Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-2c38-3wjv-55hm

около 1 года назад

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registration Handler. The manipulation of the argument email leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2c36-wq4v-5v3h

около 1 года назад

A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the application's API.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2c36-q5xr-cj3m

почти 4 года назад

SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-2c36-px5h-vq95

почти 4 года назад

Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c36-jpqg-cq22

почти 4 года назад

The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924.

EPSS: Низкий
github логотип

GHSA-2c36-4mp6-4c2f

почти 4 года назад

Multiple unspecified vulnerabilities in IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 allow attackers to have an unknown impact via vectors related to third-party .ocx files.

EPSS: Низкий
github логотип

GHSA-2c34-w9r8-qhww

12 месяцев назад

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions prior to 1.1.3. This vulnerability has been patched in versions after 1.1.3. Leaving this vulnerability unpatched could lead to unauthorized access to the underlying infrastructure.

EPSS: Низкий
github логотип

GHSA-2c33-w3rv-x526

почти 4 года назад

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c2w-j78h-7xwc

почти 4 года назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server.

EPSS: Низкий
github логотип

GHSA-2c2w-ghqr-g6hj

почти 4 года назад

Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."

EPSS: Низкий
github логотип

GHSA-2c2w-95gp-xc68

12 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ho3einie Material Dashboard allows PHP Local File Inclusion. This issue affects Material Dashboard: from n/a through 1.4.5.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c2r-rcrh-5h3h

почти 4 года назад

Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.

EPSS: Низкий
github логотип

GHSA-2c2r-r59f-9396

почти 4 года назад

An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.

EPSS: Средний
github логотип

GHSA-2c2q-v642-37w6

почти 4 года назад

The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c2q-27q9-rxpg

7 месяцев назад

Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c2p-jp6r-5757

около 1 года назад

GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c2j-9gv5-cj73

9 месяцев назад

Starlette has possible denial-of-service vector when parsing large files in multipart forms

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2c2j-2pgv-gfgc

больше 2 лет назад

Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow compromise key generation, certificate loading, and other card management operations during enrollment.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2c2h-wghv-2fg7

почти 4 года назад

CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c2h-qvww-cw95

почти 4 года назад

In Alpine through 2.24, untagged responses from an IMAP server are accepted before STARTTLS.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c38-3wjv-55hm

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registration Handler. The manipulation of the argument email leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2c36-wq4v-5v3h

A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the application's API.

CVSS3: 7.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2c36-q5xr-cj3m

SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c36-px5h-vq95

Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c36-jpqg-cq22

The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c36-4mp6-4c2f

Multiple unspecified vulnerabilities in IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 allow attackers to have an unknown impact via vectors related to third-party .ocx files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c34-w9r8-qhww

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions prior to 1.1.3. This vulnerability has been patched in versions after 1.1.3. Leaving this vulnerability unpatched could lead to unauthorized access to the underlying infrastructure.

0%
Низкий
12 месяцев назад
github логотип
GHSA-2c33-w3rv-x526

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-2c2w-j78h-7xwc

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c2w-ghqr-g6hj

Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."

9%
Низкий
почти 4 года назад
github логотип
GHSA-2c2w-95gp-xc68

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ho3einie Material Dashboard allows PHP Local File Inclusion. This issue affects Material Dashboard: from n/a through 1.4.5.

CVSS3: 7.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-2c2r-rcrh-5h3h

Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2c2r-r59f-9396

An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.

60%
Средний
почти 4 года назад
github логотип
GHSA-2c2q-v642-37w6

The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c2q-27q9-rxpg

Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in arbitrary code execution.

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-2c2p-jp6r-5757

GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2c2j-9gv5-cj73

Starlette has possible denial-of-service vector when parsing large files in multipart forms

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-2c2j-2pgv-gfgc

Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses to APDUs. This manipulation can potentially allow compromise key generation, certificate loading, and other card management operations during enrollment.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2c2h-wghv-2fg7

CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2c2h-qvww-cw95

In Alpine through 2.24, untagged responses from an IMAP server are accepted before STARTTLS.

CVSS3: 5.9
0%
Низкий
почти 4 года назад

Уязвимостей на страницу