Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 339

Количество 323 339

github логотип

GHSA-254v-c952-g64w

около 1 года назад

EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-254v-3mjq-6mjm

почти 4 года назад

SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.

EPSS: Низкий
github логотип

GHSA-254r-xffm-9c3g

около 1 года назад

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-254r-9226-v29v

почти 4 года назад

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-254q-rqmw-vx45

около 4 лет назад

Missing Authorization in librenms/librenms

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-254q-rp36-v2m8

почти 4 года назад

Missing XML Validation in Apache CXF

EPSS: Средний
github логотип

GHSA-254q-r25r-fwm9

почти 4 года назад

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-254p-hhvc-rr9q

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-254p-9j5r-3fvc

почти 4 года назад

The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.

EPSS: Низкий
github логотип

GHSA-254m-79rf-mxh7

почти 4 года назад

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

EPSS: Низкий
github логотип

GHSA-254m-3cq9-8624

около 4 лет назад

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-254j-mmc5-qhpx

почти 4 года назад

Smashing Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-254j-3m2w-23xr

почти 4 года назад

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

EPSS: Низкий
github логотип

GHSA-254h-gvgq-x2xg

больше 1 года назад

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-254g-wcpq-w26f

3 дня назад

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-254g-h6q6-4fxv

почти 4 года назад

Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

EPSS: Низкий
github логотип

GHSA-254f-jwvx-j47x

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

EPSS: Низкий
github логотип

GHSA-254f-c2wq-r664

почти 4 года назад

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

EPSS: Низкий
github логотип

GHSA-254c-893v-cfqr

9 месяцев назад

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-254c-2j77-4hhm

больше 3 лет назад

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-254v-c952-g64w

EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-254v-3mjq-6mjm

SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.

1%
Низкий
почти 4 года назад
github логотип
GHSA-254r-xffm-9c3g

Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-254r-9226-v29v

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
7%
Низкий
почти 4 года назад
github логотип
GHSA-254q-rqmw-vx45

Missing Authorization in librenms/librenms

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-254q-rp36-v2m8

Missing XML Validation in Apache CXF

12%
Средний
почти 4 года назад
github логотип
GHSA-254q-r25r-fwm9

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-254p-hhvc-rr9q

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HJYL hmd allows Stored XSS.This issue affects hmd: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-254p-9j5r-3fvc

The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference and application crash) via vectors involving a "dangling pointer" and the JS_ValueToId function.

7%
Низкий
почти 4 года назад
github логотип
GHSA-254m-79rf-mxh7

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

0%
Низкий
почти 4 года назад
github логотип
GHSA-254m-3cq9-8624

Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

CVSS3: 9.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-254j-mmc5-qhpx

Smashing Cross-site Scripting vulnerability

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-254j-3m2w-23xr

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

1%
Низкий
почти 4 года назад
github логотип
GHSA-254h-gvgq-x2xg

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-254g-wcpq-w26f

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user.

CVSS3: 2.6
3 дня назад
github логотип
GHSA-254g-h6q6-4fxv

Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-254f-jwvx-j47x

Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

6%
Низкий
почти 4 года назад
github логотип
GHSA-254f-c2wq-r664

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

0%
Низкий
почти 4 года назад
github логотип
GHSA-254c-893v-cfqr

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-254c-2j77-4hhm

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу