Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2gj5-g2gq-97mp

6 месяцев назад

S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending traversal sequences and a null byte to bypass file extension checks.

EPSS: Средний
github логотип

GHSA-2gj5-2jfx-vcmc

почти 4 года назад

BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

EPSS: Низкий
github логотип

GHSA-2gj3-xrpr-w23r

почти 4 года назад

The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.

EPSS: Низкий
github логотип

GHSA-2gj2-vj98-j2qq

около 3 лет назад

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2gj2-5v4g-j7xv

больше 3 лет назад

Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2ghx-mx8m-8w49

7 месяцев назад

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2ghv-58hc-7529

больше 3 лет назад

aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2ghr-522h-prhx

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2ghq-fx5m-357p

11 месяцев назад

Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2ghq-f5hx-5jwp

больше 3 лет назад

resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2ghq-8m9c-mqjm

больше 3 лет назад

STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0.

EPSS: Низкий
github логотип

GHSA-2ghp-ghc5-jw25

7 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2ghp-fh92-8w9r

2 месяца назад

Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2ghm-r75j-pjx2

около 2 лет назад

Cross-site Scripting in DOMSanitizer

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2ghm-cqrg-hhpv

больше 3 лет назад

IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624.

EPSS: Низкий
github логотип

GHSA-2ghj-g7p4-5ff7

больше 3 лет назад

Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering.

EPSS: Низкий
github логотип

GHSA-2ghj-7h29-wmc5

больше 3 лет назад

The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2ghh-xmvf-53hw

около 1 года назад

Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2ghh-4f9c-3725

почти 4 года назад

Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.

EPSS: Низкий
github логотип

GHSA-2ghg-fvx3-9q3q

больше 2 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gj5-g2gq-97mp

S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending traversal sequences and a null byte to bypass file extension checks.

48%
Средний
6 месяцев назад
github логотип
GHSA-2gj5-2jfx-vcmc

BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gj3-xrpr-w23r

The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gj2-vj98-j2qq

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

CVSS3: 4.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-2gj2-5v4g-j7xv

Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2ghx-mx8m-8w49

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2ghv-58hc-7529

aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2ghr-522h-prhx

Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2ghq-fx5m-357p

Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

CVSS3: 9.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2ghq-f5hx-5jwp

resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.

CVSS3: 7.2
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2ghq-8m9c-mqjm

STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2ghp-ghc5-jw25

Rejected reason: Not used

7 месяцев назад
github логотип
GHSA-2ghp-fh92-8w9r

Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2ghm-r75j-pjx2

Cross-site Scripting in DOMSanitizer

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2ghm-cqrg-hhpv

IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2ghj-g7p4-5ff7

Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2ghj-7h29-wmc5

The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2ghh-xmvf-53hw

Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2ghh-4f9c-3725

Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2ghg-fvx3-9q3q

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу