Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 325

Количество 313 325

github логотип

GHSA-29x2-pp5x-vjgj

больше 3 лет назад

IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-29x2-p4f6-vfcw

больше 3 лет назад

IBM Rational Asset Manager 7.5 could allow a remote attacker to bypass security restrictions. An attacker could exploit this vulnerability using the UID parameter to modify another user's preferences.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29x2-2gr6-gm32

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.

EPSS: Низкий
github логотип

GHSA-29wx-wghr-g778

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-29wx-vh33-7x7r

больше 1 года назад

Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-29ww-rpf8-h5rj

больше 3 лет назад

The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-29ww-cjvv-3x39

почти 3 года назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29ww-8733-7wfv

больше 3 лет назад

Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-29ww-292v-6c4r

больше 2 лет назад

Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_query' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29wv-m5qw-5h7j

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: bpf: Don't redirect packets with invalid pkt_len Syzbot found an issue [1]: fq_codel_drop() try to drop a flow whitout any skbs, that is, the flow->head is null. The root cause, as the [2] says, is because that bpf_prog_test_run_skb() run a bpf prog which redirects empty skbs. So we should determine whether the length of the packet modified by bpf prog or others like bpf_prog_test is valid before forwarding it directly.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29wr-x5mf-wc9f

больше 2 лет назад

CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-29wr-24h5-95r5

почти 4 года назад

Typo3 XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-29wq-mjx6-hr78

около 1 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shuttlethemes Shuttle allows Stored XSS.This issue affects Shuttle: from n/a through 1.5.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29wp-xqwp-4vqr

почти 2 года назад

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29wp-q2r7-4jqv

больше 3 лет назад

JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29wp-p54c-r4v7

около 1 года назад

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29wm-wgxj-3pqf

почти 4 года назад

Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.

EPSS: Низкий
github логотип

GHSA-29wj-4xr4-3424

7 месяцев назад

A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-29wh-g4c8-c35q

около 2 месяцев назад

A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29wh-8w97-366v

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: fscache: Fix oops due to race with cookie_lru and use_cookie If a cookie expires from the LRU and the LRU_DISCARD flag is set, but the state machine has not run yet, it's possible another thread can call fscache_use_cookie and begin to use it. When the cookie_worker finally runs, it will see the LRU_DISCARD flag set, transition the cookie->state to LRU_DISCARDING, which will then withdraw the cookie. Once the cookie is withdrawn the object is removed the below oops will occur because the object associated with the cookie is now NULL. Fix the oops by clearing the LRU_DISCARD bit if another thread uses the cookie before the cookie_worker runs. BUG: kernel NULL pointer dereference, address: 0000000000000008 ... CPU: 31 PID: 44773 Comm: kworker/u130:1 Tainted: G E 6.0.0-5.dneg.x86_64 #1 Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 08/26/2022 Workqueue: events_unbound net...

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29x2-pp5x-vjgj

IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29x2-p4f6-vfcw

IBM Rational Asset Manager 7.5 could allow a remote attacker to bypass security restrictions. An attacker could exploit this vulnerability using the UID parameter to modify another user's preferences.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29x2-2gr6-gm32

Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29wx-wghr-g778

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29wx-vh33-7x7r

Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-29ww-rpf8-h5rj

The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-29ww-cjvv-3x39

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-29ww-8733-7wfv

Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29ww-292v-6c4r

Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_query' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
больше 2 лет назад
github логотип
GHSA-29wv-m5qw-5h7j

In the Linux kernel, the following vulnerability has been resolved: bpf: Don't redirect packets with invalid pkt_len Syzbot found an issue [1]: fq_codel_drop() try to drop a flow whitout any skbs, that is, the flow->head is null. The root cause, as the [2] says, is because that bpf_prog_test_run_skb() run a bpf prog which redirects empty skbs. So we should determine whether the length of the packet modified by bpf prog or others like bpf_prog_test is valid before forwarding it directly.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-29wr-x5mf-wc9f

CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29wr-24h5-95r5

Typo3 XSS Vulnerability

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-29wq-mjx6-hr78

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shuttlethemes Shuttle allows Stored XSS.This issue affects Shuttle: from n/a through 1.5.0.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-29wp-xqwp-4vqr

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-29wp-q2r7-4jqv

JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-29wp-p54c-r4v7

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-29wm-wgxj-3pqf

Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.

10%
Низкий
почти 4 года назад
github логотип
GHSA-29wj-4xr4-3424

A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-29wh-g4c8-c35q

A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-29wh-8w97-366v

In the Linux kernel, the following vulnerability has been resolved: fscache: Fix oops due to race with cookie_lru and use_cookie If a cookie expires from the LRU and the LRU_DISCARD flag is set, but the state machine has not run yet, it's possible another thread can call fscache_use_cookie and begin to use it. When the cookie_worker finally runs, it will see the LRU_DISCARD flag set, transition the cookie->state to LRU_DISCARDING, which will then withdraw the cookie. Once the cookie is withdrawn the object is removed the below oops will occur because the object associated with the cookie is now NULL. Fix the oops by clearing the LRU_DISCARD bit if another thread uses the cookie before the cookie_worker runs. BUG: kernel NULL pointer dereference, address: 0000000000000008 ... CPU: 31 PID: 44773 Comm: kworker/u130:1 Tainted: G E 6.0.0-5.dneg.x86_64 #1 Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 08/26/2022 Workqueue: events_unbound net...

CVSS3: 4.7
0%
Низкий
больше 1 года назад

Уязвимостей на страницу