Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-2mc3-h3h3-g4xq

11 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk allows Path Traversal. This issue affects JS Help Desk: from n/a through 2.9.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mc3-g4mp-f2pj

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 11.0(0.98000.332) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut33659.

EPSS: Низкий
github логотип

GHSA-2mc3-3j9x-hm83

больше 3 лет назад

In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mc2-q5q3-gf79

больше 3 лет назад

Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m9x-v8g8-3x2j

почти 3 года назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2m9w-pj9w-w243

больше 3 лет назад

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m9w-9xh2-wxc3

почти 4 года назад

Link Following in Jenkins Pipeline Multibranch Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2m9w-4gr5-v6pv

почти 2 года назад

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2m9v-rwcf-g57m

24 дня назад

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument TicketID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2m9v-7mx7-mgcw

больше 3 лет назад

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2m9v-3qff-5xxf

почти 2 года назад

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2m9r-pm7q-wr6f

больше 3 лет назад

GeniXCMS denial of service (account blockage)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2m9r-8wqr-rccv

9 месяцев назад

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /sms/admin/?page=receiving/view_receiving&id=1. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2m9r-8mxg-wqgx

больше 3 лет назад

Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2m9q-5w5g-jwfp

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: bpf: Check the helper function is valid in get_helper_proto kernel test robot reported verifier bug [1] where the helper func pointer could be NULL due to disabled config option. As Alexei suggested we could check on that in get_helper_proto directly. Marking tail_call helper func with BPF_PTR_POISON, because it is unused by design. [1] https://lore.kernel.org/oe-lkp/202507160818.68358831-lkp@intel.com

EPSS: Низкий
github логотип

GHSA-2m9p-pg55-8rm3

больше 1 года назад

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary posts and append arbitrary content to existing posts.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2m9p-437w-qjx7

почти 4 года назад

PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

EPSS: Низкий
github логотип

GHSA-2m9m-v6qr-2p82

больше 3 лет назад

A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program.

EPSS: Низкий
github логотип

GHSA-2m9m-fgg6-qcx9

9 месяцев назад

HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2m9j-f7hm-696q

больше 3 лет назад

There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mc3-h3h3-g4xq

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk allows Path Traversal. This issue affects JS Help Desk: from n/a through 2.9.1.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2mc3-g4mp-f2pj

Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 11.0(0.98000.332) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut33659.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mc3-3j9x-hm83

In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mc2-q5q3-gf79

Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m9x-v8g8-3x2j

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-2m9w-pj9w-w243

B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m9w-9xh2-wxc3

Link Following in Jenkins Pipeline Multibranch Plugin

CVSS3: 6.5
2%
Низкий
почти 4 года назад
github логотип
GHSA-2m9w-4gr5-v6pv

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2m9v-rwcf-g57m

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument TicketID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.5
0%
Низкий
24 дня назад
github логотип
GHSA-2m9v-7mx7-mgcw

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

CVSS3: 9.8
24%
Средний
больше 3 лет назад
github логотип
GHSA-2m9v-3qff-5xxf

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.

CVSS3: 7.5
15%
Средний
почти 2 года назад
github логотип
GHSA-2m9r-pm7q-wr6f

GeniXCMS denial of service (account blockage)

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2m9r-8wqr-rccv

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /sms/admin/?page=receiving/view_receiving&id=1. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-2m9r-8mxg-wqgx

Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m9q-5w5g-jwfp

In the Linux kernel, the following vulnerability has been resolved: bpf: Check the helper function is valid in get_helper_proto kernel test robot reported verifier bug [1] where the helper func pointer could be NULL due to disabled config option. As Alexei suggested we could check on that in get_helper_proto directly. Marking tail_call helper func with BPF_PTR_POISON, because it is unused by design. [1] https://lore.kernel.org/oe-lkp/202507160818.68358831-lkp@intel.com

0%
Низкий
4 месяца назад
github логотип
GHSA-2m9p-pg55-8rm3

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary posts and append arbitrary content to existing posts.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2m9p-437w-qjx7

PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

7%
Низкий
почти 4 года назад
github логотип
GHSA-2m9m-v6qr-2p82

A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp directory with a Trojan horse program.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m9m-fgg6-qcx9

HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-2m9j-f7hm-696q

There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу