Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-xqp4-ghh2-wgpj

почти 4 года назад

A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206250 is the identifier assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqp4-g3qh-3x89

около 4 лет назад

iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.

EPSS: Низкий
github логотип

GHSA-xqp4-4g25-fhqx

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in usersettings.php in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

EPSS: Низкий
github логотип

GHSA-xqp3-jq6g-x3qm

30 дней назад

File Browser: Authentication Bypass via Proxy Auth Header Forgery

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xqp3-6vpp-g4f2

около 4 лет назад

DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PhotoShop file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqmx-x37r-m33p

3 месяца назад

A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the component puppeteer_navigate. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xqmx-cm26-j84p

10 месяцев назад

IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xqmx-3vx6-fm88

3 месяца назад

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper sanitization, enabling an attacker to inject a form element that could capture administrator credentials. Exploitation required an administrator to click a crafted link and enter their credentials. This vulnerability affected GitHub Enterprise Server versions 3.19.1 through 3.19.5 and 3.20.0 through 3.20.1, and was fixed in versions 3.19.6 and 3.20.2. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqmw-9249-4m7x

почти 2 года назад

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xqmw-24v9-r296

больше 3 лет назад

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xqmv-67w6-p3wm

около 2 лет назад

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in the account settings.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqmq-m74q-gr4q

4 месяца назад

Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue affects Pandora FMS: from 777 through 800

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xqmq-3744-539p

почти 2 года назад

Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-xqmq-2p4j-99x8

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() Some crafted images can have illegal (!partial_decoding && m_llen < m_plen) extents, and the LZ4 inplace decompression path can be wrongly hit, but it cannot handle (outpages < inpages) properly: "outpages - inpages" wraps to a large value and the subsequent rq->out[] access reads past the decompressed_pages array. However, such crafted cases can correctly result in a corruption report in the normal LZ4 non-inplace path. Let's add an additional check to fix this for backporting. Reproducible image (base64-encoded gzipped blob): H4sIAJGR12kCA+3SPUoDQRgG4MkmkkZk8QRbRFIIi9hbpEjrHQI5ghfwCN5BLCzTGtLbBI+g dilSJo1CnIm7GEXFxhT6PDDwfrs73/ywIQD/1ePD4r7Ou6ETsrq4mu7XcWfj++Pb58nJU/9i PNtbjhan04/9GtX4qVYc814WDqt6FaX5s+ZwXXeq52lndT6IuVvlblytLMvh4Gzwaf90nsvz 2DF/21+20T/ldgp5s1jXRaN4t/8izsy/OUB6e/Qa79r+JwAAAAAAAL52vQVuGQAAAP6+my1w ywAAAAAAAADwu14ATsEYtgBQAAA= $ mou...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xqmp-fxgv-xvq5

4 месяца назад

libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handling

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xqmm-x45g-6wf4

больше 1 года назад

Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xqmj-j6mv-4862

4 месяца назад

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

EPSS: Низкий
github логотип

GHSA-xqmh-wj7x-9rxf

больше 4 лет назад

Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

EPSS: Низкий
github логотип

GHSA-xqmh-c3cf-jrc8

около 4 лет назад

IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqmg-px4m-r5qm

около 4 лет назад

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqp4-ghh2-wgpj

A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206250 is the identifier assigned to this vulnerability.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqp4-g3qh-3x89

iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xqp4-4g25-fhqx

Cross-site scripting (XSS) vulnerability in usersettings.php in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqp3-jq6g-x3qm

File Browser: Authentication Bypass via Proxy Auth Header Forgery

CVSS3: 9.1
0%
Низкий
30 дней назад
github логотип
GHSA-xqp3-6vpp-g4f2

DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PhotoShop file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqmx-x37r-m33p

A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the component puppeteer_navigate. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xqmx-cm26-j84p

IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-xqmx-3vx6-fm88

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper sanitization, enabling an attacker to inject a form element that could capture administrator credentials. Exploitation required an administrator to click a crafted link and enter their credentials. This vulnerability affected GitHub Enterprise Server versions 3.19.1 through 3.19.5 and 3.20.0 through 3.20.1, and was fixed in versions 3.19.6 and 3.20.2. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xqmw-9249-4m7x

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.

CVSS3: 4.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xqmw-24v9-r296

The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xqmv-67w6-p3wm

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in the account settings.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xqmq-m74q-gr4q

Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Response execution. This issue affects Pandora FMS: from 777 through 800

CVSS3: 7.2
1%
Низкий
4 месяца назад
github логотип
GHSA-xqmq-3744-539p

Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service.

CVSS3: 5.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-xqmq-2p4j-99x8

In the Linux kernel, the following vulnerability has been resolved: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() Some crafted images can have illegal (!partial_decoding && m_llen < m_plen) extents, and the LZ4 inplace decompression path can be wrongly hit, but it cannot handle (outpages < inpages) properly: "outpages - inpages" wraps to a large value and the subsequent rq->out[] access reads past the decompressed_pages array. However, such crafted cases can correctly result in a corruption report in the normal LZ4 non-inplace path. Let's add an additional check to fix this for backporting. Reproducible image (base64-encoded gzipped blob): H4sIAJGR12kCA+3SPUoDQRgG4MkmkkZk8QRbRFIIi9hbpEjrHQI5ghfwCN5BLCzTGtLbBI+g dilSJo1CnIm7GEXFxhT6PDDwfrs73/ywIQD/1ePD4r7Ou6ETsrq4mu7XcWfj++Pb58nJU/9i PNtbjhan04/9GtX4qVYc814WDqt6FaX5s+ZwXXeq52lndT6IuVvlblytLMvh4Gzwaf90nsvz 2DF/21+20T/ldgp5s1jXRaN4t/8izsy/OUB6e/Qa79r+JwAAAAAAAL52vQVuGQAAAP6+my1w ywAAAAAAAADwu14ATsEYtgBQAAA= $ mou...

CVSS3: 7.1
0%
Низкий
2 месяца назад
github логотип
GHSA-xqmp-fxgv-xvq5

libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handling

CVSS3: 5.9
0%
Низкий
4 месяца назад
github логотип
GHSA-xqmm-x45g-6wf4

Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

CVSS3: 9.1
2%
Низкий
больше 1 года назад
github логотип
GHSA-xqmj-j6mv-4862

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

0%
Низкий
4 месяца назад
github логотип
GHSA-xqmh-wj7x-9rxf

Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqmh-c3cf-jrc8

IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xqmg-px4m-r5qm

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу