Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-2jrp-2x8m-mgrv

больше 3 лет назад

Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input validation may lead to denial of service conditions.

EPSS: Низкий
github логотип

GHSA-2jrp-274c-jhv3

3 дня назад

Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2jrm-p7gj-p98q

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl, (6) Profession, (7) Country, (8) State, (9) Address, (10) Location, (11) Telephone, (12) VoIP, (13) InstantMessagingIM, (14) Email, (15) HomePage, or (16) Comment parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2jrm-m9vw-3rc4

около 23 часов назад

A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This affects an unknown part of the file /restructured/csv.php. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The code repository of the project has not been active for many years.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2jrm-gww7-wch2

больше 3 лет назад

Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2jrm-g2xw-8xvr

5 месяцев назад

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2jrm-5c9c-9px7

около 2 месяцев назад

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerability has been fully addressed in FileMaker Server 22.0.4. The IIS Shortname Vulnerability exploits how Microsoft IIS handles legacy 8.3 short filenames, allowing attackers to infer the existence of files or directories by crafting requests with the tilde (~) character.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jrj-r8hh-8g59

около 3 лет назад

Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to steal user tokens and achieve a full account takeover including access to administrative tools in SAP Commerce.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2jrj-qmg4-g429

почти 4 года назад

Windows File Server Resource Management Service Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-26827.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jrj-64mg-jhw6

около 2 лет назад

An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jrj-24m8-rmrv

больше 1 года назад

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-34373 is likely a duplicate of this issue.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2jrh-pfc7-jq84

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act parameter in (a) help.php and (b) search.php, and the (2) p parameter in report.php.

EPSS: Низкий
github логотип

GHSA-2jrh-h7hv-w2v6

больше 3 лет назад

SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter.

EPSS: Низкий
github логотип

GHSA-2jrh-c5mc-7j55

больше 1 года назад

Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jrh-9rrj-2f59

почти 4 года назад

The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.

EPSS: Низкий
github логотип

GHSA-2jrg-m6qw-2x74

больше 1 года назад

In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2jrf-mm4v-jgmc

больше 1 года назад

A vulnerability was found in Pear Admin Boot up to 2.0.2 and classified as critical. This issue affects the function getDictItems of the file /system/dictData/getDictItems/. The manipulation with the input ,user(),1,1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269375.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2jrc-gh3g-pg7h

больше 3 лет назад

PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2jrc-cvv2-h9r6

почти 4 года назад

Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.

EPSS: Низкий
github логотип

GHSA-2jr9-78pp-8gv9

больше 3 лет назад

HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jrp-2x8m-mgrv

Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input validation may lead to denial of service conditions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jrp-274c-jhv3

Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling

CVSS3: 8.6
0%
Низкий
3 дня назад
github логотип
GHSA-2jrm-p7gj-p98q

Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl, (6) Profession, (7) Country, (8) State, (9) Address, (10) Location, (11) Telephone, (12) VoIP, (13) InstantMessagingIM, (14) Email, (15) HomePage, or (16) Comment parameter. NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jrm-m9vw-3rc4

A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This affects an unknown part of the file /restructured/csv.php. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The code repository of the project has not been active for many years.

CVSS3: 6.3
около 23 часов назад
github логотип
GHSA-2jrm-gww7-wch2

Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2jrm-g2xw-8xvr

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2jrm-5c9c-9px7

To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerability has been fully addressed in FileMaker Server 22.0.4. The IIS Shortname Vulnerability exploits how Microsoft IIS handles legacy 8.3 short filenames, allowing attackers to infer the existence of files or directories by crafting requests with the tilde (~) character.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2jrj-r8hh-8g59

Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to steal user tokens and achieve a full account takeover including access to administrative tools in SAP Commerce.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2jrj-qmg4-g429

Windows File Server Resource Management Service Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-26827.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2jrj-64mg-jhw6

An issue was discovered in Zammad before 6.2.0. An attacker can trigger phishing links in generated notification emails via a crafted first or last name.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2jrj-24m8-rmrv

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-34373 is likely a duplicate of this issue.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jrh-pfc7-jq84

Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act parameter in (a) help.php and (b) search.php, and the (2) p parameter in report.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2jrh-h7hv-w2v6

SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jrh-c5mc-7j55

Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jrh-9rrj-2f59

The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2jrg-m6qw-2x74

In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jrf-mm4v-jgmc

A vulnerability was found in Pear Admin Boot up to 2.0.2 and classified as critical. This issue affects the function getDictItems of the file /system/dictData/getDictItems/. The manipulation with the input ,user(),1,1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269375.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jrc-gh3g-pg7h

PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jrc-cvv2-h9r6

Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2jr9-78pp-8gv9

HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу