Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 758

Количество 324 758

github логотип

GHSA-28q9-9c3g-v3f9

больше 3 лет назад

lakeFS vulnerable to authenticated users deleting files they are not authorized to delete

EPSS: Низкий
github логотип

GHSA-28q8-f96p-q62j

больше 1 года назад

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-28q8-3hq4-6hmv

почти 4 года назад

Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 Gold through SP6 allows remote authenticated users to gain privileges via unknown vectors.

EPSS: Низкий
github логотип

GHSA-28q7-rjgm-6w8f

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ipc: mqueue: fix possible memory leak in init_mqueue_fs() commit db7cfc380900 ("ipc: Free mq_sysctls if ipc namespace creation failed") Here's a similar memory leak to the one fixed by the patch above. retire_mq_sysctls need to be called when init_mqueue_fs fails after setup_mq_sysctls.

EPSS: Низкий
github логотип

GHSA-28q7-ffc5-gfjp

около 2 лет назад

Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-28q6-w24q-3hph

почти 2 года назад

Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-28q6-prfq-9g82

почти 4 года назад

Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

EPSS: Низкий
github логотип

GHSA-28q6-f58p-4jf2

почти 4 года назад

Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.

EPSS: Низкий
github логотип

GHSA-28q6-2p45-6wjp

почти 4 года назад

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

EPSS: Низкий
github логотип

GHSA-28q5-v2r3-qj3r

9 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows SQL Injection. This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through 2.4.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-28q5-692w-348q

почти 4 года назад

The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicious Intent URI, in order to invoke private Activities within the Dolphin Browser.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28q5-2h4q-627v

больше 3 лет назад

In mdp, there is a possible out of bounds write due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342114; Issue ID: ALPS07342114.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-28q4-mjmf-52qp

3 месяца назад

The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to change the status of pending WooCommerce orders to paid/completed/on hold.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28q4-j765-rwrg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-28q4-fvwg-fpr2

почти 4 года назад

A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63581671.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28q4-frm2-r7ff

почти 4 года назад

IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-28q3-mx7c-4cc3

больше 3 лет назад

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28q3-cw55-g366

почти 4 года назад

Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0515.

EPSS: Низкий
github логотип

GHSA-28q3-23hp-5939

около 2 лет назад

Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28q2-whhf-cxg5

почти 3 года назад

Visual Studio Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28q9-9c3g-v3f9

lakeFS vulnerable to authenticated users deleting files they are not authorized to delete

больше 3 лет назад
github логотип
GHSA-28q8-f96p-q62j

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-28q8-3hq4-6hmv

Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 Gold through SP6 allows remote authenticated users to gain privileges via unknown vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-28q7-rjgm-6w8f

In the Linux kernel, the following vulnerability has been resolved: ipc: mqueue: fix possible memory leak in init_mqueue_fs() commit db7cfc380900 ("ipc: Free mq_sysctls if ipc namespace creation failed") Here's a similar memory leak to the one fixed by the patch above. retire_mq_sysctls need to be called when init_mqueue_fs fails after setup_mq_sysctls.

0%
Низкий
3 месяца назад
github логотип
GHSA-28q7-ffc5-gfjp

Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

CVSS3: 5.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-28q6-w24q-3hph

Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.

CVSS3: 9.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-28q6-prfq-9g82

Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28q6-f58p-4jf2

Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28q6-2p45-6wjp

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

3%
Низкий
почти 4 года назад
github логотип
GHSA-28q5-v2r3-qj3r

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows SQL Injection. This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through 2.4.0.

CVSS3: 8.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-28q5-692w-348q

The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicious Intent URI, in order to invoke private Activities within the Dolphin Browser.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-28q5-2h4q-627v

In mdp, there is a possible out of bounds write due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07342114; Issue ID: ALPS07342114.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28q4-mjmf-52qp

The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to change the status of pending WooCommerce orders to paid/completed/on hold.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-28q4-j765-rwrg

Cross-site scripting (XSS) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28q4-fvwg-fpr2

A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63581671.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-28q4-frm2-r7ff

IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.

CVSS3: 4.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-28q3-mx7c-4cc3

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read this uninitialized memory from the host, possibly leading to information disclosure.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28q3-cw55-g366

Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0515.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28q3-23hp-5939

Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

CVSS3: 5.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-28q2-whhf-cxg5

Visual Studio Information Disclosure Vulnerability

CVSS3: 5.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу