Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 078

Количество 314 078

github логотип

GHSA-26cp-j6f9-2w7c

почти 2 года назад

A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-26cp-4qrm-4637

почти 4 года назад

Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and information disclosure.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26cm-qrc6-mfgj

около 4 лет назад

Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-26cm-5c58-46mm

больше 3 лет назад

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not check if the user is authenticated, a malicious actor can craft a specific request on the login.cgi endpoint that contains a base32 encoded XSS payload that will be accepted and stored. A successful attack will results in the injection of malicious scripts into the user settings page.

EPSS: Низкий
github логотип

GHSA-26cj-x9h8-rx93

больше 3 лет назад

Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://

EPSS: Низкий
github логотип

GHSA-26cj-fq73-4g9h

8 дней назад

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26ch-x2j2-w6vx

больше 3 лет назад

The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.

EPSS: Низкий
github логотип

GHSA-26ch-h6w2-4q6g

почти 4 года назад

inc_login_check.asp ACS Blog 0.8 through 1.1.3 allows remote attackers to gain administrator privileges via the "in" value in a cookie.

EPSS: Низкий
github логотип

GHSA-26ch-39wc-5m9p

больше 1 года назад

robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-26ch-2fxx-xjff

больше 3 лет назад

Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. As a result, the FRP function is bypassed.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-26cg-rw99-22rc

почти 2 года назад

Cross site scripting (XSS) vulnerability in file main.php in sourcecodester oretnom23 Blog Site 1.0 via the name and email parameters to function user_add.\

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26cg-cvm3-73gm

почти 4 года назад

Cross-site scripting (XSS) vulnerability in default.asp in QuickerSite 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the svalue parameter in a search action. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-26cf-ch3x-rfxg

больше 2 лет назад

Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-26c9-jffw-hrr9

почти 4 года назад

Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.

EPSS: Низкий
github логотип

GHSA-26c9-c5gx-m85h

больше 3 лет назад

The HoneyBee Mag (aka com.magzter.honeybeemag) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-26c8-846h-xfjj

больше 3 лет назад

An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::ReconstructUnsampled() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.

EPSS: Низкий
github логотип

GHSA-26c7-w6fg-fw3h

больше 3 лет назад

The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user browses an attack-controlled domain. This is fixed in version 2.6.1_Windows.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26c6-j7hf-fgpp

4 месяца назад

A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /login.php. Performing manipulation of the argument email results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-26c6-c3h3-4qf7

около 1 года назад

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

EPSS: Низкий
github логотип

GHSA-26c6-8j4f-jwqh

почти 4 года назад

A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or a kernel information leak.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26cp-j6f9-2w7c

A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.

CVSS3: 4.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-26cp-4qrm-4637

Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and information disclosure.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-26cm-qrc6-mfgj

Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker

CVSS3: 8.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-26cm-5c58-46mm

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not check if the user is authenticated, a malicious actor can craft a specific request on the login.cgi endpoint that contains a base32 encoded XSS payload that will be accepted and stored. A successful attack will results in the injection of malicious scripts into the user settings page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26cj-x9h8-rx93

Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://

1%
Низкий
больше 3 лет назад
github логотип
GHSA-26cj-fq73-4g9h

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

CVSS3: 5.5
0%
Низкий
8 дней назад
github логотип
GHSA-26ch-x2j2-w6vx

The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26ch-h6w2-4q6g

inc_login_check.asp ACS Blog 0.8 through 1.1.3 allows remote attackers to gain administrator privileges via the "in" value in a cookie.

1%
Низкий
почти 4 года назад
github логотип
GHSA-26ch-39wc-5m9p

robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.

CVSS3: 9.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-26ch-2fxx-xjff

Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B130,FRD-L02C675B170CUSTC675D001,FRD-L04C567B162,FRD-L04C605B131,FRD-L09C10B130,FRD-L09C185B130,FRD-L09C432B131,FRD-L09C636B130,FRD-L14C567B162,FRD-L19C10B130,FRD-L19C432B131,FRD-L19C636B130 have a factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Swype Keyboard and can perform some operations to update the Google account. As a result, the FRP function is bypassed.

CVSS3: 4.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26cg-rw99-22rc

Cross site scripting (XSS) vulnerability in file main.php in sourcecodester oretnom23 Blog Site 1.0 via the name and email parameters to function user_add.\

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-26cg-cvm3-73gm

Cross-site scripting (XSS) vulnerability in default.asp in QuickerSite 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the svalue parameter in a search action. NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26cf-ch3x-rfxg

Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVSS3: 9.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26c9-jffw-hrr9

Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.

1%
Низкий
почти 4 года назад
github логотип
GHSA-26c9-c5gx-m85h

The HoneyBee Mag (aka com.magzter.honeybeemag) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26c8-846h-xfjj

An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::ReconstructUnsampled() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26c7-w6fg-fw3h

The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user browses an attack-controlled domain. This is fixed in version 2.6.1_Windows.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26c6-j7hf-fgpp

A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /login.php. Performing manipulation of the argument email results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-26c6-c3h3-4qf7

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

0%
Низкий
около 1 года назад
github логотип
GHSA-26c6-8j4f-jwqh

A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or a kernel information leak.

CVSS3: 6.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу