Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 185

Количество 326 185

github логотип

GHSA-2h2v-vcj6-9g2j

почти 4 года назад

Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action.

EPSS: Низкий
github логотип

GHSA-2h2v-8cgx-wfvj

почти 4 года назад

A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h2r-w6vh-2w6r

почти 4 года назад

DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2h2r-cg5q-pf39

около 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted content from the lock screen.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h2q-fhfv-pjvj

почти 4 года назад

The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0108.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2h2q-cpp4-qphp

почти 4 года назад

Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.

EPSS: Низкий
github логотип

GHSA-2h2q-74g8-r928

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool allows Cross Site Request Forgery. This issue affects Football Pool: from n/a through 2.12.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h2q-6mw2-pq7r

6 месяцев назад

A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2h2q-4chj-wggp

почти 4 года назад

Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2h2q-3qrx-m3j7

9 месяцев назад

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2h2q-247m-jhjc

10 месяцев назад

A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the argument filename leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h2p-mvfx-868w

около 1 месяца назад

SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-2h2p-h37h-5phg

почти 4 года назад

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

EPSS: Высокий
github логотип

GHSA-2h2m-v2mg-656c

2 месяца назад

Craft Commerce has Stored XSS in Product Type Name

EPSS: Низкий
github логотип

GHSA-2h2m-7hfv-6h4g

почти 4 года назад

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."

EPSS: Низкий
github логотип

GHSA-2h2m-3wv3-pqw4

почти 4 года назад

mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.

EPSS: Средний
github логотип

GHSA-2h2j-mg4w-wm75

почти 4 года назад

cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2h2j-hwh4-6vfv

почти 4 года назад

VP9 Video Extensions Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-2h2j-9q8m-6ccv

8 месяцев назад

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2h2j-55g7-g43c

почти 3 года назад

The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog folders

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h2v-vcj6-9g2j

Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2h2v-8cgx-wfvj

A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2h2r-w6vh-2w6r

DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2h2r-cg5q-pf39

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted content from the lock screen.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2h2q-fhfv-pjvj

The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0108.

CVSS3: 7.5
24%
Средний
почти 4 года назад
github логотип
GHSA-2h2q-cpp4-qphp

Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2h2q-74g8-r928

Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool allows Cross Site Request Forgery. This issue affects Football Pool: from n/a through 2.12.2.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2h2q-6mw2-pq7r

A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 2.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-2h2q-4chj-wggp

Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2h2q-3qrx-m3j7

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2h2q-247m-jhjc

A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the argument filename leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2h2p-mvfx-868w

SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage

CVSS3: 9.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2h2p-h37h-5phg

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

84%
Высокий
почти 4 года назад
github логотип
GHSA-2h2m-v2mg-656c

Craft Commerce has Stored XSS in Product Type Name

0%
Низкий
2 месяца назад
github логотип
GHSA-2h2m-7hfv-6h4g

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."

0%
Низкий
почти 4 года назад
github логотип
GHSA-2h2m-3wv3-pqw4

mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.

16%
Средний
почти 4 года назад
github логотип
GHSA-2h2j-mg4w-wm75

cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2h2j-hwh4-6vfv

VP9 Video Extensions Remote Code Execution Vulnerability

CVSS3: 7.8
12%
Средний
почти 4 года назад
github логотип
GHSA-2h2j-9q8m-6ccv

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function.

CVSS3: 4.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2h2j-55g7-g43c

The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog folders

CVSS3: 6.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу