Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-2567-843w-hp69

около 1 года назад

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file /intranet/educar_aluno_beneficio_lst.php of the component Student Benefits Registration. The manipulation of the argument Benefício leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2567-3r9v-7m92

больше 3 лет назад

Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2566-p8jv-48q3

больше 4 лет назад

The sell function of a smart contract implementation for MyYLC, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2566-fq23-672g

больше 2 лет назад

An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2566-7hcg-m8r2

больше 4 лет назад

SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL commands via the orderid parameter in a status action.

EPSS: Низкий
github логотип

GHSA-2565-pm5h-w9cc

больше 4 лет назад

HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2565-9vww-cf73

около 2 лет назад

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2565-6q46-9x5v

3 месяца назад

Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2564-4rf9-wv93

больше 4 лет назад

Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.

EPSS: Низкий
github логотип

GHSA-2563-x4h3-pq75

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KentoThemes Justified Image Gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2563-r73r-7cq9

больше 4 лет назад

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2563-fp9c-mgm8

больше 3 лет назад

Moodle Session Fixation vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2563-9f8c-7cw3

больше 4 лет назад

PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

EPSS: Низкий
github логотип

GHSA-2563-83p7-f34p

около 6 лет назад

Malicious Package in requestt

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-255x-mvhm-3947

больше 4 лет назад

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-255w-8g7g-qmg6

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix race condition during IPSec ESN update In IPSec full offload mode, the device reports an ESN (Extended Sequence Number) wrap event to the driver. The driver validates this event by querying the IPSec ASO and checking that the esn_event_arm field is 0x0, which indicates an event has occurred. After handling the event, the driver must re-arm the context by setting esn_event_arm back to 0x1. A race condition exists in this handling path. After validating the event, the driver calls mlx5_accel_esp_modify_xfrm() to update the kernel's xfrm state. This function temporarily releases and re-acquires the xfrm state lock. So, need to acknowledge the event first by setting esn_event_arm to 0x1. This prevents the driver from reprocessing the same ESN update if the hardware sends events for other reason. Since the next ESN update only occurs after nearly 2^31 packets are received, there's no risk of missing an...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-255w-87rh-rg44

почти 2 года назад

Cross-site Scripting via uploaded SVG

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-255w-3rfx-h4rv

5 месяцев назад

Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-255v-qv84-29p5

около 1 года назад

DragonFly's manager generates mTLS certificates for arbitrary IP addresses

EPSS: Низкий
github логотип

GHSA-255v-qpcm-wc95

больше 4 лет назад

Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2567-843w-hp69

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file /intranet/educar_aluno_beneficio_lst.php of the component Student Benefits Registration. The manipulation of the argument Benefício leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2567-3r9v-7m92

Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2566-p8jv-48q3

The sell function of a smart contract implementation for MyYLC, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2566-fq23-672g

An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2566-7hcg-m8r2

SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL commands via the orderid parameter in a status action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2565-pm5h-w9cc

HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2565-9vww-cf73

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2565-6q46-9x5v

Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2564-4rf9-wv93

Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2563-x4h3-pq75

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KentoThemes Justified Image Gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2563-r73r-7cq9

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2563-fp9c-mgm8

Moodle Session Fixation vulnerability

CVSS3: 9.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-2563-9f8c-7cw3

PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2563-83p7-f34p

Malicious Package in requestt

CVSS3: 9.8
около 6 лет назад
github логотип
GHSA-255x-mvhm-3947

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-255w-8g7g-qmg6

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix race condition during IPSec ESN update In IPSec full offload mode, the device reports an ESN (Extended Sequence Number) wrap event to the driver. The driver validates this event by querying the IPSec ASO and checking that the esn_event_arm field is 0x0, which indicates an event has occurred. After handling the event, the driver must re-arm the context by setting esn_event_arm back to 0x1. A race condition exists in this handling path. After validating the event, the driver calls mlx5_accel_esp_modify_xfrm() to update the kernel's xfrm state. This function temporarily releases and re-acquires the xfrm state lock. So, need to acknowledge the event first by setting esn_event_arm to 0x1. This prevents the driver from reprocessing the same ESN update if the hardware sends events for other reason. Since the next ESN update only occurs after nearly 2^31 packets are received, there's no risk of missing an...

CVSS3: 4.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-255w-87rh-rg44

Cross-site Scripting via uploaded SVG

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-255w-3rfx-h4rv

Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-255v-qv84-29p5

DragonFly's manager generates mTLS certificates for arbitrary IP addresses

0%
Низкий
около 1 года назад
github логотип
GHSA-255v-qpcm-wc95

Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу