Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-24j3-w3xq-4r3w

10 месяцев назад

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-24j2-jggq-gp96

6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thiudis Custom Menu allows Stored XSS. This issue affects Custom Menu: from n/a through 1.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24j2-327w-xq74

около 3 лет назад

Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24hw-jxqf-4vc6

почти 4 года назад

Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php.

EPSS: Низкий
github логотип

GHSA-24hr-cpfg-6gx9

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: mfd: max77620: Fix refcount leak in max77620_initialise_fps of_get_child_by_name() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount leak.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24hp-jpqm-m2j2

больше 3 лет назад

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A local attacker may be able to elevate their privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24hp-h6f6-wg59

больше 3 лет назад

oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

EPSS: Низкий
github логотип

GHSA-24hp-h53g-7w7v

почти 4 года назад

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214534.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24hp-84jp-8wgm

около 3 лет назад

Cross-Site Request Forgery in Jenkins Cluster Statistics Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24hm-wm2h-h8w7

2 месяца назад

Peppol-py is vulnerable to XXE attacks due to Saxon configuration

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-24hj-mv6m-7hw4

почти 4 года назад

ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24hj-cmm2-v789

больше 3 лет назад

Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872 and CVE-2017-14409.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24hh-m38m-8727

около 1 года назад

A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown part of the file /newProject.php. The manipulation of the argument projectName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-24hh-hrh3-7p5w

почти 4 года назад

The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."

EPSS: Средний
github логотип

GHSA-24hh-5wmw-c8j8

10 месяцев назад

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-24hf-8w68-m6w3

почти 4 года назад

SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.

EPSS: Низкий
github логотип

GHSA-24hc-6j9g-g379

почти 4 года назад

Multiple SQL injection vulnerabilities in phplist before 2.10.3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-24h9-xh6m-x5jf

больше 3 лет назад

A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions.

EPSS: Низкий
github логотип

GHSA-24h9-wwcg-r638

почти 4 года назад

Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.

EPSS: Низкий
github логотип

GHSA-24h9-pvx3-c6g5

около 2 месяцев назад

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24j3-w3xq-4r3w

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function.

CVSS3: 7.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-24j2-jggq-gp96

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thiudis Custom Menu allows Stored XSS. This issue affects Custom Menu: from n/a through 1.8.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-24j2-327w-xq74

Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-24hw-jxqf-4vc6

Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-24hr-cpfg-6gx9

In the Linux kernel, the following vulnerability has been resolved: mfd: max77620: Fix refcount leak in max77620_initialise_fps of_get_child_by_name() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount leak.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-24hp-jpqm-m2j2

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A local attacker may be able to elevate their privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24hp-h6f6-wg59

oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-24hp-h53g-7w7v

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214534.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-24hp-84jp-8wgm

Cross-Site Request Forgery in Jenkins Cluster Statistics Plugin

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-24hm-wm2h-h8w7

Peppol-py is vulnerable to XXE attacks due to Saxon configuration

CVSS3: 5
0%
Низкий
2 месяца назад
github логотип
GHSA-24hj-mv6m-7hw4

ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-24hj-cmm2-v789

Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872 and CVE-2017-14409.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24hh-m38m-8727

A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown part of the file /newProject.php. The manipulation of the argument projectName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-24hh-hrh3-7p5w

The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."

67%
Средний
почти 4 года назад
github логотип
GHSA-24hh-5wmw-c8j8

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.

CVSS3: 4.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-24hf-8w68-m6w3

SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-24hc-6j9g-g379

Multiple SQL injection vulnerabilities in phplist before 2.10.3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-24h9-xh6m-x5jf

A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-24h9-wwcg-r638

Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.

1%
Низкий
почти 4 года назад
github логотип
GHSA-24h9-pvx3-c6g5

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу