Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 571

Количество 323 571

github логотип

GHSA-2657-8gwf-j8hg

больше 1 года назад

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of the argument hookId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Средний
github логотип

GHSA-2657-7p36-qgfg

почти 4 года назад

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0606, CVE-2013-0615, CVE-2013-0617, and CVE-2013-0621.

EPSS: Средний
github логотип

GHSA-2657-3c98-63jq

2 месяца назад

esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages

EPSS: Низкий
github логотип

GHSA-2656-55x6-58wg

почти 4 года назад

PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.

EPSS: Средний
github логотип

GHSA-2656-4hrh-2j7f

6 месяцев назад

A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogController of the file /sys/smslog/queryAll. Such manipulation leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2655-q453-22f9

почти 4 года назад

Django Allows Arbitrary URL Generation

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2654-qm47-j43q

больше 2 лет назад

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2654-g3cq-gh34

10 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2653-xjr2-pr7h

почти 4 года назад

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to execute arbitrary code or cause a denial of service (integer underflow and memory corruption) via crafted 3GPP metadata, aka internal bug 20923261, a related issue to CVE-2015-3826.

EPSS: Средний
github логотип

GHSA-2652-m543-h3h5

около 3 лет назад

A vulnerability was found in OCLC-Research OAICat 1.5.61. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.5.62 is able to address this issue. The name of the patch is 6cc65501869fa663bcd24a70b63f41f5cfe6b3e1. It is recommended to upgrade the affected component. The identifier VDB-221489 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2652-fvfq-x6xr

7 месяцев назад

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/appform.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2652-63hr-2gvh

почти 4 года назад

mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2652-4r69-fm9r

почти 4 года назад

SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the author_id parameter in profile.php and (2) the aut_id parameter in userarticles.php. NOTE: the aut_id vector can produce resultant path disclosure if the SQL manipulation is invalid.

EPSS: Низкий
github логотип

GHSA-264x-wjpr-7j93

почти 4 года назад

The Jack'd - Gay Chat & Dating (aka mobi.jackd.android) application 1.9.0a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-264x-w2cv-phgq

около 2 месяцев назад

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-264x-4r27-x5m2

почти 4 года назад

FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-264w-xrr7-6qqg

почти 4 года назад

RCE vulnerability in Jenkins OpenShift Pipeline Plugin

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-264w-p3vv-mx7p

больше 2 лет назад

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-264w-h7gv-xm4m

больше 3 лет назад

A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 22b925449c84faa9b7496abe4f8f5661cb5eb3bf. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216480.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-264w-gw9g-fhgj

больше 3 лет назад

Cross-site Scripting in librenms/librenms

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2657-8gwf-j8hg

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of the argument hookId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
61%
Средний
больше 1 года назад
github логотип
GHSA-2657-7p36-qgfg

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0606, CVE-2013-0615, CVE-2013-0617, and CVE-2013-0621.

13%
Средний
почти 4 года назад
github логотип
GHSA-2657-3c98-63jq

esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages

0%
Низкий
2 месяца назад
github логотип
GHSA-2656-55x6-58wg

PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.

12%
Средний
почти 4 года назад
github логотип
GHSA-2656-4hrh-2j7f

A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogController of the file /sys/smslog/queryAll. Such manipulation leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2655-q453-22f9

Django Allows Arbitrary URL Generation

CVSS3: 7.5
4%
Низкий
почти 4 года назад
github логотип
GHSA-2654-qm47-j43q

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2654-g3cq-gh34

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2653-xjr2-pr7h

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to execute arbitrary code or cause a denial of service (integer underflow and memory corruption) via crafted 3GPP metadata, aka internal bug 20923261, a related issue to CVE-2015-3826.

27%
Средний
почти 4 года назад
github логотип
GHSA-2652-m543-h3h5

A vulnerability was found in OCLC-Research OAICat 1.5.61. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.5.62 is able to address this issue. The name of the patch is 6cc65501869fa663bcd24a70b63f41f5cfe6b3e1. It is recommended to upgrade the affected component. The identifier VDB-221489 was assigned to this vulnerability.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2652-fvfq-x6xr

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/appform.

CVSS3: 5.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-2652-63hr-2gvh

mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.

CVSS3: 7.5
52%
Средний
почти 4 года назад
github логотип
GHSA-2652-4r69-fm9r

SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the author_id parameter in profile.php and (2) the aut_id parameter in userarticles.php. NOTE: the aut_id vector can produce resultant path disclosure if the SQL manipulation is invalid.

1%
Низкий
почти 4 года назад
github логотип
GHSA-264x-wjpr-7j93

The Jack'd - Gay Chat & Dating (aka mobi.jackd.android) application 1.9.0a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-264x-w2cv-phgq

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

CVSS3: 4.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-264x-4r27-x5m2

FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution.

CVSS3: 9.8
13%
Средний
почти 4 года назад
github логотип
GHSA-264w-xrr7-6qqg

RCE vulnerability in Jenkins OpenShift Pipeline Plugin

CVSS3: 8.8
4%
Низкий
почти 4 года назад
github логотип
GHSA-264w-p3vv-mx7p

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.

CVSS3: 4.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-264w-h7gv-xm4m

A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 22b925449c84faa9b7496abe4f8f5661cb5eb3bf. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216480.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-264w-gw9g-fhgj

Cross-site Scripting in librenms/librenms

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу