Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2hj9-rhvv-rxfx

больше 3 лет назад

modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.

EPSS: Низкий
github логотип

GHSA-2hj9-f386-5hvr

5 месяцев назад

Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2hj8-q57r-32v5

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.30 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-2hj8-3q87-cf35

больше 3 лет назад

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2hj6-wmqq-6j5w

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in WP Royal Bard allows Cross Site Request Forgery.This issue affects Bard: from n/a through 2.210.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hj6-m35h-cfcc

больше 3 лет назад

Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable information disclosure via local access.

EPSS: Низкий
github логотип

GHSA-2hj6-cwhm-rfg9

больше 1 года назад

SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hj6-9wp7-hvmh

больше 2 лет назад

A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hj6-52jv-mj58

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in PBSite allow remote attackers to execute arbitrary PHP code via a URL in the (1) dbpath parameter to (a) useronline.php, (b) ucp.php, (c) setcookie.php, (d) sendpm.php, (e) search.php, (f) register.php, (g) profile.php, (h) post.php, (i) pmpshow.php, (j) pm.php, (k) ntopic.php, (l) nreply.php, (m) news.php, (n) memberslist.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (u) editpost.php, (v) delpost.php, (w) delpm.php, (x) confirm.php, (y) board.php, (z) admin2.php, (aa) admin.php, or (bb) templates/pb/css/formstyles.php; or the (2) temppath parameter to (a) useronline.php, (c) setcookie.php, (e) search.php, (f) register.php, (h) post.php, (l) nreply.php, (m) news.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (w) delpm.php, (x) confirm.php, or (y) board.php.

EPSS: Низкий
github логотип

GHSA-2hj5-g64g-fp6p

9 месяцев назад

Argo CD allows cross-site scripting on repositories page

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-2hj5-4f6v-58m4

12 месяцев назад

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2hj4-qrq6-rw3w

больше 2 лет назад

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-2hj4-ccw5-92h5

больше 2 лет назад

A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP). This vulnerability is due to incorrect processing of SCP commands in AAA command authorization checks. An attacker with valid credentials and level 15 privileges could exploit this vulnerability by using SCP to connect to an affected device from an external machine. A successful exploit could allow the attacker to obtain or change the configuration of the affected device and put files on or retrieve files from the affected device.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2hj3-jfqh-fjvc

5 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Bytes.co WP Compiler allows Cross Site Request Forgery. This issue affects WP Compiler: from n/a through 1.0.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hj2-fcr9-9p35

больше 2 лет назад

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2hj2-cv37-jq8x

больше 3 лет назад

Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hhx-vp2f-m5hf

12 месяцев назад

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hhx-g28r-fqwv

почти 4 года назад

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543.

EPSS: Низкий
github логотип

GHSA-2hhw-p8mg-jrm6

почти 7 лет назад

Path Traversal in http-live-simulator

EPSS: Низкий
github логотип

GHSA-2hhv-wp8q-p8vm

почти 4 года назад

gri before 2.12.18 generates temporary files in an insecure way.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hj9-rhvv-rxfx

modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hj9-f386-5hvr

Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerary information.

CVSS3: 3.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2hj8-q57r-32v5

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.30 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hj8-3q87-cf35

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.

CVSS3: 6.5
21%
Средний
больше 3 лет назад
github логотип
GHSA-2hj6-wmqq-6j5w

Cross-Site Request Forgery (CSRF) vulnerability in WP Royal Bard allows Cross Site Request Forgery.This issue affects Bard: from n/a through 2.210.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2hj6-m35h-cfcc

Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable information disclosure via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hj6-cwhm-rfg9

SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hj6-9wp7-hvmh

A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2hj6-52jv-mj58

Multiple PHP remote file inclusion vulnerabilities in PBSite allow remote attackers to execute arbitrary PHP code via a URL in the (1) dbpath parameter to (a) useronline.php, (b) ucp.php, (c) setcookie.php, (d) sendpm.php, (e) search.php, (f) register.php, (g) profile.php, (h) post.php, (i) pmpshow.php, (j) pm.php, (k) ntopic.php, (l) nreply.php, (m) news.php, (n) memberslist.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (u) editpost.php, (v) delpost.php, (w) delpm.php, (x) confirm.php, (y) board.php, (z) admin2.php, (aa) admin.php, or (bb) templates/pb/css/formstyles.php; or the (2) temppath parameter to (a) useronline.php, (c) setcookie.php, (e) search.php, (f) register.php, (h) post.php, (l) nreply.php, (m) news.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (w) delpm.php, (x) confirm.php, or (y) board.php.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2hj5-g64g-fp6p

Argo CD allows cross-site scripting on repositories page

CVSS3: 9
0%
Низкий
9 месяцев назад
github логотип
GHSA-2hj5-4f6v-58m4

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
1%
Низкий
12 месяцев назад
github логотип
GHSA-2hj4-qrq6-rw3w

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2hj4-ccw5-92h5

A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP). This vulnerability is due to incorrect processing of SCP commands in AAA command authorization checks. An attacker with valid credentials and level 15 privileges could exploit this vulnerability by using SCP to connect to an affected device from an external machine. A successful exploit could allow the attacker to obtain or change the configuration of the affected device and put files on or retrieve files from the affected device.

CVSS3: 8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2hj3-jfqh-fjvc

Cross-Site Request Forgery (CSRF) vulnerability in Bytes.co WP Compiler allows Cross Site Request Forgery. This issue affects WP Compiler: from n/a through 1.0.0.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2hj2-fcr9-9p35

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

CVSS3: 9.8
89%
Высокий
больше 2 лет назад
github логотип
GHSA-2hj2-cv37-jq8x

Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hhx-vp2f-m5hf

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-2hhx-g28r-fqwv

Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hhw-p8mg-jrm6

Path Traversal in http-live-simulator

1%
Низкий
почти 7 лет назад
github логотип
GHSA-2hhv-wp8q-p8vm

gri before 2.12.18 generates temporary files in an insecure way.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу