Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2m7w-32cj-4pj7

4 месяца назад

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-2m7v-wmjf-9gq6

3 месяца назад

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2m7v-fvqp-gr2c

около 1 года назад

A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2m7v-8fgj-5354

8 месяцев назад

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m7r-x6hh-8373

почти 2 года назад

A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/category/controller.php. The manipulation of the argument CATEGORYID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257377 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2m7r-mqpg-x97r

больше 3 лет назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2m7r-8x5f-v32g

почти 4 года назад

list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.

EPSS: Низкий
github логотип

GHSA-2m7r-8cjp-ww5h

больше 3 лет назад

The iwgif_read_image function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2m7q-gxv6-mxf5

больше 3 лет назад

Remote code execution in Hanwha Techwin Smartcams

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m7p-qcqr-gfv2

больше 3 лет назад

The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.

CVSS3: 6.7
EPSS: Средний
github логотип

GHSA-2m7m-jhx5-8crh

почти 2 года назад

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2m7m-j3mq-9g6p

7 месяцев назад

A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of the component Public API. The manipulation leads to memory corruption. The exploit has been disclosed to the public and may be used.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2m7m-3qp3-4h9x

больше 3 лет назад

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.

EPSS: Низкий
github логотип

GHSA-2m7j-prfm-384p

почти 4 года назад

Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2m7j-4ff8-h52q

больше 1 года назад

Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2m7h-86qq-fp4v

больше 3 лет назад

Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2m7h-5m38-vhh4

5 месяцев назад

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m7g-9q74-9m3q

почти 6 лет назад

Improper Certificate Validation in Apache Beam

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2m7g-9m2h-fmjg

около 3 лет назад

Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2m7g-78xc-qr55

больше 3 лет назад

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2m7w-32cj-4pj7

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as low as Contributor to perform SSRF attack.

CVSS3: 3.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2m7v-wmjf-9gq6

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2m7v-fvqp-gr2c

A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2m7v-8fgj-5354

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2m7r-x6hh-8373

A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/category/controller.php. The manipulation of the argument CATEGORYID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257377 was assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2m7r-mqpg-x97r

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2m7r-8x5f-v32g

list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2m7r-8cjp-ww5h

The iwgif_read_image function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2m7q-gxv6-mxf5

Remote code execution in Hanwha Techwin Smartcams

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2m7p-qcqr-gfv2

The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.

CVSS3: 6.7
65%
Средний
больше 3 лет назад
github логотип
GHSA-2m7m-jhx5-8crh

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2m7m-j3mq-9g6p

A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of the component Public API. The manipulation leads to memory corruption. The exploit has been disclosed to the public and may be used.

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2m7m-3qp3-4h9x

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m7j-prfm-384p

Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.

9%
Низкий
почти 4 года назад
github логотип
GHSA-2m7j-4ff8-h52q

Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2m7h-86qq-fp4v

Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params

CVSS3: 8.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m7h-5m38-vhh4

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-2m7g-9q74-9m3q

Improper Certificate Validation in Apache Beam

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
github логотип
GHSA-2m7g-9m2h-fmjg

Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2m7g-78xc-qr55

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу