Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2g5p-9p7q-76jj

10 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-2g5m-5chx-p2ww

около 4 лет назад

A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8383.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g5j-j89x-7x2c

около 4 лет назад

Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

EPSS: Низкий
github логотип

GHSA-2g5j-5x95-r6hr

больше 3 лет назад

Unsafe tar unpacking in HashiCorp go-slug

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2g5h-j52x-gmg7

12 месяцев назад

A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown functionality of the component LocalStorage Handler. The manipulation of the argument projectID leads to authorization bypass. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2g5g-hcgh-q3rp

6 месяцев назад

DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2g5f-835h-7qjr

около 4 лет назад

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).

EPSS: Средний
github логотип

GHSA-2g5f-4p47-mx3m

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix cleanup after dev_set_name() If dev_set_name() fails, we leak nvmem->wp_gpio as the cleanup does not put this. While a minimal fix for this would be to add the gpiod_put() call, we can do better if we split device_register(), and use the tested nvmem_release() cleanup code by initialising the device early, and putting the device. This results in a slightly larger fix, but results in clear code. Note: this patch depends on "nvmem: core: initialise nvmem->id early" and "nvmem: core: remove nvmem_config wp_gpio". [Srini: Fixed subject line and error code handing with wp_gpio while applying.]

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g5c-v49p-7c89

2 месяца назад

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to product.php with union-based SQL injection payloads in the id parameter to extract sensitive database information including usernames and database names.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2g5c-228j-p52x

почти 4 года назад

XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection

CVSS3: 9.9
EPSS: Высокий
github логотип

GHSA-2g59-pjjw-j55p

около 4 лет назад

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-2g59-m95p-pgfq

6 месяцев назад

Chainlit contain a server-side request forgery (SSRF) vulnerability

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2g58-j9wc-pg3h

около 4 лет назад

The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2g58-2x39-qh45

около 2 лет назад

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g58-2r94-f674

около 2 лет назад

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g56-8jc9-jg87

11 месяцев назад

In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2g56-7jv7-wxxq

около 4 лет назад

Missing Cryptographic Step in OWASP Enterprise Security API for Java

EPSS: Низкий
github логотип

GHSA-2g55-8gcv-fc24

11 месяцев назад

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g55-8535-gp6f

больше 2 лет назад

Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2g55-7wqw-h2c5

около 4 лет назад

Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g5p-9p7q-76jj

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

CVSS3: 8.7
1%
Низкий
10 месяцев назад
github логотип
GHSA-2g5m-5chx-p2ww

A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8383.

CVSS3: 4.3
4%
Низкий
около 4 лет назад
github логотип
GHSA-2g5j-j89x-7x2c

Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2g5j-5x95-r6hr

Unsafe tar unpacking in HashiCorp go-slug

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2g5h-j52x-gmg7

A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown functionality of the component LocalStorage Handler. The manipulation of the argument projectID leads to authorization bypass. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-2g5g-hcgh-q3rp

DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes

CVSS3: 7.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-2g5f-835h-7qjr

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).

15%
Средний
около 4 лет назад
github логотип
GHSA-2g5f-4p47-mx3m

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix cleanup after dev_set_name() If dev_set_name() fails, we leak nvmem->wp_gpio as the cleanup does not put this. While a minimal fix for this would be to add the gpiod_put() call, we can do better if we split device_register(), and use the tested nvmem_release() cleanup code by initialising the device early, and putting the device. This results in a slightly larger fix, but results in clear code. Note: this patch depends on "nvmem: core: initialise nvmem->id early" and "nvmem: core: remove nvmem_config wp_gpio". [Srini: Fixed subject line and error code handing with wp_gpio while applying.]

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g5c-v49p-7c89

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to product.php with union-based SQL injection payloads in the id parameter to extract sensitive database information including usernames and database names.

CVSS3: 8.2
0%
Низкий
2 месяца назад
github логотип
GHSA-2g5c-228j-p52x

XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection

CVSS3: 9.9
74%
Высокий
почти 4 года назад
github логотип
GHSA-2g59-pjjw-j55p

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVSS3: 7.2
66%
Средний
около 4 лет назад
github логотип
GHSA-2g59-m95p-pgfq

Chainlit contain a server-side request forgery (SSRF) vulnerability

CVSS3: 7.7
4%
Низкий
6 месяцев назад
github логотип
GHSA-2g58-j9wc-pg3h

The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2g58-2x39-qh45

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-2g58-2r94-f674

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.

CVSS3: 4.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-2g56-8jc9-jg87

In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2g56-7jv7-wxxq

Missing Cryptographic Step in OWASP Enterprise Security API for Java

2%
Низкий
около 4 лет назад
github логотип
GHSA-2g55-8gcv-fc24

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS3: 5.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-2g55-8535-gp6f

Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2g55-7wqw-h2c5

Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

CVSS3: 5.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.