Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2jm6-v38h-g4f5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.4 allows remote attackers to inject arbitrary web script or HTML via a JavaScript onload event in the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: this issue exists because of an incomplete fix for CVE-2008-1168.

EPSS: Низкий
github логотип

GHSA-2jm5-p544-m6xw

больше 3 лет назад

Multiple heap-based buffer overflows in vp6.w5s (aka the VP6 codec) in Winamp before 5.59 Beta build 3033 might allow remote attackers to execute arbitrary code via a crafted VP6 (1) video file or (2) video stream.

EPSS: Низкий
github логотип

GHSA-2jm5-gphf-c739

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in FrescoChat Live Chat allows Stored XSS. This issue affects FrescoChat Live Chat: from n/a through 3.2.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2jm5-2cqf-6vw9

больше 5 лет назад

Malicious Package in baes-x

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2jm4-pp6h-mpwx

около 2 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes EcoGrow ecogrow allows PHP Local File Inclusion.This issue affects EcoGrow: from n/a through <= 1.7.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2jm4-m62p-325r

больше 1 года назад

A privilege escalation vulnerability exists in the Veertu Anka Build 1.42.0. The vulnerability occurs during Anka node agent update. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jm4-cm7h-hghg

почти 4 года назад

Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".

EPSS: Низкий
github логотип

GHSA-2jm4-4x2h-4g5p

6 месяцев назад

Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2jm3-4crv-w9ff

11 месяцев назад

The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS). An authenticated user can access the slides within a project and injecting malicious JavaScript into the "memo" field. The memo field has a hover over action that will display a Microsoft Tool Tip which a user can use to quickly view the memo associated with the slide and execute the JavaScript.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2jm2-q946-gq54

почти 3 года назад

An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jm2-2p35-rp3j

3 месяца назад

OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jjw-vxxv-7gqg

больше 1 года назад

The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2jjv-qf24-vfm4

5 месяцев назад

Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions

EPSS: Низкий
github логотип

GHSA-2jjq-x889-r334

больше 3 лет назад

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.

EPSS: Низкий
github логотип

GHSA-2jjq-x548-rhpv

больше 3 лет назад

isolated-vm has vulnerable CachedDataOptions in API

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2jjq-jgq8-2h5h

больше 3 лет назад

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions). The vulnerability could allow an unauthenticated attacker to reboot the device over the network by using special urls from integrated web server of the affected products.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2jjq-jfw3-m48c

почти 2 года назад

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jjp-v4x9-55gm

почти 4 года назад

Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a "ReDoS" vulnerability.

EPSS: Низкий
github логотип

GHSA-2jjp-c35x-v2v9

больше 2 лет назад

Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2jjp-9wg8-3jxx

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jm6-v38h-g4f5

Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.4 allows remote attackers to inject arbitrary web script or HTML via a JavaScript onload event in the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: this issue exists because of an incomplete fix for CVE-2008-1168.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jm5-p544-m6xw

Multiple heap-based buffer overflows in vp6.w5s (aka the VP6 codec) in Winamp before 5.59 Beta build 3033 might allow remote attackers to execute arbitrary code via a crafted VP6 (1) video file or (2) video stream.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2jm5-gphf-c739

Cross-Site Request Forgery (CSRF) vulnerability in FrescoChat Live Chat allows Stored XSS. This issue affects FrescoChat Live Chat: from n/a through 3.2.6.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-2jm5-2cqf-6vw9

Malicious Package in baes-x

CVSS3: 9.1
больше 5 лет назад
github логотип
GHSA-2jm4-pp6h-mpwx

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes EcoGrow ecogrow allows PHP Local File Inclusion.This issue affects EcoGrow: from n/a through <= 1.7.

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2jm4-m62p-325r

A privilege escalation vulnerability exists in the Veertu Anka Build 1.42.0. The vulnerability occurs during Anka node agent update. A low privilege user can trigger the update action which can result in unexpected elevation of privilege.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jm4-cm7h-hghg

Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".

0%
Низкий
почти 4 года назад
github логотип
GHSA-2jm4-4x2h-4g5p

Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-2jm3-4crv-w9ff

The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS). An authenticated user can access the slides within a project and injecting malicious JavaScript into the "memo" field. The memo field has a hover over action that will display a Microsoft Tool Tip which a user can use to quickly view the memo associated with the slide and execute the JavaScript.

CVSS3: 4.6
0%
Низкий
11 месяцев назад
github логотип
GHSA-2jm2-q946-gq54

An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2jm2-2p35-rp3j

OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2jjw-vxxv-7gqg

The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jjv-qf24-vfm4

Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions

0%
Низкий
5 месяцев назад
github логотип
GHSA-2jjq-x889-r334

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jjq-x548-rhpv

isolated-vm has vulnerable CachedDataOptions in API

CVSS3: 9.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jjq-jgq8-2h5h

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions). The vulnerability could allow an unauthenticated attacker to reboot the device over the network by using special urls from integrated web server of the affected products.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jjq-jfw3-m48c

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2jjp-v4x9-55gm

Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a "ReDoS" vulnerability.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2jjp-c35x-v2v9

Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jjp-9wg8-3jxx

Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу