Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-298v-qmqm-hfrx

2 месяца назад

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of github-kanban-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the create_issue parameter. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-27784.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-298v-7gc3-86vj

почти 4 года назад

UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-298r-5c48-7q2r

больше 3 лет назад

Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-298q-wv2h-v5vw

почти 4 года назад

Magento 2 Community Edition XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-298q-w9qh-3r99

около 2 лет назад

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-298q-cxp8-5c9m

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-298p-q946-hhq4

почти 4 года назад

Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.

EPSS: Низкий
github логотип

GHSA-298p-mmc8-j4x9

больше 1 года назад

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-298m-hvgh-x9cw

почти 3 года назад

Alluxio Cross Site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-298j-cm7q-56g9

почти 4 года назад

An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-298j-9q4w-6rm4

почти 4 года назад

Agent-to-controller security bypass in Jenkins xUnit Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-298h-vfc8-fcfc

около 1 года назад

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-298h-373h-w6rq

около 3 лет назад

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mighty Digital Nooz plugin <= 1.6.0 versions.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-298g-w225-3g3w

почти 4 года назад

Unspecified vulnerability in the Cabo/UIX component in Oracle Fusion Middleware 10.1.2.3 and 10.1.3.5 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2010-2395 and CVE-2010-2410.

EPSS: Низкий
github логотип

GHSA-298c-rvvp-xh7q

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: topology: Fix references to freed memory Most users after parsing a topology file, release memory used by it, so having pointer references directly into topology file contents is wrong. Use devm_kmemdup(), to allocate memory as needed.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2989-gqx8-wgwx

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: FS: JFS: Check for read-only mounted filesystem in txBegin This patch adds a check for read-only mounted filesystem in txBegin before starting a transaction potentially saving from NULL pointer deref.

EPSS: Низкий
github логотип

GHSA-2988-m58c-m55p

больше 3 лет назад

OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2988-fj4q-frxv

11 месяцев назад

A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getResource of the file /cms/fileTemplate/form of the component URI Scheme Handler. The manipulation of the argument Name leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2988-8m49-6wmh

больше 1 года назад

A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2988-2x63-c565

почти 4 года назад

** DISPUTED ** Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE: An established researcher has disputed this issue, saying that "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-298v-qmqm-hfrx

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of github-kanban-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the create_issue parameter. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-27784.

CVSS3: 9.8
1%
Низкий
2 месяца назад
github логотип
GHSA-298v-7gc3-86vj

UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-298r-5c48-7q2r

Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion

CVSS3: 8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-298q-wv2h-v5vw

Magento 2 Community Edition XSS Vulnerability

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-298q-w9qh-3r99

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

CVSS3: 8.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-298q-cxp8-5c9m

Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-298p-q946-hhq4

Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.

1%
Низкий
почти 4 года назад
github логотип
GHSA-298p-mmc8-j4x9

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.1
9%
Низкий
больше 1 года назад
github логотип
GHSA-298m-hvgh-x9cw

Alluxio Cross Site Scripting vulnerability

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-298j-cm7q-56g9

An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-298j-9q4w-6rm4

Agent-to-controller security bypass in Jenkins xUnit Plugin

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-298h-vfc8-fcfc

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-298h-373h-w6rq

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mighty Digital Nooz plugin <= 1.6.0 versions.

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-298g-w225-3g3w

Unspecified vulnerability in the Cabo/UIX component in Oracle Fusion Middleware 10.1.2.3 and 10.1.3.5 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2010-2395 and CVE-2010-2410.

0%
Низкий
почти 4 года назад
github логотип
GHSA-298c-rvvp-xh7q

In the Linux kernel, the following vulnerability has been resolved: ASoC: topology: Fix references to freed memory Most users after parsing a topology file, release memory used by it, so having pointer references directly into topology file contents is wrong. Use devm_kmemdup(), to allocate memory as needed.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2989-gqx8-wgwx

In the Linux kernel, the following vulnerability has been resolved: FS: JFS: Check for read-only mounted filesystem in txBegin This patch adds a check for read-only mounted filesystem in txBegin before starting a transaction potentially saving from NULL pointer deref.

0%
Низкий
4 месяца назад
github логотип
GHSA-2988-m58c-m55p

OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.

CVSS3: 7.2
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2988-fj4q-frxv

A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getResource of the file /cms/fileTemplate/form of the component URI Scheme Handler. The manipulation of the argument Name leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2988-8m49-6wmh

A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2988-2x63-c565

** DISPUTED ** Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE: An established researcher has disputed this issue, saying that "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."

11%
Средний
почти 4 года назад

Уязвимостей на страницу