Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-24xc-5f2v-5mc5

8 месяцев назад

A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects the function AdminShitiListRequestVo of the file com\llisoft\controller\admin\shiti\AdminShitiController.java. The manipulation of the argument stTypeIds leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-24xc-3gmc-877f

больше 3 лет назад

The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24x9-9gx2-3g25

больше 3 лет назад

The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24x8-vf4r-m3v5

около 1 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows Blind SQL Injection.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24x8-275w-hwpr

около 2 лет назад

The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24x7-gxr3-5r7r

больше 3 лет назад

The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24x7-c4mf-44m6

10 месяцев назад

A vulnerability, which was classified as problematic, has been found in ConcreteCMS up to 9.3.9. This issue affects the function addEditQuestion of the component Legacy Form Block Handler. The manipulation of the argument Question leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-24x7-8mv3-v5xj

почти 3 года назад

A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226276.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-24x6-8c7m-hv3f

больше 4 лет назад

Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-24x5-c472-vx8w

3 месяца назад

A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. A remote attacker may be able to cause a denial-of-service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24x4-hpq6-x4j9

почти 4 года назад

Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter.

EPSS: Низкий
github логотип

GHSA-24x4-6qmh-88qg

почти 4 года назад

Use after free in `DecodePng` kernel

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-24x4-44mg-fffp

больше 3 лет назад

Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photos/.

EPSS: Низкий
github логотип

GHSA-24x2-jv4m-57w2

около 1 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-24wx-mghc-gchm

больше 3 лет назад

A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24wx-m9jq-x9f7

27 дней назад

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24ww-mc5x-xc43

больше 4 лет назад

Man-in-the-middle attack in Apache Cassandra

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-24ww-hqf6-2c58

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-24ww-94h4-w44f

почти 4 года назад

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-24wv-qqjw-rp9w

больше 3 лет назад

Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVSS3: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24xc-5f2v-5mc5

A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects the function AdminShitiListRequestVo of the file com\llisoft\controller\admin\shiti\AdminShitiController.java. The manipulation of the argument stTypeIds leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-24xc-3gmc-877f

The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24x9-9gx2-3g25

The Awin Data Feed WordPress plugin through 1.6 does not sanitise and escape a parameter before outputting it back via an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
5%
Низкий
больше 3 лет назад
github логотип
GHSA-24x8-vf4r-m3v5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows Blind SQL Injection.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-24x8-275w-hwpr

The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-24x7-gxr3-5r7r

The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24x7-c4mf-44m6

A vulnerability, which was classified as problematic, has been found in ConcreteCMS up to 9.3.9. This issue affects the function addEditQuestion of the component Legacy Form Block Handler. The manipulation of the argument Question leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
10 месяцев назад
github логотип
GHSA-24x7-8mv3-v5xj

A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226276.

CVSS3: 2.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-24x6-8c7m-hv3f

Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`

CVSS3: 2.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-24x5-c472-vx8w

A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. A remote attacker may be able to cause a denial-of-service.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-24x4-hpq6-x4j9

Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-24x4-6qmh-88qg

Use after free in `DecodePng` kernel

CVSS3: 7.6
0%
Низкий
почти 4 года назад
github логотип
GHSA-24x4-44mg-fffp

Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photos/.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-24x2-jv4m-57w2

Rejected reason: Not used

около 1 месяца назад
github логотип
GHSA-24wx-mghc-gchm

A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24wx-m9jq-x9f7

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.

CVSS3: 9.8
0%
Низкий
27 дней назад
github логотип
GHSA-24ww-mc5x-xc43

Man-in-the-middle attack in Apache Cassandra

CVSS3: 5.9
0%
Низкий
больше 4 лет назад
github логотип
GHSA-24ww-hqf6-2c58

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-24ww-94h4-w44f

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-24wv-qqjw-rp9w

Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVSS3: 4.6
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу