Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-xq8v-3x6g-9vpm

почти 4 года назад

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

EPSS: Низкий
github логотип

GHSA-xq8r-r72r-pqwm

больше 5 лет назад

Downloads Resources over HTTP in roslib-socketio

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xq8r-c6vq-9553

почти 4 года назад

The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 does not properly remove duplicate environment variables, which allows local users to pass dangerous variables such as LD_PRELOAD to loading processes, which might be leveraged to gain privileges.

EPSS: Низкий
github логотип

GHSA-xq8r-6v6q-5jcf

почти 4 года назад

Check Point SmartConsole before R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.

EPSS: Низкий
github логотип

GHSA-xq8m-m27q-hg69

больше 2 лет назад

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq8m-cj64-vrmm

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound UniTimetable allows Stored XSS. This issue affects UniTimetable: from n/a through 1.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq8m-cc84-8x5q

почти 4 года назад

SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xq8j-rprv-xmq6

11 месяцев назад

A vulnerability was found in D-Link DIR-619L 2.04B04. It has been declared as critical. This vulnerability affects the function wake_on_lan. The manipulation of the argument mac leads to command injection. The attack can be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xq8j-q3rm-cg9c

почти 4 года назад

A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq8j-8h49-q9q4

почти 4 года назад

An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.

EPSS: Низкий
github логотип

GHSA-xq8j-75w7-8q64

больше 2 лет назад

Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in `vcd_recorder_main`.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq8h-vhf6-2hhq

почти 4 года назад

Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appear to be exploitable via Affected version run the malicious code at startup . This vulnerability appears to have been fixed in 5.2.0 and later .

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq8g-hgh6-87hv

12 дней назад

OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing

EPSS: Низкий
github логотип

GHSA-xq8g-h7mf-47qr

почти 4 года назад

sample.sh in maildirsync 1.1 allows local users to append data to arbitrary files via a symlink attack on a /tmp/maildirsync-*.#####.log temporary file.

EPSS: Низкий
github логотип

GHSA-xq8f-72xr-vw5q

больше 1 года назад

Missing Authorization vulnerability in 10Web 10WebAnalytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAnalytics: from n/a through 1.2.12.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xq8c-wgh5-f4w9

почти 4 года назад

Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq8c-w262-v25h

почти 4 года назад

English/pages_MacUS/wls_set_content.html on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers shows the Wi-Fi PSK passphrase in cleartext, which allows physically proximate attackers to obtain sensitive information by reading the screen of an unattended workstation.

EPSS: Низкий
github логотип

GHSA-xq8c-cw49-4mwf

почти 4 года назад

Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection issue that will result in unauthenticated remote code execution in the username and password fields of the logon prompt. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.

EPSS: Низкий
github логотип

GHSA-xq89-553h-3j4m

почти 4 года назад

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xq88-r3w7-9fw6

больше 1 года назад

Missing Authorization vulnerability in Stephen Sherrard Member Directory and Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Member Directory and Contact Form: from n/a through 1.7.0.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq8v-3x6g-9vpm

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

9%
Низкий
почти 4 года назад
github логотип
GHSA-xq8r-r72r-pqwm

Downloads Resources over HTTP in roslib-socketio

CVSS3: 8.1
1%
Низкий
больше 5 лет назад
github логотип
GHSA-xq8r-c6vq-9553

The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 does not properly remove duplicate environment variables, which allows local users to pass dangerous variables such as LD_PRELOAD to loading processes, which might be leveraged to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq8r-6v6q-5jcf

Check Point SmartConsole before R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq8m-m27q-hg69

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xq8m-cj64-vrmm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound UniTimetable allows Stored XSS. This issue affects UniTimetable: from n/a through 1.1.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xq8m-cc84-8x5q

SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq8j-rprv-xmq6

A vulnerability was found in D-Link DIR-619L 2.04B04. It has been declared as critical. This vulnerability affects the function wake_on_lan. The manipulation of the argument mac leads to command injection. The attack can be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 6.3
1%
Низкий
11 месяцев назад
github логотип
GHSA-xq8j-q3rm-cg9c

A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq8j-8h49-q9q4

An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq8j-75w7-8q64

Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in `vcd_recorder_main`.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq8h-vhf6-2hhq

Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appear to be exploitable via Affected version run the malicious code at startup . This vulnerability appears to have been fixed in 5.2.0 and later .

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq8g-hgh6-87hv

OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing

12 дней назад
github логотип
GHSA-xq8g-h7mf-47qr

sample.sh in maildirsync 1.1 allows local users to append data to arbitrary files via a symlink attack on a /tmp/maildirsync-*.#####.log temporary file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq8f-72xr-vw5q

Missing Authorization vulnerability in 10Web 10WebAnalytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAnalytics: from n/a through 1.2.12.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq8c-wgh5-f4w9

Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xq8c-w262-v25h

English/pages_MacUS/wls_set_content.html on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers shows the Wi-Fi PSK passphrase in cleartext, which allows physically proximate attackers to obtain sensitive information by reading the screen of an unattended workstation.

8%
Низкий
почти 4 года назад
github логотип
GHSA-xq8c-cw49-4mwf

Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection issue that will result in unauthenticated remote code execution in the username and password fields of the logon prompt. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.

4%
Низкий
почти 4 года назад
github логотип
GHSA-xq89-553h-3j4m

In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

CVSS3: 4.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq88-r3w7-9fw6

Missing Authorization vulnerability in Stephen Sherrard Member Directory and Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Member Directory and Contact Form: from n/a through 1.7.0.

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу