Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-226m-fqfj-v6xp

почти 2 года назад

Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-226j-3v4h-8cg4

больше 1 года назад

Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-226h-qrg4-8236

больше 3 лет назад

Stored XSS vulnerability in chosen-views-tabbar Plugin

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-226h-j848-vv7w

8 месяцев назад

A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-226h-h99r-j24r

около 2 лет назад

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-226h-cxv5-p8qg

около 2 месяцев назад

The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing nonce validation in the quran_gateway_options function. This makes it possible for unauthenticated attackers to modify the plugin's display settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-226h-772w-v9vj

больше 3 лет назад

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).

EPSS: Низкий
github логотип

GHSA-226h-2qfh-4hf8

больше 1 года назад

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-226f-28jj-g35j

6 месяцев назад

A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation of the argument rm_port leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-226c-wpq4-r9cj

почти 4 года назад

SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

EPSS: Низкий
github логотип

GHSA-226c-v4c5-7xv2

около 1 месяца назад

The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2269-968q-6hcq

почти 3 года назад

Memory corruption due to improper access control in Qualcomm IPC.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2268-w43v-j544

больше 1 года назад

Cross-Site Request Forgery (CSRF) in stitionai/devika

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2268-rqjm-gx38

больше 2 лет назад

IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-2268-hc24-w7pm

около 3 лет назад

Azure Network Watcher Agent Security Feature Bypass Vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2268-98wh-qfhf

около 2 лет назад

JLine vulnerable to out of memory error

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2268-76c3-x85m

больше 3 лет назад

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2267-xqcf-gw2m

около 1 месяца назад

FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload

EPSS: Низкий
github логотип

GHSA-2267-x99j-hcv3

12 месяцев назад

Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2267-87gq-vw4p

около 3 лет назад

In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-226m-fqfj-v6xp

Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-226j-3v4h-8cg4

Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-226h-qrg4-8236

Stored XSS vulnerability in chosen-views-tabbar Plugin

CVSS3: 8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-226h-j848-vv7w

A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-226h-h99r-j24r

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-226h-cxv5-p8qg

The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing nonce validation in the quran_gateway_options function. This makes it possible for unauthenticated attackers to modify the plugin's display settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-226h-772w-v9vj

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).

3%
Низкий
больше 3 лет назад
github логотип
GHSA-226h-2qfh-4hf8

Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-226f-28jj-g35j

A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation of the argument rm_port leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-226c-wpq4-r9cj

SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-226c-v4c5-7xv2

The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input field in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2269-968q-6hcq

Memory corruption due to improper access control in Qualcomm IPC.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2268-w43v-j544

Cross-Site Request Forgery (CSRF) in stitionai/devika

CVSS3: 8.8
больше 1 года назад
github логотип
GHSA-2268-rqjm-gx38

IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.

CVSS3: 5.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2268-hc24-w7pm

Azure Network Watcher Agent Security Feature Bypass Vulnerability.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2268-98wh-qfhf

JLine vulnerable to out of memory error

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2268-76c3-x85m

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least one of the meta-types. As a result, subsequent queries from clients requesting DNSSEC validation will be answered with a ServFail.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2267-xqcf-gw2m

FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload

0%
Низкий
около 1 месяца назад
github логотип
GHSA-2267-x99j-hcv3

Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-2267-87gq-vw4p

In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203

CVSS3: 5.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу