Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4pj2-464p-xg99

больше 4 лет назад

A local escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4phw-xx96-wm6w

больше 4 лет назад

SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to index.php.

EPSS: Низкий
github логотип

GHSA-4phw-6824-6cfp

5 месяцев назад

OpenStack Keystone: Restricted application credentials can create EC2 credentials

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4phw-36g5-73g8

больше 4 лет назад

The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access these endpoints and overwrite the current application configuration. This can be abused for various purposes, including adding new administrative users. Affected Products: UniFi Video Controller v3.9.3 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.9.6 and newer.

EPSS: Низкий
github логотип

GHSA-4phv-whx6-wqqc

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Accommodate VMA splitting Prior to this commit, the gntdev driver code did not handle the following scenario correctly with paravirtualized (PV) Xen domains: * User process sets up a gntdev mapping composed of two grant mappings (i.e., two pages shared by another Xen domain). * User process munmap()s one of the pages. * User process munmap()s the remaining page. * User process exits. In the scenario above, the user process would cause the kernel to log the following messages in dmesg for the first munmap(), and the second munmap() call would result in similar log messages: BUG: Bad page map in process doublemap.test pte:... pmd:... page:0000000057c97bff refcount:1 mapcount:-1 \ mapping:0000000000000000 index:0x0 pfn:... ... page dumped because: bad pte ... file:gntdev fault:0x0 mmap:gntdev_mmap [xen_gntdev] readpage:0x0 ... Call Trace: <TASK> dump_stack_lvl+0x46/0x5e ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4phv-c8x5-787x

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) title and (2) description parameters when creating a task.

EPSS: Низкий
github логотип

GHSA-4phr-gh22-r9hw

больше 2 лет назад

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4phr-gcpq-3v8p

больше 4 лет назад

Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via parameter values for "syncPointList" not being correctly sanitsed.

EPSS: Низкий
github логотип

GHSA-4phr-f8p6-4r74

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Merkulove Selection Lite allows Stored XSS.This issue affects Selection Lite: from n/a through 1.13.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4phr-f525-643q

больше 4 лет назад

A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.

EPSS: Низкий
github логотип

GHSA-4phr-7mh9-vvgh

больше 3 лет назад

In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245770596

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4php-vvmh-7vx6

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua.

EPSS: Низкий
github логотип

GHSA-4php-gphw-3462

почти 3 года назад

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' attribute of the 'pic2' multipart parameter of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4phj-rv4r-gjvp

12 месяцев назад

A vulnerability in HCL HCL MyXalytics allows HTML InjectionThis issue affects HCL MyXalytics: 6.6.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-4phh-x97m-378h

5 месяцев назад

A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argument ID causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4phh-wxc8-pcp3

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the navigation panel, (4) a crafted entry in a certain proxy list, or (5) crafted content in a version.json file.

EPSS: Низкий
github логотип

GHSA-4phg-hpqm-c3j4

почти 4 года назад

Strapi mishandles hidden attributes within admin API responses

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4phc-m7h5-frwr

7 месяцев назад

strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4phc-fq33-39gx

почти 3 года назад

NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4ph9-c9g2-q29q

больше 4 лет назад

Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary directories, and possibly download arbitrary photos, via a .. (dot dot) in the dir parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4pj2-464p-xg99

A local escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address this security vulnerability.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4phw-xx96-wm6w

SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4phw-6824-6cfp

OpenStack Keystone: Restricted application credentials can create EC2 credentials

CVSS3: 3.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4phw-36g5-73g8

The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access these endpoints and overwrite the current application configuration. This can be abused for various purposes, including adding new administrative users. Affected Products: UniFi Video Controller v3.9.3 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.9.6 and newer.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4phv-whx6-wqqc

In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Accommodate VMA splitting Prior to this commit, the gntdev driver code did not handle the following scenario correctly with paravirtualized (PV) Xen domains: * User process sets up a gntdev mapping composed of two grant mappings (i.e., two pages shared by another Xen domain). * User process munmap()s one of the pages. * User process munmap()s the remaining page. * User process exits. In the scenario above, the user process would cause the kernel to log the following messages in dmesg for the first munmap(), and the second munmap() call would result in similar log messages: BUG: Bad page map in process doublemap.test pte:... pmd:... page:0000000057c97bff refcount:1 mapcount:-1 \ mapping:0000000000000000 index:0x0 pfn:... ... page dumped because: bad pte ... file:gntdev fault:0x0 mmap:gntdev_mmap [xen_gntdev] readpage:0x0 ... Call Trace: <TASK> dump_stack_lvl+0x46/0x5e ...

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-4phv-c8x5-787x

Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) title and (2) description parameters when creating a task.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4phr-gh22-r9hw

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4phr-gcpq-3v8p

Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via parameter values for "syncPointList" not being correctly sanitsed.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4phr-f8p6-4r74

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Merkulove Selection Lite allows Stored XSS.This issue affects Selection Lite: from n/a through 1.13.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4phr-f525-643q

A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4phr-7mh9-vvgh

In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245770596

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4php-vvmh-7vx6

Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4php-gphw-3462

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' attribute of the 'pic2' multipart parameter of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
почти 3 года назад
github логотип
GHSA-4phj-rv4r-gjvp

A vulnerability in HCL HCL MyXalytics allows HTML InjectionThis issue affects HCL MyXalytics: 6.6.

CVSS3: 4.6
0%
Низкий
12 месяцев назад
github логотип
GHSA-4phh-x97m-378h

A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argument ID causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVSS3: 3.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4phh-wxc8-pcp3

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a crafted logo URL in the navigation panel, (4) a crafted entry in a certain proxy list, or (5) crafted content in a version.json file.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4phg-hpqm-c3j4

Strapi mishandles hidden attributes within admin API responses

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-4phc-m7h5-frwr

strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().

CVSS3: 6.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-4phc-fq33-39gx

NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4ph9-c9g2-q29q

Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary directories, and possibly download arbitrary photos, via a .. (dot dot) in the dir parameter.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу