Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-223m-fhfm-47hr

около 4 лет назад

PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.

EPSS: Низкий
github логотип

GHSA-223m-4rfp-646h

11 месяцев назад

Jenkins is missing a permission check in the authenticated users' profile menu

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-223j-w649-gh98

10 месяцев назад

Server-Side Request Forgery (SSRF) vulnerability in Alex Content Mask allows Server Side Request Forgery. This issue affects Content Mask: from n/a through 1.8.5.2.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-223j-8f9f-qhc5

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Block Pack allows Reflected XSS. This issue affects WP Block Pack: from n/a through 1.1.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-223j-7cj4-4cw7

больше 1 года назад

Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-223j-4rm8-mrmf

больше 1 года назад

Next.js may leak x-middleware-subrequest-id to external hosts

EPSS: Низкий
github логотип

GHSA-223h-r336-f673

около 3 лет назад

Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 allows attackers to escalate privileges to root via supplying a crafted binary to the target system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-223h-642r-2f6v

9 дней назад

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-223g-f5mq-gw33

3 месяца назад

OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover

EPSS: Низкий
github логотип

GHSA-223g-8w3x-98wr

около 3 лет назад

Snowflake Connector .Net Command Injection

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-223f-gch2-xvq3

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding request fails (e.g. wrong password), the error path unconditionally sets sess->state = SMB2_SESSION_EXPIRED. However, during binding, sess points to the target session looked up via ksmbd_session_lookup_slowpath() -- which belongs to another connection's user. This allows a remote attacker to invalidate any active session by simply sending a binding request with a wrong password (DoS). Fix this by skipping session expiration when the failed request was a binding attempt, since the session does not belong to the current connection. The reference taken by ksmbd_session_lookup_slowpath() is still correctly released via ksmbd_user_session_put().

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-223f-f395-r8rw

7 месяцев назад

A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-223c-vgc5-mrv4

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.

EPSS: Низкий
github логотип

GHSA-223c-8f3h-q9f9

9 месяцев назад

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2239-q247-vvp8

около 4 лет назад

Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary code via the ReturnConnection method in (1) CM_ADOConnection.dll, (2) CM_AddressInfoDBC.dll, and (3) CM_RecordingLocationDBC.dll, related to improper dereferencing. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2239-pmp7-cm44

больше 2 лет назад

A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/view-appointment-detail.php. The manipulation of the argument editid leads to improper control of resource identifiers. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-262226 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2239-h2rh-5fp9

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2238-xc5r-v9hj

5 месяцев назад

@tinacms/graphql has a Path Traversal issue

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2238-539f-qq79

почти 4 года назад

A vulnerability, which was classified as problematic, was found in oretnom23 Fast Food Ordering System. This affects an unknown part of the component Menu List Page. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205725 was assigned to this vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2237-w692-94pv

около 4 лет назад

libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-223m-fhfm-47hr

PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.

6%
Низкий
около 4 лет назад
github логотип
GHSA-223m-4rfp-646h

Jenkins is missing a permission check in the authenticated users' profile menu

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-223j-w649-gh98

Server-Side Request Forgery (SSRF) vulnerability in Alex Content Mask allows Server Side Request Forgery. This issue affects Content Mask: from n/a through 1.8.5.2.

CVSS3: 6.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-223j-8f9f-qhc5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Block Pack allows Reflected XSS. This issue affects WP Block Pack: from n/a through 1.1.6.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-223j-7cj4-4cw7

Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.

CVSS3: 9.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-223j-4rm8-mrmf

Next.js may leak x-middleware-subrequest-id to external hosts

0%
Низкий
больше 1 года назад
github логотип
GHSA-223h-r336-f673

Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 allows attackers to escalate privileges to root via supplying a crafted binary to the target system.

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-223h-642r-2f6v

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.

CVSS3: 6.8
0%
Низкий
9 дней назад
github логотип
GHSA-223g-f5mq-gw33

OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover

0%
Низкий
3 месяца назад
github логотип
GHSA-223g-8w3x-98wr

Snowflake Connector .Net Command Injection

CVSS3: 7.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-223f-gch2-xvq3

In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding request fails (e.g. wrong password), the error path unconditionally sets sess->state = SMB2_SESSION_EXPIRED. However, during binding, sess points to the target session looked up via ksmbd_session_lookup_slowpath() -- which belongs to another connection's user. This allows a remote attacker to invalidate any active session by simply sending a binding request with a wrong password (DoS). Fix this by skipping session expiration when the failed request was a binding attempt, since the session does not belong to the current connection. The reference taken by ksmbd_session_lookup_slowpath() is still correctly released via ksmbd_user_session_put().

CVSS3: 8.2
0%
Низкий
3 месяца назад
github логотип
GHSA-223f-f395-r8rw

A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-223c-vgc5-mrv4

Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.

1%
Низкий
около 4 лет назад
github логотип
GHSA-223c-8f3h-q9f9

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2239-q247-vvp8

Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary code via the ReturnConnection method in (1) CM_ADOConnection.dll, (2) CM_AddressInfoDBC.dll, and (3) CM_RecordingLocationDBC.dll, related to improper dereferencing. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2239-pmp7-cm44

A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/view-appointment-detail.php. The manipulation of the argument editid leads to improper control of resource identifiers. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-262226 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2239-h2rh-5fp9

Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2238-xc5r-v9hj

@tinacms/graphql has a Path Traversal issue

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2238-539f-qq79

A vulnerability, which was classified as problematic, was found in oretnom23 Fast Food Ordering System. This affects an unknown part of the component Menu List Page. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205725 was assigned to this vulnerability.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2237-w692-94pv

libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.

CVSS3: 7.5
4%
Низкий
около 4 лет назад

Уязвимостей на страницу