Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-2556-mvh4-2wcq

почти 4 года назад

SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

EPSS: Низкий
github логотип

GHSA-2556-7mq8-5gp5

больше 3 лет назад

Unspecified vulnerability in a TList 6 ActiveX control in Oracle Hyperion Financial Management 11.1.1.4 and 11.1.2.1.104 allows remote attackers to execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2555-mvwv-p45x

больше 3 лет назад

The random-number generator in the kernel in Apple Mac OS X before 10.9 provides lengthy exclusive access for processing of large requests, which allows local users to cause a denial of service (temporary generator outage) via an application that requires many random numbers.

EPSS: Низкий
github логотип

GHSA-2554-pph3-4jmx

больше 3 лет назад

Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series) and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2554-hmfm-35j3

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: mm/damon/reclaim: fix potential memory leak in damon_reclaim_init() damon_reclaim_init() allocates a memory chunk for ctx with damon_new_ctx(). When damon_select_ops() fails, ctx is not released, which will lead to a memory leak. We should release the ctx with damon_destroy_ctx() when damon_select_ops() fails to fix the memory leak.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2552-xggr-7cv4

7 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory allows SQL Injection. This issue affects Simple Link Directory: from n/a through 14.7.3.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2552-r9rc-6x22

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in inc/extensions.php in VertrigoServ 2.25 allows remote attackers to inject arbitrary web script or HTML via the ext parameter.

EPSS: Низкий
github логотип

GHSA-2552-7vjw-33qv

больше 3 лет назад

In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms. Session and query IDs are unique and random, but have not been documented or consistently treated as sensitive secrets. Therefore they may be exposed in logs or interfaces. They were also not generated with a cryptographically secure random number generator, so are vulnerable to random number generator attacks that predict future IDs based on past IDs. Impala deployments with Apache Sentry or Apache Ranger authorization enabled may be vulnerable to privilege escalation if an authenticated attacker is able to hijack a session or query from another authenticated user with privileges not assigned to the attacker. Impala deployments with audit logging enabled may be vulnerable to incorrect audit logging as a user could undertake ...

EPSS: Низкий
github логотип

GHSA-254x-7xj8-2w85

больше 3 лет назад

The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message.

EPSS: Низкий
github логотип

GHSA-254x-3896-gg43

почти 4 года назад

FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.

EPSS: Низкий
github логотип

GHSA-254w-gr7h-wvh4

больше 2 лет назад

The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin settings, such as the allowed upload file types. This can lead to remote code execution through other vulnerabilities.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-254v-xjfq-x8gj

почти 4 года назад

PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.

EPSS: Низкий
github логотип

GHSA-254v-c952-g64w

около 1 года назад

EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-254v-3mjq-6mjm

почти 4 года назад

SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.

EPSS: Низкий
github логотип

GHSA-254r-xffm-9c3g

11 месяцев назад

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-254r-9226-v29v

больше 3 лет назад

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-254q-rqmw-vx45

почти 4 года назад

Exposure of Sensitive Information to an Unauthorized Actor in librenms

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-254q-rp36-v2m8

больше 3 лет назад

Missing XML Validation in Apache CXF

EPSS: Средний
github логотип

GHSA-254q-r25r-fwm9

больше 3 лет назад

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-254p-hhvc-rr9q

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2556-mvh4-2wcq

SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2556-7mq8-5gp5

Unspecified vulnerability in a TList 6 ActiveX control in Oracle Hyperion Financial Management 11.1.1.4 and 11.1.2.1.104 allows remote attackers to execute arbitrary code via unknown vectors.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-2555-mvwv-p45x

The random-number generator in the kernel in Apple Mac OS X before 10.9 provides lengthy exclusive access for processing of large requests, which allows local users to cause a denial of service (temporary generator outage) via an application that requires many random numbers.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2554-pph3-4jmx

Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Type Advanced 7 Series) and Movable Type Premium Advanced 1.44 and earlier) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2554-hmfm-35j3

In the Linux kernel, the following vulnerability has been resolved: mm/damon/reclaim: fix potential memory leak in damon_reclaim_init() damon_reclaim_init() allocates a memory chunk for ctx with damon_new_ctx(). When damon_select_ops() fails, ctx is not released, which will lead to a memory leak. We should release the ctx with damon_destroy_ctx() when damon_select_ops() fails to fix the memory leak.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2552-xggr-7cv4

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory allows SQL Injection. This issue affects Simple Link Directory: from n/a through 14.7.3.

CVSS3: 8.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2552-r9rc-6x22

Cross-site scripting (XSS) vulnerability in inc/extensions.php in VertrigoServ 2.25 allows remote attackers to inject arbitrary web script or HTML via the ext parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2552-7vjw-33qv

In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms. Session and query IDs are unique and random, but have not been documented or consistently treated as sensitive secrets. Therefore they may be exposed in logs or interfaces. They were also not generated with a cryptographically secure random number generator, so are vulnerable to random number generator attacks that predict future IDs based on past IDs. Impala deployments with Apache Sentry or Apache Ranger authorization enabled may be vulnerable to privilege escalation if an authenticated attacker is able to hijack a session or query from another authenticated user with privileges not assigned to the attacker. Impala deployments with audit logging enabled may be vulnerable to incorrect audit logging as a user could undertake ...

0%
Низкий
больше 3 лет назад
github логотип
GHSA-254x-7xj8-2w85

The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-254x-3896-gg43

FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.

0%
Низкий
почти 4 года назад
github логотип
GHSA-254w-gr7h-wvh4

The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin settings, such as the allowed upload file types. This can lead to remote code execution through other vulnerabilities.

CVSS3: 9.9
5%
Низкий
больше 2 лет назад
github логотип
GHSA-254v-xjfq-x8gj

PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.

2%
Низкий
почти 4 года назад
github логотип
GHSA-254v-c952-g64w

EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-254v-3mjq-6mjm

SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.

1%
Низкий
почти 4 года назад
github логотип
GHSA-254r-xffm-9c3g

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-254r-9226-v29v

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
7%
Низкий
больше 3 лет назад
github логотип
GHSA-254q-rqmw-vx45

Exposure of Sensitive Information to an Unauthorized Actor in librenms

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-254q-rp36-v2m8

Missing XML Validation in Apache CXF

20%
Средний
больше 3 лет назад
github логотип
GHSA-254q-r25r-fwm9

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-254p-hhvc-rr9q

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу