Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-297g-cjpm-qw2x

10 месяцев назад

Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-297g-9xq6-v8vj

больше 3 лет назад

Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-297g-9658-43jh

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.

EPSS: Низкий
github логотип

GHSA-297g-672r-7mgh

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-297g-44c7-436q

почти 4 года назад

Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.

EPSS: Низкий
github логотип

GHSA-297f-r9w7-w492

больше 3 лет назад

Magento Improper input validation vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-297f-24c2-wwfv

3 месяца назад

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-297c-p9xm-3rhf

10 месяцев назад

A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-297c-8rmr-xrxf

почти 4 года назад

Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.

EPSS: Низкий
github логотип

GHSA-297c-34f3-r565

почти 4 года назад

feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php.

EPSS: Низкий
github логотип

GHSA-2979-3fv7-8r3w

около 1 месяца назад

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2978-89p5-cxgh

больше 3 лет назад

An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2978-6549-pf4r

почти 4 года назад

SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.

EPSS: Низкий
github логотип

GHSA-2977-w3fj-rc33

почти 2 года назад

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2977-ph22-g7f6

больше 3 лет назад

The Slingshot Forum (aka com.tapatalk.theslingshotforumcom) application 3.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2977-c3c9-wqxf

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2977-6mrh-4c63

около 1 года назад

MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2977-5php-6789

8 месяцев назад

Erxes Path Traversal vulnerability

EPSS: Низкий
github логотип

GHSA-2976-mg74-v97h

больше 2 лет назад

Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2976-6mfc-xmp6

больше 3 лет назад

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-297g-cjpm-qw2x

Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.

CVSS3: 5.3
2%
Низкий
10 месяцев назад
github логотип
GHSA-297g-9xq6-v8vj

Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student assessment submission, file upload, news, ePortfolio and calendar event creation were found to be vulnerable to cross-site scripting.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-297g-9658-43jh

Multiple cross-site scripting (XSS) vulnerabilities in filter search forms in admin web pages on Cisco Web Security Appliance (WSA) devices with software 8.5.0-497 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut39213.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-297g-672r-7mgh

Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-297g-44c7-436q

Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.

4%
Низкий
почти 4 года назад
github логотип
GHSA-297f-r9w7-w492

Magento Improper input validation vulnerability

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-297f-24c2-wwfv

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-297c-p9xm-3rhf

A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-297c-8rmr-xrxf

Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privileges via malicious programs.

0%
Низкий
почти 4 года назад
github логотип
GHSA-297c-34f3-r565

feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2979-3fv7-8r3w

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2978-89p5-cxgh

An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2978-6549-pf4r

SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2977-w3fj-rc33

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2977-ph22-g7f6

The Slingshot Forum (aka com.tapatalk.theslingshotforumcom) application 3.9.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2977-c3c9-wqxf

Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2977-6mrh-4c63

MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2977-5php-6789

Erxes Path Traversal vulnerability

0%
Низкий
8 месяцев назад
github логотип
GHSA-2976-mg74-v97h

Vulnerability of mutual exclusion management in the kernel module.Successful exploitation of this vulnerability will affect availability.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2976-6mfc-xmp6

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу