpv2

The CBSharedReviewCloseDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qx6-48vf-vq3c

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qx6-333j-9r92

Directory traversal vulnerability in NukeFixes 3.1 for PHP-Nuke 7.8 allows remote attackers to include arbitrary files via the file parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2qx5-mv7p-q62v

An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qx5-c394-4qm8

An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qx5-723m-q6mc

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2qx4-67q8-fwg5

The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qx3-66fq-3wq2

Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) Client-IP HTTP header in a request to the default URI under admin/.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2qx2-q2qf-89vq

The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted program.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2qwx-gxrj-p2mw

Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.

CVSS3: 7.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-2qwx-g2g4-pw3m

A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235051.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2qwx-3c7v-ppp5

Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) header parameter to (a) conad/include/rootGui.inc.php and (b) include/rootGui.inc.php; (2) mysqlCall parameter to (c) conad/changeEmail.inc.php, (d) conad/changeUserDetails.inc.php, (e) conad/checkPasswd.inc.php, (f) conad/login.inc.php and (g) conad/logout.inc.php; (3) mysqlcall parameter to (h) include/listall.inc.php; (4) prefix parameter to (i) show/index.php; and (5) config parameter to (j) conad/include/mysqlCall.inc.php.

12%
Средний
почти 4 года назад
github логотип
GHSA-2qww-mx2p-2v4m

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. An attacker with user privileges may be able to read kernel memory.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2qww-cm69-c4w4

Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2qwv-xp73-79cx

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-2qwv-78pj-mrp7

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with a legacy form in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qwv-4qw2-9pcq

A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.

CVSS3: 9.8
1%
Низкий
около 2 лет назад

Уязвимостей на страницу