Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-27v4-jvv2-r77h

около 4 лет назад

SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field.

EPSS: Низкий
github логотип

GHSA-27v4-h6gj-f3w5

около 4 лет назад

A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-27v4-cjp2-mwc4

около 4 лет назад

Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending crafted TCP packets quickly, aka Bug ID CSCuo42063.

EPSS: Низкий
github логотип

GHSA-27v4-8jv4-3cp6

около 4 лет назад

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

EPSS: Низкий
github логотип

GHSA-27v4-4v2q-w2wg

3 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-27v4-4p5h-63xx

около 4 лет назад

Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.

EPSS: Низкий
github логотип

GHSA-27v3-wp78-r8ww

около 4 лет назад

When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at the very end of the string, the application will mistakenly write the null-byte outside the bounds of its destination. This can result in heap corruption that can lead code execution under the context of the application

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27v3-j68w-q6ph

около 4 лет назад

SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-27v2-398x-f74x

около 4 лет назад

MAGMI cross-site scripting (XSS)

EPSS: Средний
github логотип

GHSA-27rx-wrqr-qj3v

около 4 лет назад

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

EPSS: Низкий
github логотип

GHSA-27rx-w643-mrjg

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27rv-vgm8-cv35

больше 2 лет назад

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27rv-f8p8-59gg

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: afs: Fix corruption in reads at fpos 2G-4G from an OpenAFS server AFS-3 has two data fetch RPC variants, FS.FetchData and FS.FetchData64, and Linux's afs client switches between them when talking to a non-YFS server if the read size, the file position or the sum of the two have the upper 32 bits set of the 64-bit value. This is a problem, however, since the file position and length fields of FS.FetchData are *signed* 32-bit values. Fix this by capturing the capability bits obtained from the fileserver when it's sent an FS.GetCapabilities RPC, rather than just discarding them, and then picking out the VICED_CAPABILITY_64BITFILES flag. This can then be used to decide whether to use FS.FetchData or FS.FetchData64 - and also FS.StoreData or FS.StoreData64 - rather than using upper_32_bits() to switch on the parameter values. This capabilities flag could also be used to limit the maximum size of the file, but all s...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27rr-v6v6-57q8

около 4 лет назад

Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.

EPSS: Низкий
github логотип

GHSA-27rr-r4mx-xr9r

около 4 лет назад

In BlackBerry QNX Software Development Platform (SDP) 6.6.0, the default configuration of the QNX SDP system did not in all circumstances prevent attackers from modifying the GOT or PLT tables with buffer overflow attacks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27rq-4943-qcwp

больше 4 лет назад

Insertion of Sensitive Information into Log File in Hashicorp go-getter

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27rp-rjv6-3rv3

12 месяцев назад

The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-27rp-767p-m9wx

около 4 лет назад

PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.

EPSS: Низкий
github логотип

GHSA-27rm-rrv9-67mv

4 месяца назад

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account for standard Shell command substitution Ridvay Code (specifically$(...)and backticks ...). An attacker can construct a command such as git log --grep="$(malicious_command)", forcing Syntx to misidentify it as a safe git operation and automatically approve it. The underlying Shell prioritizes the execution of the malicious code injected within the arguments, resulting in Remote Code Execution without any user interaction.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27rm-pvpp-228f

почти 2 года назад

A stored Cross-Site Scripting (XSS) vulnerability has been identified in SMSEagle software version < 6.0. The vulnerability arises because the application did not properly sanitize user input in the SMS messages in the inbox. This could allow an attacker to inject malicious JavaScript code into an SMS message, which gets executed when the SMS is viewed and specially interacted in web-GUI.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27v4-jvv2-r77h

SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field.

1%
Низкий
около 4 лет назад
github логотип
GHSA-27v4-h6gj-f3w5

A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).

CVSS3: 4.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-27v4-cjp2-mwc4

Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending crafted TCP packets quickly, aka Bug ID CSCuo42063.

3%
Низкий
около 4 лет назад
github логотип
GHSA-27v4-8jv4-3cp6

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

1%
Низкий
около 4 лет назад
github логотип
GHSA-27v4-4v2q-w2wg

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

3 месяца назад
github логотип
GHSA-27v4-4p5h-63xx

Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-27v3-wp78-r8ww

When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at the very end of the string, the application will mistakenly write the null-byte outside the bounds of its destination. This can result in heap corruption that can lead code execution under the context of the application

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-27v3-j68w-q6ph

SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-27v2-398x-f74x

MAGMI cross-site scripting (XSS)

14%
Средний
около 4 лет назад
github логотип
GHSA-27rx-wrqr-qj3v

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

2%
Низкий
около 4 лет назад
github логотип
GHSA-27rx-w643-mrjg

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-27rv-vgm8-cv35

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27rv-f8p8-59gg

In the Linux kernel, the following vulnerability has been resolved: afs: Fix corruption in reads at fpos 2G-4G from an OpenAFS server AFS-3 has two data fetch RPC variants, FS.FetchData and FS.FetchData64, and Linux's afs client switches between them when talking to a non-YFS server if the read size, the file position or the sum of the two have the upper 32 bits set of the 64-bit value. This is a problem, however, since the file position and length fields of FS.FetchData are *signed* 32-bit values. Fix this by capturing the capability bits obtained from the fileserver when it's sent an FS.GetCapabilities RPC, rather than just discarding them, and then picking out the VICED_CAPABILITY_64BITFILES flag. This can then be used to decide whether to use FS.FetchData or FS.FetchData64 - and also FS.StoreData or FS.StoreData64 - rather than using upper_32_bits() to switch on the parameter values. This capabilities flag could also be used to limit the maximum size of the file, but all s...

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-27rr-v6v6-57q8

Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.

3%
Низкий
около 4 лет назад
github логотип
GHSA-27rr-r4mx-xr9r

In BlackBerry QNX Software Development Platform (SDP) 6.6.0, the default configuration of the QNX SDP system did not in all circumstances prevent attackers from modifying the GOT or PLT tables with buffer overflow attacks.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-27rq-4943-qcwp

Insertion of Sensitive Information into Log File in Hashicorp go-getter

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-27rp-rjv6-3rv3

The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-27rp-767p-m9wx

PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-27rm-rrv9-67mv

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account for standard Shell command substitution Ridvay Code (specifically$(...)and backticks ...). An attacker can construct a command such as git log --grep="$(malicious_command)", forcing Syntx to misidentify it as a safe git operation and automatically approve it. The underlying Shell prioritizes the execution of the malicious code injected within the arguments, resulting in Remote Code Execution without any user interaction.

CVSS3: 9.8
2%
Низкий
4 месяца назад
github логотип
GHSA-27rm-pvpp-228f

A stored Cross-Site Scripting (XSS) vulnerability has been identified in SMSEagle software version < 6.0. The vulnerability arises because the application did not properly sanitize user input in the SMS messages in the inbox. This could allow an attacker to inject malicious JavaScript code into an SMS message, which gets executed when the SMS is viewed and specially interacted in web-GUI.

CVSS3: 6.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу