Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 571

Количество 323 571

github логотип

GHSA-xp77-7ppq-j5jg

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Callback Request allows Reflected XSS. This issue affects Callback Request: from n/a through 1.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xp76-357g-9wqq

почти 4 года назад

SciPy creates insecure temporary directories

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp76-33m9-43ww

7 месяцев назад

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp75-w7vq-5x6j

около 1 года назад

OpenDaylight SFC Insecure Shiro Cookie Configuration

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xp75-r577-cvhp

8 месяцев назад

Privileged OpenBao Operator May Execute Code on the Underlying Host

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xp73-99p3-8q2g

почти 4 года назад

The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue.

EPSS: Низкий
github логотип

GHSA-xp6x-f75w-g3q7

больше 2 лет назад

An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp6x-8hgv-x5w5

больше 2 лет назад

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp6x-54qx-mg3m

2 месяца назад

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xp6v-qx65-4pp7

больше 4 лет назад

Data races in gfwx

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xp6v-frx8-276h

почти 4 года назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xp6v-2px2-m727

почти 4 года назад

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-xp6r-hhmh-jgfj

почти 4 года назад

Multiple unspecified vulnerabilities in phpns before 2.1.1beta1 have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-xp6r-5ghh-6w2m

почти 4 года назад

Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.

EPSS: Низкий
github логотип

GHSA-xp6r-3p5r-p29g

почти 4 года назад

The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

EPSS: Средний
github логотип

GHSA-xp6q-cm7h-qg74

почти 3 года назад

An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check of the return value of kzalloc() and will cause the NULL Pointer Dereference.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp6q-4ch5-xqhr

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ext4: refuse to create ea block when umounted The ea block expansion need to access s_root while it is already set as NULL when umount is triggered. Refuse this request to avoid panic.

EPSS: Низкий
github логотип

GHSA-xp6q-36fr-27p3

около 2 лет назад

The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta output in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xp6p-29w5-vq4h

почти 4 года назад

Windows Print Configuration Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp6m-95m6-gvf5

больше 3 лет назад

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp77-7ppq-j5jg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Callback Request allows Reflected XSS. This issue affects Callback Request: from n/a through 1.4.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xp76-357g-9wqq

SciPy creates insecure temporary directories

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp76-33m9-43ww

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-xp75-w7vq-5x6j

OpenDaylight SFC Insecure Shiro Cookie Configuration

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xp75-r577-cvhp

Privileged OpenBao Operator May Execute Code on the Underlying Host

CVSS3: 9.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-xp73-99p3-8q2g

The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xp6x-f75w-g3q7

An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.

CVSS3: 8.8
4%
Низкий
больше 2 лет назад
github логотип
GHSA-xp6x-8hgv-x5w5

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xp6x-54qx-mg3m

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-xp6v-qx65-4pp7

Data races in gfwx

CVSS3: 7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xp6v-frx8-276h

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.

CVSS3: 9.8
92%
Критический
почти 4 года назад
github логотип
GHSA-xp6v-2px2-m727

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."

51%
Средний
почти 4 года назад
github логотип
GHSA-xp6r-hhmh-jgfj

Multiple unspecified vulnerabilities in phpns before 2.1.1beta1 have unknown impact and attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp6r-5ghh-6w2m

Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xp6r-3p5r-p29g

The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

32%
Средний
почти 4 года назад
github логотип
GHSA-xp6q-cm7h-qg74

An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check of the return value of kzalloc() and will cause the NULL Pointer Dereference.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xp6q-4ch5-xqhr

In the Linux kernel, the following vulnerability has been resolved: ext4: refuse to create ea block when umounted The ea block expansion need to access s_root while it is already set as NULL when umount is triggered. Refuse this request to avoid panic.

0%
Низкий
3 месяца назад
github логотип
GHSA-xp6q-36fr-27p3

The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta output in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xp6p-29w5-vq4h

Windows Print Configuration Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp6m-95m6-gvf5

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу