Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-3mq7-3ggv-qpgc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.

EPSS: Низкий
github логотип

GHSA-3mq6-q8x8-h9pp

больше 4 лет назад

Windows Graphics Component Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mq5-m58g-fgj3

больше 4 лет назад

An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.

EPSS: Низкий
github логотип

GHSA-3mq5-fq9h-gj7j

около 4 лет назад

Duplicate Advisory: Denial of Service due to parser crash

EPSS: Низкий
github логотип

GHSA-3mq5-2hmg-6cr7

около 3 лет назад

A stack based out-of-bounds write flaw was found in the netfilter subsystem in the Linux kernel. If the expression length is a multiple of 4 (register size), the `nft_exthdr_eval` family of functions writes 4 NULL bytes past the end of the `regs` argument, leading to stack corruption and potential information disclosure or a denial of service.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mq4-x52h-fcwc

больше 4 лет назад

ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3mpx-xv5p-92mv

около 1 месяца назад

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mpv-xg32-wjg6

больше 4 лет назад

The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

EPSS: Средний
github логотип

GHSA-3mpv-vc7v-xpc6

больше 4 лет назад

ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.

EPSS: Низкий
github логотип

GHSA-3mpv-gr2q-vh5j

больше 4 лет назад

A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mpv-g3cv-rx7h

больше 4 лет назад

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mpv-3cfr-mgjj

больше 4 лет назад

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

EPSS: Низкий
github логотип

GHSA-3mpr-vw5v-hq89

больше 4 лет назад

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mpr-qj98-wfp9

больше 4 лет назад

The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.

EPSS: Низкий
github логотип

GHSA-3mpr-hq3p-49h9

около 8 лет назад

Prototype Pollution in mixin-deep

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mpr-9r86-mfv2

больше 2 лет назад

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mpq-x397-f3cg

больше 4 лет назад

FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI.

EPSS: Низкий
github логотип

GHSA-3mpq-f59x-83gx

больше 4 лет назад

Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.

EPSS: Низкий
github логотип

GHSA-3mpq-55rm-gc7g

больше 4 лет назад

SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.

EPSS: Низкий
github логотип

GHSA-3mpp-xhfx-rv7h

больше 3 лет назад

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mq7-3ggv-qpgc

Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mq6-q8x8-h9pp

Windows Graphics Component Information Disclosure Vulnerability

CVSS3: 5.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3mq5-m58g-fgj3

An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mq5-fq9h-gj7j

Duplicate Advisory: Denial of Service due to parser crash

около 4 лет назад
github логотип
GHSA-3mq5-2hmg-6cr7

A stack based out-of-bounds write flaw was found in the netfilter subsystem in the Linux kernel. If the expression length is a multiple of 4 (register size), the `nft_exthdr_eval` family of functions writes 4 NULL bytes past the end of the `regs` argument, leading to stack corruption and potential information disclosure or a denial of service.

CVSS3: 6.1
около 3 лет назад
github логотип
GHSA-3mq4-x52h-fcwc

ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.

CVSS3: 7.5
45%
Средний
больше 4 лет назад
github логотип
GHSA-3mpx-xv5p-92mv

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3mpv-xg32-wjg6

The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

13%
Средний
больше 4 лет назад
github логотип
GHSA-3mpv-vc7v-xpc6

ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpv-gr2q-vh5j

A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpv-g3cv-rx7h

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.

CVSS3: 5.3
6%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpv-3cfr-mgjj

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpr-vw5v-hq89

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpr-qj98-wfp9

The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpr-hq3p-49h9

Prototype Pollution in mixin-deep

CVSS3: 8.8
2%
Низкий
около 8 лет назад
github логотип
GHSA-3mpr-9r86-mfv2

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3mpq-x397-f3cg

FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpq-f59x-83gx

Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpq-55rm-gc7g

SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpp-xhfx-rv7h

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу