Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 339

Количество 323 339

github логотип

GHSA-258p-rm7h-v463

почти 4 года назад

Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-258m-qv8h-28wx

почти 4 года назад

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190986.

EPSS: Низкий
github логотип

GHSA-258m-ggv2-xxv3

почти 3 года назад

When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-258j-hjx4-w4m2

почти 4 года назад

Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-258j-7hr2-w66m

около 2 месяцев назад

Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /api.php endpoint. Attackers can craft a malicious LaTeX payload with shell commands that are executed when processed by the application's tex2png API action.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-258h-f687-4226

больше 1 года назад

PheonixAppAPI has visible Encoding Maps

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-258g-4g7h-f495

почти 4 года назад

Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to conduct XML External E...

EPSS: Низкий
github логотип

GHSA-258f-3vwc-4rjv

больше 2 лет назад

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-258c-h3vm-64r5

9 месяцев назад

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-258c-cqq8-pmrp

13 дней назад

Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.

EPSS: Низкий
github логотип

GHSA-258c-748x-qf4g

12 месяцев назад

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2589-w6xf-983r

больше 4 лет назад

Cross-site scripting in react-bootstrap-table

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2589-r26x-mh8p

почти 4 года назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2589-6chq-5gj4

почти 4 года назад

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.

EPSS: Низкий
github логотип

GHSA-2588-cx6w-6vm6

больше 3 лет назад

Missing permission checks in Jenkins XebiaLabs XL Release Plugin allow capturing credentials

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2587-w93g-63m2

около 4 лет назад

Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin allows reading arbitrary files

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2587-cwc2-rm4f

больше 2 лет назад

Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2586-p5rg-fxqv

около 3 лет назад

A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5382.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2586-jx35-m7r7

почти 4 года назад

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2586-f3p4-hq84

больше 1 года назад

LightGBM Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-258p-rm7h-v463

Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some of these details are obtained from third party information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-258m-qv8h-28wx

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190986.

0%
Низкий
почти 4 года назад
github логотип
GHSA-258m-ggv2-xxv3

When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-258j-hjx4-w4m2

Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-258j-7hr2-w66m

Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /api.php endpoint. Attackers can craft a malicious LaTeX payload with shell commands that are executed when processed by the application's tex2png API action.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-258h-f687-4226

PheonixAppAPI has visible Encoding Maps

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-258g-4g7h-f495

Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver. 1.586L and earlier, GX Works3 Ver. 1.058L and earlier, M_CommDTM-HART Ver. 1.00A, M_CommDTM-IO-Link Ver. 1.02C and earlier, MELFA-Works Ver. 4.3 and earlier, MELSEC-L Flexible High-Speed I/O Control Module Configuration Tool Ver.1.004E and earlier, MELSOFT FieldDeviceConfigurator Ver. 1.03D and earlier, MELSOFT iQ AppPortal Ver. 1.11M and earlier, MELSOFT Navigator Ver. 2.58L and earlier, MI Configurator Ver. 1.003D and earlier, Motion Control Setting Ver. 1.005F and earlier, MR Configurator2 Ver. 1.72A and earlier, MT Works2 Ver. 1.156N and earlier, RT ToolBox2 Ver. 3.72A and earlier, and RT ToolBox3 Ver. 1.50C and earlier) allows an attacker to conduct XML External E...

0%
Низкий
почти 4 года назад
github логотип
GHSA-258f-3vwc-4rjv

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-258c-h3vm-64r5

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-258c-cqq8-pmrp

Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.

0%
Низкий
13 дней назад
github логотип
GHSA-258c-748x-qf4g

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

CVSS3: 4.6
0%
Низкий
12 месяцев назад
github логотип
GHSA-2589-w6xf-983r

Cross-site scripting in react-bootstrap-table

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2589-r26x-mh8p

ChakraCore RCE Vulnerability

CVSS3: 7.5
28%
Средний
почти 4 года назад
github логотип
GHSA-2589-6chq-5gj4

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2588-cx6w-6vm6

Missing permission checks in Jenkins XebiaLabs XL Release Plugin allow capturing credentials

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2587-w93g-63m2

Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin allows reading arbitrary files

CVSS3: 5.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2587-cwc2-rm4f

Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2586-p5rg-fxqv

A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5382.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2586-jx35-m7r7

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2586-f3p4-hq84

LightGBM Remote Code Execution Vulnerability

CVSS3: 8.1
2%
Низкий
больше 1 года назад

Уязвимостей на страницу