Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-xr2p-f39w-cjpv

около 3 лет назад

ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr2p-8p3f-gvvg

почти 4 года назад

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-xr2p-42gc-m46q

почти 4 года назад

** DISPUTED ** On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover secret data shown on the display. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. NOTE: the vendor's position is that there is "insignificant risk."

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-xr2m-m75v-cg43

почти 4 года назад

cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive.

EPSS: Низкий
github логотип

GHSA-xr2m-8rhq-x323

почти 4 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xr2j-xr37-3jm3

почти 4 года назад

Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

EPSS: Низкий
github логотип

GHSA-xr2j-w2jp-cp5m

почти 4 года назад

Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).

EPSS: Средний
github логотип

GHSA-xr2h-wg3w-vrcr

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xr2g-wg2c-hrx6

около 4 лет назад

Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr2f-69jg-7g6f

больше 1 года назад

Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xr2c-mwcx-4xmj

почти 4 года назад

Buffer overflow in NIS+, in Sun's rpc.nisd program.

EPSS: Низкий
github логотип

GHSA-xr2c-mghr-gmr2

больше 3 лет назад

Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xr2c-5w89-63pv

около 4 лет назад

Poetry before v1.1.9 contains Untrusted Search Path

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr2c-56qc-4ffh

около 4 лет назад

A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions)

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xr2c-4prw-6479

почти 4 года назад

PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xr29-6gg3-jq8m

почти 4 года назад

SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.

EPSS: Низкий
github логотип

GHSA-xr29-4f97-vhvq

30 дней назад

A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xr28-hrcf-5jw6

больше 1 года назад

Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xr28-f4wv-gfp3

почти 4 года назад

An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr27-wwfr-j97v

почти 4 года назад

CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr2p-f39w-cjpv

ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xr2p-8p3f-gvvg

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

0%
Низкий
почти 4 года назад
github логотип
GHSA-xr2p-42gc-m46q

** DISPUTED ** On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover secret data shown on the display. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. NOTE: the vendor's position is that there is "insignificant risk."

CVSS3: 2.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr2m-m75v-cg43

cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xr2m-8rhq-x323

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr2j-xr37-3jm3

Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xr2j-w2jp-cp5m

Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).

40%
Средний
почти 4 года назад
github логотип
GHSA-xr2h-wg3w-vrcr

Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xr2g-wg2c-hrx6

Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xr2f-69jg-7g6f

Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xr2c-mwcx-4xmj

Buffer overflow in NIS+, in Sun's rpc.nisd program.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xr2c-mghr-gmr2

Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xr2c-5w89-63pv

Poetry before v1.1.9 contains Untrusted Search Path

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr2c-56qc-4ffh

A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions)

CVSS3: 7.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-xr2c-4prw-6479

PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.

CVSS3: 8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr29-6gg3-jq8m

SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xr29-4f97-vhvq

A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
0%
Низкий
30 дней назад
github логотип
GHSA-xr28-hrcf-5jw6

Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xr28-f4wv-gfp3

An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr27-wwfr-j97v

CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу