Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-27wp-x9q2-grf8

больше 3 лет назад

SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-27wp-jvhw-v4xp

больше 1 года назад

Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-27wp-chg4-ffw3

12 месяцев назад

An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-27wp-7452-56g5

7 дней назад

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.7.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-27wm-p6hh-jm27

почти 3 года назад

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27wj-qvh3-g73h

3 месяца назад

Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27wj-6vjv-96mm

больше 3 лет назад

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27wh-h3mm-7hf3

почти 4 года назад

FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.

EPSS: Низкий
github логотип

GHSA-27wg-r456-jc87

около 2 лет назад

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-27wg-m2hx-ww9m

больше 3 лет назад

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27wg-jv26-vh4g

больше 3 лет назад

login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.

EPSS: Низкий
github логотип

GHSA-27wg-99g8-2v4v

около 2 лет назад

Rust EVM erroneousle handles `record_external_operation` error return

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-27wg-3m5v-r5fh

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27wf-jhgm-qm73

10 месяцев назад

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-27wf-832r-r7vc

больше 3 лет назад

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: SmmSmbiosElog SHA256: 3a8acb4f9bddccb19ec3b22b22ad97963711550f76b27b606461cd5073a93b59 Module GUID: 8e61fd6b-7a8b-404f-b83f-aa90a47cabdf This issue affects: AMI Aptio 5.x. This issue affects: AMI Aptio 5.x.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27wf-5967-98gx

около 1 года назад

Kubernetes kubelet arbitrary command execution

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-27wf-58x2-9c98

больше 3 лет назад

In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-27wf-3ww8-gq93

больше 3 лет назад

The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27wc-fr9j-8x58

больше 3 лет назад

A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent remote access to all the contents of the web application, including key configuration files. Affected releases are TIBCO JasperReports Server 6.4.0, TIBCO JasperReports Server Community Edition 6.4.0, TIBCO JasperReports Server for ActiveMatrix BPM 6.4.0, TIBCO Jaspersoft for AWS with Multi-Tenancy 6.4.0, TIBCO Jaspersoft Reporting and Analytics for AWS 6.4.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27w9-h9rx-p7c5

10 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shiptrack Booking Calendar and Notification allows Blind SQL Injection.This issue affects Booking Calendar and Notification: from n/a through 4.0.3.

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27wp-x9q2-grf8

SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27wp-jvhw-v4xp

Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

CVSS3: 8.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-27wp-chg4-ffw3

An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.

CVSS3: 8.2
0%
Низкий
12 месяцев назад
github логотип
GHSA-27wp-7452-56g5

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.7.3.

CVSS3: 4.3
0%
Низкий
7 дней назад
github логотип
GHSA-27wm-p6hh-jm27

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-27wj-qvh3-g73h

Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-27wj-6vjv-96mm

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27wh-h3mm-7hf3

FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-27wg-r456-jc87

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability.

CVSS3: 5.3
28%
Средний
около 2 лет назад
github логотип
GHSA-27wg-m2hx-ww9m

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27wg-jv26-vh4g

login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-27wg-99g8-2v4v

Rust EVM erroneousle handles `record_external_operation` error return

CVSS3: 5.9
1%
Низкий
около 2 лет назад
github логотип
GHSA-27wg-3m5v-r5fh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-27wf-jhgm-qm73

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-27wf-832r-r7vc

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: SmmSmbiosElog SHA256: 3a8acb4f9bddccb19ec3b22b22ad97963711550f76b27b606461cd5073a93b59 Module GUID: 8e61fd6b-7a8b-404f-b83f-aa90a47cabdf This issue affects: AMI Aptio 5.x. This issue affects: AMI Aptio 5.x.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27wf-5967-98gx

Kubernetes kubelet arbitrary command execution

CVSS3: 8.1
27%
Средний
около 1 года назад
github логотип
GHSA-27wf-58x2-9c98

In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.

CVSS3: 6.5
33%
Средний
больше 3 лет назад
github логотип
GHSA-27wf-3ww8-gq93

The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27wc-fr9j-8x58

A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent remote access to all the contents of the web application, including key configuration files. Affected releases are TIBCO JasperReports Server 6.4.0, TIBCO JasperReports Server Community Edition 6.4.0, TIBCO JasperReports Server for ActiveMatrix BPM 6.4.0, TIBCO Jaspersoft for AWS with Multi-Tenancy 6.4.0, TIBCO Jaspersoft Reporting and Analytics for AWS 6.4.0.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27w9-h9rx-p7c5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shiptrack Booking Calendar and Notification allows Blind SQL Injection.This issue affects Booking Calendar and Notification: from n/a through 4.0.3.

CVSS3: 9.3
0%
Низкий
10 месяцев назад

Уязвимостей на страницу