Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 805

Количество 323 805

github логотип

GHSA-2736-j3p7-98mc

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in EzUpload Pro 2.10 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) form.php, (2) customize.php, and (3) initialize.php.

EPSS: Низкий
github логотип

GHSA-2736-7x8v-6v3p

почти 4 года назад

Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive information via a brute-force attack on a weakly encrypted e-mail message.

EPSS: Низкий
github логотип

GHSA-2734-8vv8-c662

около 2 лет назад

Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2733-h98q-64p4

3 месяца назад

A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/add_admin.php. Executing manipulation of the argument Username can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2733-6c58-pf27

2 месяца назад

deepHas vulnerable to Prototype Pollution via constructor.prototype

EPSS: Низкий
github логотип

GHSA-2732-hqjr-j84c

3 месяца назад

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-272x-wj83-g7hx

почти 4 года назад

The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by leveraging administrative access to these domain names, as demonstrated by alarm and log information.

EPSS: Низкий
github логотип

GHSA-272x-qrpw-27mm

около 1 года назад

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-272x-qj5p-5hgv

почти 4 года назад

NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit.

EPSS: Низкий
github логотип

GHSA-272x-j33v-vxm7

почти 4 года назад

Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-272x-gpf6-6c9f

8 дней назад

NVIDIA Triton Inference Server contains a vulnerability in the HTTP endpoint where an attacker may cause a denial of service by providing a large compressed payload. A successful exploit of this vulnerability may lead to denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-272v-4hpv-gq59

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ángel C. Simple Google Static Map allows DOM-Based XSS. This issue affects Simple Google Static Map: from n/a through 1.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-272r-gvjr-j5qh

почти 4 года назад

Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.

EPSS: Низкий
github логотип

GHSA-272r-9r62-xgwc

больше 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, where group runners information was disclosed to unauthorised group members.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-272r-9398-x32j

больше 2 лет назад

A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially allow an attacker to achieve read-only access to the server's filesystem.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-272r-5fmj-xph5

почти 4 года назад

Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a resume photo, then accessing it via a direct request to the file in jobseekers/jobseeker_profile_images.

EPSS: Низкий
github логотип

GHSA-272r-38vw-2pf9

почти 4 года назад

Stack-based buffer overflow in Ares FileShare 1.1 allows remote attackers or local users to execute arbitrary code via a (1) long history parameter in the configuration file (ares.conf) or (2) long search string.

EPSS: Низкий
github логотип

GHSA-272q-hvx6-q97c

почти 4 года назад

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-272q-6m92-rrfr

почти 4 года назад

Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.

EPSS: Средний
github логотип

GHSA-272q-3rfm-9jxh

около 3 лет назад

The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2736-j3p7-98mc

Multiple PHP remote file inclusion vulnerabilities in EzUpload Pro 2.10 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) form.php, (2) customize.php, and (3) initialize.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2736-7x8v-6v3p

Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive information via a brute-force attack on a weakly encrypted e-mail message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2734-8vv8-c662

Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.

CVSS3: 8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2733-h98q-64p4

A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/add_admin.php. Executing manipulation of the argument Username can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2733-6c58-pf27

deepHas vulnerable to Prototype Pollution via constructor.prototype

0%
Низкий
2 месяца назад
github логотип
GHSA-2732-hqjr-j84c

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.

CVSS3: 10
0%
Низкий
3 месяца назад
github логотип
GHSA-272x-wj83-g7hx

The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by leveraging administrative access to these domain names, as demonstrated by alarm and log information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-272x-qrpw-27mm

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.8
2%
Низкий
около 1 года назад
github логотип
GHSA-272x-qj5p-5hgv

NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit.

0%
Низкий
почти 4 года назад
github логотип
GHSA-272x-j33v-vxm7

Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-272x-gpf6-6c9f

NVIDIA Triton Inference Server contains a vulnerability in the HTTP endpoint where an attacker may cause a denial of service by providing a large compressed payload. A successful exploit of this vulnerability may lead to denial of service.

CVSS3: 7.5
0%
Низкий
8 дней назад
github логотип
GHSA-272v-4hpv-gq59

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ángel C. Simple Google Static Map allows DOM-Based XSS. This issue affects Simple Google Static Map: from n/a through 1.0.1.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-272r-gvjr-j5qh

Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.

0%
Низкий
почти 4 года назад
github логотип
GHSA-272r-9r62-xgwc

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, where group runners information was disclosed to unauthorised group members.

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-272r-9398-x32j

A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditions, this could potentially allow an attacker to achieve read-only access to the server's filesystem.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-272r-5fmj-xph5

Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a resume photo, then accessing it via a direct request to the file in jobseekers/jobseeker_profile_images.

4%
Низкий
почти 4 года назад
github логотип
GHSA-272r-38vw-2pf9

Stack-based buffer overflow in Ares FileShare 1.1 allows remote attackers or local users to execute arbitrary code via a (1) long history parameter in the configuration file (ares.conf) or (2) long search string.

4%
Низкий
почти 4 года назад
github логотип
GHSA-272q-hvx6-q97c

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-272q-6m92-rrfr

Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.

45%
Средний
почти 4 года назад
github логотип
GHSA-272q-3rfm-9jxh

The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.

CVSS3: 4.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу