Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 322 267

Количество 322 267

github логотип

GHSA-22jv-36fh-m28x

больше 1 года назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22jr-vc7j-g762

около 6 лет назад

Potential buffer overflow in psd-tools

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22jr-qpvv-v9f3

6 месяцев назад

A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-22jr-jqv2-c6r8

5 месяцев назад

Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .  All firmware versions with the Serial Number from 2000 to 5166

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-22jr-f6pc-522x

около 1 месяца назад

Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22jq-crhx-w9j5

почти 4 года назад

The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.

EPSS: Низкий
github логотип

GHSA-22jq-62mj-8hw3

почти 4 года назад

Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.

EPSS: Низкий
github логотип

GHSA-22jq-22rq-52q5

почти 4 года назад

Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220.

EPSS: Низкий
github логотип

GHSA-22jp-w3cg-gvmm

7 месяцев назад

Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature

EPSS: Низкий
github логотип

GHSA-22jp-m5f3-q68p

почти 4 года назад

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22jm-p2vv-j2hc

почти 4 года назад

Plone XSS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22jm-gmg3-6r8v

почти 4 года назад

Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter.

EPSS: Низкий
github логотип

GHSA-22jm-4hxw-35jf

почти 4 года назад

OpenStack Nova can leak consoleauth token into log files

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-22jj-r264-9ffc

7 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection allows SQL Injection. This issue affects ZIP Code Based Content Protection: from n/a through 1.0.0.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-22jj-744v-92v5

около 4 лет назад

livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

EPSS: Низкий
github логотип

GHSA-22jh-hqf7-v4mw

почти 4 года назад

Windows Network Address Translation (NAT) Denial of Service Vulnerability.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-22jh-6gx8-f944

почти 4 года назад

Elastic APM agent for Python client CGI proxy redirection flaw

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-22jh-5463-4m46

почти 4 года назад

Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.

EPSS: Низкий
github логотип

GHSA-22jg-rc3r-96wc

почти 4 года назад

Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-22jf-gccc-jpfh

почти 4 года назад

VCFTools vcfools prior to version 0.1.15 is affected by: Heap Use-After-Free. The impact is: Denial of Service or possibly unspecified impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22jv-36fh-m28x

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-22jr-vc7j-g762

Potential buffer overflow in psd-tools

CVSS3: 9.8
0%
Низкий
около 6 лет назад
github логотип
GHSA-22jr-qpvv-v9f3

A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-22jr-jqv2-c6r8

Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .  All firmware versions with the Serial Number from 2000 to 5166

CVSS3: 9.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-22jr-f6pc-522x

Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-22jq-crhx-w9j5

The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22jq-62mj-8hw3

Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.

6%
Низкий
почти 4 года назад
github логотип
GHSA-22jq-22rq-52q5

Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220.

1%
Низкий
почти 4 года назад
github логотип
GHSA-22jp-w3cg-gvmm

Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature

0%
Низкий
7 месяцев назад
github логотип
GHSA-22jp-m5f3-q68p

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 6.5
7%
Низкий
почти 4 года назад
github логотип
CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-22jm-gmg3-6r8v

Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-22jm-4hxw-35jf

OpenStack Nova can leak consoleauth token into log files

CVSS3: 3.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-22jj-r264-9ffc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection allows SQL Injection. This issue affects ZIP Code Based Content Protection: from n/a through 1.0.0.

CVSS3: 7.6
0%
Низкий
7 месяцев назад
github логотип
GHSA-22jj-744v-92v5

livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

0%
Низкий
около 4 лет назад
github логотип
GHSA-22jh-hqf7-v4mw

Windows Network Address Translation (NAT) Denial of Service Vulnerability.

CVSS3: 7.5
24%
Средний
почти 4 года назад
github логотип
GHSA-22jh-6gx8-f944

Elastic APM agent for Python client CGI proxy redirection flaw

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-22jh-5463-4m46

Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22jg-rc3r-96wc

Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22jf-gccc-jpfh

VCFTools vcfools prior to version 0.1.15 is affected by: Heap Use-After-Free. The impact is: Denial of Service or possibly unspecified impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file.

почти 4 года назад

Уязвимостей на страницу