Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-27mc-9399-r9mx

3 месяца назад

Drupal Access code allows Brute Force Attempts

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-27m8-q4mw-5g3g

почти 4 года назад

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-27m7-ffhq-jqrm

2 месяца назад

MCP Watch has a Critical Command Injection in cloneRepo allows Remote Code Execution (RCE) via malicious URL

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27m7-5vm3-3prg

больше 1 года назад

The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service logic. Attackers can exploit the issue by forcing the AI service to leak the standard hard-coded system prompts and/or execute unwanted prompts. When engaging with EmailGPT by submitting a malicious prompt that requests harmful information, the system will respond by providing the requested data. This vulnerability can be exploited by any individual with access to the service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27m7-4v2p-j66r

больше 3 лет назад

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27m5-g4hr-5cg5

почти 4 года назад

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-27m4-qpvr-f79g

больше 3 лет назад

On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code execution, a subset of SVE-2016-6542.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27m4-83f2-2x77

больше 3 лет назад

Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27m2-vhr6-4qpc

больше 3 лет назад

The Talk Radio Europe (aka com.nobexinc.wls_31251464.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-27m2-q889-735v

больше 3 лет назад

A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add a new admin user.

EPSS: Низкий
github логотип

GHSA-27m2-4fpr-973q

почти 3 года назад

A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27jx-wc84-xqv7

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) anzahl_beitraege parameter to jgs_portal.php, (2) year parameter to jgs_portal_statistik.php, (3) year parameter to jgs_portal_beitraggraf.php, (4) tag parameter to jgs_portal_viewsgraf.php, (5) year parameter to jgs_portal_themengraf.php, (6) year parameter to jgs_portal_mitgraf.php, (7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php. NOTE: this issue may stem from the same core problem as CVE-2005-1633.

EPSS: Низкий
github логотип

GHSA-27jx-ffw8-xrqv

почти 2 года назад

pgAdmin Remote Code Execution (RCE) vulnerability

CVSS3: 7.4
EPSS: Критический
github логотип

GHSA-27jx-2xcq-7549

больше 3 лет назад

Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, and CVE-2011-0607.

EPSS: Низкий
github логотип

GHSA-27jw-fm48-8f8j

9 месяцев назад

The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the file_download REST API endpoint due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to download files uploaded by others users and expose potentially sensitive information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27jr-vp8c-qhvq

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27jq-qqfj-p2xx

3 месяца назад

Missing Authorization vulnerability in Gaurav Aggarwal Backup and Move backup-and-move allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backup and Move: from n/a through <= 0.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27jp-f6mj-xr9q

11 месяцев назад

FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27jm-6pj2-8w7g

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-27jj-5xgw-m6qw

почти 4 года назад

Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27mc-9399-r9mx

Drupal Access code allows Brute Force Attempts

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-27m8-q4mw-5g3g

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

53%
Средний
почти 4 года назад
github логотип
GHSA-27m7-ffhq-jqrm

MCP Watch has a Critical Command Injection in cloneRepo allows Remote Code Execution (RCE) via malicious URL

CVSS3: 9.8
1%
Низкий
2 месяца назад
github логотип
GHSA-27m7-5vm3-3prg

The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service logic. Attackers can exploit the issue by forcing the AI service to leak the standard hard-coded system prompts and/or execute unwanted prompts. When engaging with EmailGPT by submitting a malicious prompt that requests harmful information, the system will respond by providing the requested data. This vulnerability can be exploited by any individual with access to the service.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-27m7-4v2p-j66r

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27m5-g4hr-5cg5

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."

35%
Средний
почти 4 года назад
github логотип
GHSA-27m4-qpvr-f79g

On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code execution, a subset of SVE-2016-6542.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-27m4-83f2-2x77

Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27m2-vhr6-4qpc

The Talk Radio Europe (aka com.nobexinc.wls_31251464.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27m2-q889-735v

A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add a new admin user.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-27m2-4fpr-973q

A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-27jx-wc84-xqv7

Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) anzahl_beitraege parameter to jgs_portal.php, (2) year parameter to jgs_portal_statistik.php, (3) year parameter to jgs_portal_beitraggraf.php, (4) tag parameter to jgs_portal_viewsgraf.php, (5) year parameter to jgs_portal_themengraf.php, (6) year parameter to jgs_portal_mitgraf.php, (7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php. NOTE: this issue may stem from the same core problem as CVE-2005-1633.

0%
Низкий
почти 4 года назад
github логотип
GHSA-27jx-ffw8-xrqv

pgAdmin Remote Code Execution (RCE) vulnerability

CVSS3: 7.4
91%
Критический
почти 2 года назад
github логотип
GHSA-27jx-2xcq-7549

Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, and CVE-2011-0607.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-27jw-fm48-8f8j

The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the file_download REST API endpoint due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to download files uploaded by others users and expose potentially sensitive information.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-27jr-vp8c-qhvq

Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 versions.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-27jq-qqfj-p2xx

Missing Authorization vulnerability in Gaurav Aggarwal Backup and Move backup-and-move allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backup and Move: from n/a through <= 0.1.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-27jp-f6mj-xr9q

FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

CVSS3: 9.8
2%
Низкий
11 месяцев назад
github логотип
GHSA-27jm-6pj2-8w7g

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

CVSS3: 8.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-27jj-5xgw-m6qw

Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу