Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-27w7-4rrm-p796

больше 3 лет назад

An issue was discovered in libthulac.so in THULAC through 2018-02-25. "operator delete" is used with "operator new[]" in the TaggingLearner class in include/cb_tagging_learner.h, possibly leading to memory corruption.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27w7-2jg3-x45x

9 месяцев назад

A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an unknown function of the file /admin/admin_addnew_product.php. The manipulation of the argument txtProdId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-27w6-8m77-x3qf

почти 2 года назад

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-27w5-gj5q-82fv

4 месяца назад

@nubosoftware/node-static failure to catch exception can result in server crash

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27w5-9p4f-w4h8

больше 3 лет назад

A memory corruption vulnerability exists in the .PSD parsing functionality of ACDSee Ultimate 10.0.0.292. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in potential code execution. An attacker can send a specific .PSD file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27w3-xhwh-5xw4

почти 4 года назад

Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string.

EPSS: Низкий
github логотип

GHSA-27w2-xhhr-rp5p

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.

EPSS: Низкий
github логотип

GHSA-27w2-gfcm-69mr

больше 2 лет назад

A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-229598 is the identifier assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-27vx-r33r-rh7x

больше 3 лет назад

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27vr-8fpq-79vm

больше 3 лет назад

A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27vr-69mf-gx49

почти 4 года назад

Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.

EPSS: Низкий
github логотип

GHSA-27vr-5h5p-w59c

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.5.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27vr-24cc-98h4

почти 2 года назад

Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-27vq-rfj8-6mx2

2 месяца назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-27vq-mhjm-v9gc

почти 4 года назад

Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27vq-hv74-7cqp

около 1 года назад

SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type

EPSS: Низкий
github логотип

GHSA-27vq-c7q6-wxpx

около 4 лет назад

NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

EPSS: Низкий
github логотип

GHSA-27vp-6288-jjwg

больше 1 года назад

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27vm-9gw5-232w

больше 3 лет назад

Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27vh-hwmj-r5gc

больше 3 лет назад

Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Tasks.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27w7-4rrm-p796

An issue was discovered in libthulac.so in THULAC through 2018-02-25. "operator delete" is used with "operator new[]" in the TaggingLearner class in include/cb_tagging_learner.h, possibly leading to memory corruption.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27w7-2jg3-x45x

A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an unknown function of the file /admin/admin_addnew_product.php. The manipulation of the argument txtProdId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-27w6-8m77-x3qf

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.

CVSS3: 3.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-27w5-gj5q-82fv

@nubosoftware/node-static failure to catch exception can result in server crash

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-27w5-9p4f-w4h8

A memory corruption vulnerability exists in the .PSD parsing functionality of ACDSee Ultimate 10.0.0.292. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in potential code execution. An attacker can send a specific .PSD file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27w3-xhwh-5xw4

Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string.

0%
Низкий
почти 4 года назад
github логотип
GHSA-27w2-xhhr-rp5p

Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27w2-gfcm-69mr

A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-229598 is the identifier assigned to this vulnerability.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27vx-r33r-rh7x

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27vr-8fpq-79vm

A permissions issue existed. This issue was addressed with improved permission validation. This issue affected versions prior to iOS 12.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27vr-69mf-gx49

Cross-site scripting (XSS) vulnerability in lostpwd.php in Creative Digital Resources SocketMail 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the lost_id parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-27vr-5h5p-w59c

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.5.1.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-27vr-24cc-98h4

Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.

CVSS3: 6.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-27vq-rfj8-6mx2

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
2 месяца назад
github логотип
GHSA-27vq-mhjm-v9gc

Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-27vq-hv74-7cqp

SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type

около 1 года назад
github логотип
GHSA-27vq-c7q6-wxpx

NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

0%
Низкий
около 4 лет назад
github логотип
GHSA-27vp-6288-jjwg

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

CVSS3: 7.5
2%
Низкий
больше 1 года назад
github логотип
GHSA-27vm-9gw5-232w

Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27vh-hwmj-r5gc

Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Tasks.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу