Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2fmx-fw55-g6jg

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2fmx-8p94-cm2g

около 2 лет назад

Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fmw-vp29-wcgf

больше 3 лет назад

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2fmv-j5xj-4fmq

больше 3 лет назад

Moodle Reveals Student Information Meant To Be Anonymous

EPSS: Низкий
github логотип

GHSA-2fmv-g8v2-32hj

больше 3 лет назад

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.

EPSS: Низкий
github логотип

GHSA-2fmv-49qj-83rm

больше 2 лет назад

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fmr-xm36-8jjg

почти 4 года назад

The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

EPSS: Низкий
github логотип

GHSA-2fmr-2c6h-79j9

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through 2.2.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fmq-75qj-9j34

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.

EPSS: Низкий
github логотип

GHSA-2fmp-mw85-gxqw

около 2 лет назад

An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an authenticated local attacker to modify the URL of the registration page in the web GUI of an affected device.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fmp-7xwf-wvwr

больше 5 лет назад

Arbitrary File Read in Snyk Broker

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fmj-pq77-gvj7

больше 2 лет назад

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin through 2.4 use a third-party library that removes the escaping on some HTML characters, leading to a Cross-Site Scripting vulnerability.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-2fmj-fcp4-f992

больше 3 лет назад

Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fmh-chfc-392c

9 месяцев назад

mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fmg-qfp6-p727

больше 3 лет назад

An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.

EPSS: Низкий
github логотип

GHSA-2fmc-hw9p-wg9h

больше 3 лет назад

service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with GBK encoding, aka Qualcomm internal bug CR 978452.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fm9-qxp4-2wgh

почти 3 года назад

A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file users/registration.php of the component POST Parameter Handler. The manipulation of the argument fullname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227228.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2fm9-mpfh-qw5j

почти 4 года назад

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0093.

EPSS: Низкий
github логотип

GHSA-2fm9-m3j5-q4fm

6 месяцев назад

LinkJoin through 882f196 mishandles lacks type checking in password reset.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2fm9-c463-r93v

больше 2 лет назад

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fmx-fw55-g6jg

Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2fmx-8p94-cm2g

Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2fmw-vp29-wcgf

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

CVSS3: 9.8
70%
Высокий
больше 3 лет назад
github логотип
GHSA-2fmv-j5xj-4fmq

Moodle Reveals Student Information Meant To Be Anonymous

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fmv-g8v2-32hj

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fmv-49qj-83rm

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fmr-xm36-8jjg

The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fmr-2c6h-79j9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through 2.2.2.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2fmq-75qj-9j34

Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fmp-mw85-gxqw

An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an authenticated local attacker to modify the URL of the registration page in the web GUI of an affected device.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2fmp-7xwf-wvwr

Arbitrary File Read in Snyk Broker

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-2fmj-pq77-gvj7

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin through 2.4 use a third-party library that removes the escaping on some HTML characters, leading to a Cross-Site Scripting vulnerability.

CVSS3: 6.1
22%
Средний
больше 2 лет назад
github логотип
GHSA-2fmj-fcp4-f992

Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fmh-chfc-392c

mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.

CVSS3: 9.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-2fmg-qfp6-p727

An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fmc-hw9p-wg9h

service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with GBK encoding, aka Qualcomm internal bug CR 978452.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fm9-qxp4-2wgh

A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file users/registration.php of the component POST Parameter Handler. The manipulation of the argument fullname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227228.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-2fm9-mpfh-qw5j

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0093.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2fm9-m3j5-q4fm

LinkJoin through 882f196 mishandles lacks type checking in password reset.

CVSS3: 7.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-2fm9-c463-r93v

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу