Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-23jc-vf68-9rcv

12 дней назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woofer696 Dinatur dinatur allows Stored XSS.This issue affects Dinatur: from n/a through <= 1.18.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-23jc-mx6c-hh36

больше 3 лет назад

The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value for the remote address field.

EPSS: Низкий
github логотип

GHSA-23jc-966q-fmw3

больше 3 лет назад

In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-124232283.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-23jc-43ph-xg8h

около 3 лет назад

An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23j9-g3qf-7fpq

почти 3 года назад

A vulnerability, which was classified as critical, has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. This issue affects some unknown processing of the file /admin/login.php. The manipulation of the argument txtusername/txtpassword leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222851.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23j9-36qq-2q2f

5 месяцев назад

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability refers to the authenticated OS Command Injection that occurs through the attacker-controlled `btn1` parameter, at offset `0x8eb0`.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-23j9-2h8v-jvjm

больше 3 лет назад

TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23j8-j8rc-c9hw

больше 3 лет назад

When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() function in lib/q.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23j7-px3w-jwp2

7 месяцев назад

Jenkins Xooa Plugin vulnerability does not mask its Xooa Deployment Token

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23j7-2rxw-3q84

около 2 лет назад

A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250444.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23j5-p74r-rvqm

больше 3 лет назад

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.

EPSS: Низкий
github логотип

GHSA-23j4-mw76-5v7h

больше 1 года назад

Scrapy allows redirect following in protocols other than HTTP

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23j3-qh8r-rpx6

почти 4 года назад

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

EPSS: Низкий
github логотип

GHSA-23j2-8hh8-295f

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: hpsa: Fix possible memory leak in hpsa_init_one() The hpda_alloc_ctlr_info() allocates h and its field reply_map. However, in hpsa_init_one(), if alloc_percpu() failed, the hpsa_init_one() jumps to clean1 directly, which frees h and leaks the h->reply_map. Fix by calling hpda_free_ctlr_info() to release h->replay_map and h instead free h directly.

EPSS: Низкий
github логотип

GHSA-23hx-rv96-mjqx

больше 3 лет назад

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

EPSS: Низкий
github логотип

GHSA-23hx-gmq6-vwxq

больше 3 лет назад

Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.

EPSS: Низкий
github логотип

GHSA-23hw-vp6g-7987

8 месяцев назад

A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-23hv-mwm6-g8jf

6 месяцев назад

Apache Tomcat Session Fixation vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23hv-h2r7-ggj5

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23hv-gjhm-8vrh

4 месяца назад

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23jc-vf68-9rcv

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woofer696 Dinatur dinatur allows Stored XSS.This issue affects Dinatur: from n/a through <= 1.18.

CVSS3: 7.2
0%
Низкий
12 дней назад
github логотип
GHSA-23jc-mx6c-hh36

The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value for the remote address field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23jc-966q-fmw3

In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-124232283.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23jc-43ph-xg8h

An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-23j9-g3qf-7fpq

A vulnerability, which was classified as critical, has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. This issue affects some unknown processing of the file /admin/login.php. The manipulation of the argument txtusername/txtpassword leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222851.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-23j9-36qq-2q2f

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability refers to the authenticated OS Command Injection that occurs through the attacker-controlled `btn1` parameter, at offset `0x8eb0`.

CVSS3: 7.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-23j9-2h8v-jvjm

TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23j8-j8rc-c9hw

When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() function in lib/q.c.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23j7-px3w-jwp2

Jenkins Xooa Plugin vulnerability does not mask its Xooa Deployment Token

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-23j7-2rxw-3q84

A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250444.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-23j5-p74r-rvqm

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23j4-mw76-5v7h

Scrapy allows redirect following in protocols other than HTTP

CVSS3: 6.5
больше 1 года назад
github логотип
GHSA-23j3-qh8r-rpx6

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

1%
Низкий
почти 4 года назад
github логотип
GHSA-23j2-8hh8-295f

In the Linux kernel, the following vulnerability has been resolved: scsi: hpsa: Fix possible memory leak in hpsa_init_one() The hpda_alloc_ctlr_info() allocates h and its field reply_map. However, in hpsa_init_one(), if alloc_percpu() failed, the hpsa_init_one() jumps to clean1 directly, which frees h and leaks the h->reply_map. Fix by calling hpda_free_ctlr_info() to release h->replay_map and h instead free h directly.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-23hx-rv96-mjqx

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23hx-gmq6-vwxq

Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-23hw-vp6g-7987

A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-23hv-mwm6-g8jf

Apache Tomcat Session Fixation vulnerability

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-23hv-h2r7-ggj5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-23hv-gjhm-8vrh

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу