Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 306 694

Количество 306 694

github логотип

GHSA-249m-jph6-jc9x

больше 2 лет назад

In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08037801; Issue ID: ALPS08037801.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-249j-wgjq-35gx

почти 3 года назад

Vsourz Digital Advanced Contact form 7 DB Versions 1.7.2 and 1.9.1 is vulnerable to Cross Site Scripting (XSS).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-249j-v9cr-p779

больше 3 лет назад

Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash) and possibly execute arbitrary code via format string specifiers in an output string.

EPSS: Низкий
github логотип

GHSA-249j-6h9f-vfjw

больше 3 лет назад

In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-249j-645x-c97w

почти 3 года назад

A vulnerability has been found in Red Snapper NView and classified as critical. This vulnerability affects the function mutate of the file src/Session.php. The manipulation of the argument session leads to sql injection. The name of the patch is cbd255f55d476b29e5680f66f48c73ddb3d416a8. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217516.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-249j-5vj9-w35v

больше 3 лет назад

The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.

EPSS: Низкий
github логотип

GHSA-249h-g975-9xj2

больше 3 лет назад

In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-249h-cc9x-grm3

больше 3 лет назад

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-249g-vvxr-xjqh

больше 3 лет назад

Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability

EPSS: Низкий
github логотип

GHSA-249f-3j5h-crgv

больше 1 года назад

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932916; Issue ID: MSV-1550.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-249c-j5p3-pjx6

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> tags, which are filtered by PHP-Nuke.

EPSS: Низкий
github логотип

GHSA-249c-5cfq-cwqh

больше 3 лет назад

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker to impersonate another account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2499-9m7g-hrw5

больше 3 лет назад

A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2499-8qv4-fpf6

больше 3 лет назад

IOCatalogue in IOKitUser in Apple iOS before 7 allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted application.

EPSS: Низкий
github логотип

GHSA-2498-8v9g-2q83

больше 3 лет назад

The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not initialize a certain output data structure, which allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering a QUEUE_BUFFER action, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26338109.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2497-vx3h-24wc

больше 3 лет назад

A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

EPSS: Высокий
github логотип

GHSA-2497-mh3q-frq7

больше 3 лет назад

Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.

EPSS: Низкий
github логотип

GHSA-2497-m587-h6c8

больше 1 года назад

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2495-6v7r-rmx4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter.

EPSS: Низкий
github логотип

GHSA-2494-q7mq-75f7

больше 3 лет назад

PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-249m-jph6-jc9x

In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08037801; Issue ID: ALPS08037801.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-249j-wgjq-35gx

Vsourz Digital Advanced Contact form 7 DB Versions 1.7.2 and 1.9.1 is vulnerable to Cross Site Scripting (XSS).

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-249j-v9cr-p779

Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash) and possibly execute arbitrary code via format string specifiers in an output string.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-249j-6h9f-vfjw

In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-249j-645x-c97w

A vulnerability has been found in Red Snapper NView and classified as critical. This vulnerability affects the function mutate of the file src/Session.php. The manipulation of the argument session leads to sql injection. The name of the patch is cbd255f55d476b29e5680f66f48c73ddb3d416a8. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217516.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-249j-5vj9-w35v

The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-249h-g975-9xj2

In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-249h-cc9x-grm3

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-249g-vvxr-xjqh

Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability

0%
Низкий
больше 3 лет назад
github логотип
GHSA-249f-3j5h-crgv

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932916; Issue ID: MSV-1550.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-249c-j5p3-pjx6

Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> tags, which are filtered by PHP-Nuke.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-249c-5cfq-cwqh

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker to impersonate another account.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2499-9m7g-hrw5

A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2499-8qv4-fpf6

IOCatalogue in IOKitUser in Apple iOS before 7 allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted application.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2498-8v9g-2q83

The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not initialize a certain output data structure, which allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering a QUEUE_BUFFER action, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26338109.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2497-vx3h-24wc

A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.

83%
Высокий
больше 3 лет назад
github логотип
GHSA-2497-mh3q-frq7

Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2497-m587-h6c8

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2495-6v7r-rmx4

Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2494-q7mq-75f7

PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу