Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2j7w-p7qj-9hg9

больше 2 лет назад

ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j7r-vr72-m9vf

больше 3 лет назад

An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2j7r-32wv-4cfj

больше 2 лет назад

The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2j7q-245v-xcrj

около 3 лет назад

Microsoft ODBC Driver Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41047.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2j7m-x4gh-v3m8

больше 3 лет назад

Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to upload arbitrary files.

EPSS: Низкий
github логотип

GHSA-2j7j-mg3j-2mr8

почти 4 года назад

sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file.

EPSS: Низкий
github логотип

GHSA-2j7j-jvr9-h35r

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2j7j-55ff-pvmw

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the layout sheet attribute. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5374.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j7h-v8wc-gmgr

11 месяцев назад

In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j7h-rpqp-4v2f

больше 1 года назад

A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation efforts, the application fails to properly sanitize or validate the output from the model, allowing for the injection and execution of malicious JavaScript code within the context of a user's browser. This vulnerability can lead to the execution of arbitrary JavaScript code in the context of other users' browsers, potentially resulting in the hijacking of victims' browsers.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2j7h-923g-m6xf

больше 2 лет назад

The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefox < 115.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2j7h-8wqx-75mg

больше 3 лет назад

Unspecified vulnerability in the Oracle iSupplier Portal component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Supplier Management.

EPSS: Низкий
github логотип

GHSA-2j7g-j9qp-627h

больше 3 лет назад

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, and CVE-2014-0545.

EPSS: Низкий
github логотип

GHSA-2j7g-cpcm-93qx

около 2 лет назад

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2j7g-5vhg-rj47

почти 4 года назад

Unspecified vulnerability in JoomlaLib (com_joomlalib) before 1.2.2 for Joomla! allows remote attackers to have an unknown impact, related to "Joomla globals hacked by script kiddies."

EPSS: Низкий
github логотип

GHSA-2j7f-m85p-rvqj

почти 4 года назад

The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password.

EPSS: Низкий
github логотип

GHSA-2j7c-c562-m564

почти 4 года назад

Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.

EPSS: Низкий
github логотип

GHSA-2j79-8rwp-pjrp

почти 4 года назад

Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with a long href element.

EPSS: Низкий
github логотип

GHSA-2j79-8pqc-r7x6

больше 3 лет назад

react-native-reanimated vulnerable to ReDoS

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j79-5jhx-wg65

больше 3 лет назад

The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j7w-p7qj-9hg9

ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2j7r-vr72-m9vf

An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j7r-32wv-4cfj

The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2j7q-245v-xcrj

Microsoft ODBC Driver Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41047.

CVSS3: 8.8
14%
Средний
около 3 лет назад
github логотип
GHSA-2j7m-x4gh-v3m8

Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to upload arbitrary files.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-2j7j-mg3j-2mr8

sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2j7j-jvr9-h35r

Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j7j-55ff-pvmw

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the layout sheet attribute. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5374.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j7h-v8wc-gmgr

In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-2j7h-rpqp-4v2f

A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation efforts, the application fails to properly sanitize or validate the output from the model, allowing for the injection and execution of malicious JavaScript code within the context of a user's browser. This vulnerability can lead to the execution of arbitrary JavaScript code in the context of other users' browsers, potentially resulting in the hijacking of victims' browsers.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2j7h-923g-m6xf

The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefox < 115.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2j7h-8wqx-75mg

Unspecified vulnerability in the Oracle iSupplier Portal component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Supplier Management.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j7g-j9qp-627h

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Compiler before 14.0.0.178 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2014-0542, CVE-2014-0543, CVE-2014-0544, and CVE-2014-0545.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j7g-cpcm-93qx

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2j7g-5vhg-rj47

Unspecified vulnerability in JoomlaLib (com_joomlalib) before 1.2.2 for Joomla! allows remote attackers to have an unknown impact, related to "Joomla globals hacked by script kiddies."

0%
Низкий
почти 4 года назад
github логотип
GHSA-2j7f-m85p-rvqj

The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2j7c-c562-m564

Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2j79-8rwp-pjrp

Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with a long href element.

7%
Низкий
почти 4 года назад
github логотип
GHSA-2j79-8pqc-r7x6

react-native-reanimated vulnerable to ReDoS

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j79-5jhx-wg65

The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу