Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 368

Количество 313 368

github логотип

GHSA-2564-4rf9-wv93

больше 3 лет назад

Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.

EPSS: Низкий
github логотип

GHSA-2563-x4h3-pq75

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KentoThemes Justified Image Gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2563-r73r-7cq9

почти 4 года назад

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2563-fp9c-mgm8

почти 3 года назад

Moodle Session Fixation vulnerability

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2563-9f8c-7cw3

почти 4 года назад

PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

EPSS: Низкий
github логотип

GHSA-2563-83p7-f34p

больше 5 лет назад

Malicious Package in requestt

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-255x-mvhm-3947

больше 3 лет назад

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-255w-87rh-rg44

больше 1 года назад

Cross-site Scripting via uploaded SVG

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-255v-qv84-29p5

5 месяцев назад

DragonFly's manager generates mTLS certificates for arbitrary IP addresses

EPSS: Низкий
github логотип

GHSA-255v-qpcm-wc95

больше 3 лет назад

Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

EPSS: Низкий
github логотип

GHSA-255v-hc9m-54wv

около 2 месяцев назад

Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-255v-grg6-24pg

больше 2 лет назад

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-255v-ffqg-5w87

больше 3 лет назад

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-255r-pghp-r5wh

больше 5 лет назад

Malicious Package in hdeky

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-255r-f4p7-p9r5

больше 3 лет назад

Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

EPSS: Низкий
github логотип

GHSA-255r-3prx-mf99

почти 3 года назад

`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8

EPSS: Низкий
github логотип

GHSA-255q-f9p7-jxj6

больше 2 лет назад

Microsoft SharePoint Server Spoofing Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-255p-hfwr-9qm4

больше 3 лет назад

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-255p-hfc6-whjx

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021.

EPSS: Низкий
github логотип

GHSA-255m-x7w5-9w65

12 месяцев назад

Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2564-4rf9-wv93

Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2563-x4h3-pq75

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KentoThemes Justified Image Gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2563-r73r-7cq9

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
17%
Средний
почти 4 года назад
github логотип
GHSA-2563-fp9c-mgm8

Moodle Session Fixation vulnerability

CVSS3: 9.8
21%
Средний
почти 3 года назад
github логотип
GHSA-2563-9f8c-7cw3

PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-2563-83p7-f34p

Malicious Package in requestt

CVSS3: 9.8
больше 5 лет назад
github логотип
GHSA-255x-mvhm-3947

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-255w-87rh-rg44

Cross-site Scripting via uploaded SVG

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-255v-qv84-29p5

DragonFly's manager generates mTLS certificates for arbitrary IP addresses

0%
Низкий
5 месяцев назад
github логотип
GHSA-255v-qpcm-wc95

Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-255v-hc9m-54wv

Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-255v-grg6-24pg

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.

CVSS3: 9.8
10%
Низкий
больше 2 лет назад
github логотип
GHSA-255v-ffqg-5w87

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-255r-pghp-r5wh

Malicious Package in hdeky

CVSS3: 9.1
больше 5 лет назад
github логотип
GHSA-255r-f4p7-p9r5

Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-255r-3prx-mf99

`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8

почти 3 года назад
github логотип
GHSA-255q-f9p7-jxj6

Microsoft SharePoint Server Spoofing Vulnerability

CVSS3: 8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-255p-hfwr-9qm4

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-255p-hfc6-whjx

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-255m-x7w5-9w65

Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

CVSS3: 9.8
0%
Низкий
12 месяцев назад

Уязвимостей на страницу