Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-xqrh-mp77-29j5

почти 4 года назад

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqrh-6pmp-4rgf

почти 4 года назад

Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.

EPSS: Низкий
github логотип

GHSA-xqrh-6c7q-6xm3

почти 4 года назад

The sell function of a smart contract implementation for R Time Token v3 (RS) (Contract Name: RTokenMain), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqrg-hj9q-p9jx

почти 4 года назад

The Melodigram (aka com.minusdegree.melodigramandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xqrg-6p99-hc76

4 месяца назад

Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqrc-qw3v-43mc

около 3 лет назад

Not used in 2022

EPSS: Низкий
github логотип

GHSA-xqrc-jpv5-hccp

8 месяцев назад

XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. The flaw resides in the upload functionality, which fails to properly validate or restrict uploaded file types. By crafting a multipart/form-data POST request, an attacker can upload a .php file directly into the web-accessible files/ directory and trigger its execution via a subsequent GET request.

EPSS: Средний
github логотип

GHSA-xqrc-68p6-rf7p

почти 3 года назад

Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqrc-6556-5gcq

11 месяцев назад

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqrc-4v76-jfhh

6 месяцев назад

A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xqr8-7jwr-rhp7

больше 2 лет назад

Removal of e-Tugra root certificate

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqr7-fvpx-w934

больше 3 лет назад

In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqr7-5xxr-2vp5

почти 4 года назад

The Maleficent Free Fall (aka com.disney.maleficent_goo) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xqr7-4vq4-5j5j

4 месяца назад

Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xqr6-xwgv-r3rg

почти 4 года назад

PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rInfo[content] parameter.

EPSS: Низкий
github логотип

GHSA-xqr6-h56f-8r2j

почти 4 года назад

DCMTK through 3.6.6 does not handle memory free properly. The malloced memory for storing all file information are recorded in a global variable LST and are not freed properly. Sending specific requests to the dcmqrdb program can incur a memory leak. An attacker can use it to launch a DoS attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqr6-6vvj-h9gc

почти 4 года назад

The Passcode Lock implementation in Apple iOS before 6.1.3 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging an error in the emergency-call feature.

EPSS: Низкий
github логотип

GHSA-xqr4-wc4c-36xj

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register() bcm_sf2_mdio_register() calls of_phy_find_device() and then phy_device_remove() in a loop to remove existing PHY devices. of_phy_find_device() eventually calls bus_find_device(), which calls get_device() on the returned struct device * to increment the refcount. The current implementation does not decrement the refcount, which causes memory leak. This commit adds the missing phy_device_free() call to decrement the refcount via put_device() to balance the refcount.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqr4-7mxg-hjgj

почти 4 года назад

oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xqr3-vfxg-3qjr

почти 4 года назад

A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may compromise the device's availability by performing multiple initial VPN requests.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqrh-mp77-29j5

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqrh-6pmp-4rgf

Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqrh-6c7q-6xm3

The sell function of a smart contract implementation for R Time Token v3 (RS) (Contract Name: RTokenMain), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqrg-hj9q-p9jx

The Melodigram (aka com.minusdegree.melodigramandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqrg-6p99-hc76

Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-xqrc-qw3v-43mc

Not used in 2022

около 3 лет назад
github логотип
GHSA-xqrc-jpv5-hccp

XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. The flaw resides in the upload functionality, which fails to properly validate or restrict uploaded file types. By crafting a multipart/form-data POST request, an attacker can upload a .php file directly into the web-accessible files/ directory and trigger its execution via a subsequent GET request.

67%
Средний
8 месяцев назад
github логотип
GHSA-xqrc-68p6-rf7p

Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xqrc-6556-5gcq

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-xqrc-4v76-jfhh

A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xqr8-7jwr-rhp7

Removal of e-Tugra root certificate

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqr7-fvpx-w934

In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xqr7-5xxr-2vp5

The Maleficent Free Fall (aka com.disney.maleficent_goo) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqr7-4vq4-5j5j

Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.

CVSS3: 8.1
0%
Низкий
4 месяца назад
github логотип
GHSA-xqr6-xwgv-r3rg

PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rInfo[content] parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-xqr6-h56f-8r2j

DCMTK through 3.6.6 does not handle memory free properly. The malloced memory for storing all file information are recorded in a global variable LST and are not freed properly. Sending specific requests to the dcmqrdb program can incur a memory leak. An attacker can use it to launch a DoS attack.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqr6-6vvj-h9gc

The Passcode Lock implementation in Apple iOS before 6.1.3 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging an error in the emergency-call feature.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqr4-wc4c-36xj

In the Linux kernel, the following vulnerability has been resolved: net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register() bcm_sf2_mdio_register() calls of_phy_find_device() and then phy_device_remove() in a loop to remove existing PHY devices. of_phy_find_device() eventually calls bus_find_device(), which calls get_device() on the returned struct device * to increment the refcount. The current implementation does not decrement the refcount, which causes memory leak. This commit adds the missing phy_device_free() call to decrement the refcount via put_device() to balance the refcount.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqr4-7mxg-hjgj

oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqr3-vfxg-3qjr

A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may compromise the device's availability by performing multiple initial VPN requests.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу