Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-xp5q-j3fq-3qw3

почти 4 года назад

Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.

EPSS: Средний
github логотип

GHSA-xp5q-f74v-x8r5

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflected XSS. This issue affects Simple Link Directory: from n/a through n/a.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xp5q-c655-9565

почти 4 года назад

The function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp5q-77mh-6hm2

больше 4 лет назад

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp5p-m9rq-h59j

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects PJ News Ticker: from n/a through 1.9.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp5p-5cr9-v76h

3 месяца назад

Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp5m-682p-74cw

почти 4 года назад

eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.

EPSS: Низкий
github логотип

GHSA-xp5m-4c9f-498q

больше 7 лет назад

django-epiceditor vulnerable to XSS in form field

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp5m-3m34-5m96

почти 4 года назад

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp5j-wj4h-2jq9

около 4 лет назад

Injection and Improper Input Validation in Apache Unomi

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xp5j-hrqw-xvpc

почти 4 года назад

In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp5j-75x6-qx28

почти 4 года назад

awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.

EPSS: Низкий
github логотип

GHSA-xp5h-f8jf-rc8q

почти 3 года назад

rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xp5g-whvx-3f7g

почти 4 года назад

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp5g-v8fx-97mv

почти 4 года назад

An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xp5g-jhg3-3rg2

почти 3 года назад

Double spend in snarkjs

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp5g-gff9-qvvx

6 месяцев назад

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp5f-4q2v-q3xf

10 месяцев назад

A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xp5c-p5xg-fx95

почти 4 года назад

Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.

EPSS: Низкий
github логотип

GHSA-xp58-v8qq-x8jr

почти 4 года назад

In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp5q-j3fq-3qw3

Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.

11%
Средний
почти 4 года назад
github логотип
GHSA-xp5q-f74v-x8r5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflected XSS. This issue affects Simple Link Directory: from n/a through n/a.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-xp5q-c655-9565

The function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp5q-77mh-6hm2

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xp5p-m9rq-h59j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects PJ News Ticker: from n/a through 1.9.5.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xp5p-5cr9-v76h

Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xp5m-682p-74cw

eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp5m-4c9f-498q

django-epiceditor vulnerable to XSS in form field

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
github логотип
GHSA-xp5m-3m34-5m96

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp5j-wj4h-2jq9

Injection and Improper Input Validation in Apache Unomi

CVSS3: 9.8
94%
Критический
около 4 лет назад
github логотип
GHSA-xp5j-hrqw-xvpc

In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp5j-75x6-qx28

awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xp5h-f8jf-rc8q

rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xp5g-whvx-3f7g

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp5g-v8fx-97mv

An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

CVSS3: 7.5
25%
Средний
почти 4 года назад
github логотип
GHSA-xp5g-jhg3-3rg2

Double spend in snarkjs

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xp5g-gff9-qvvx

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xp5f-4q2v-q3xf

A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xp5c-p5xg-fx95

Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp58-v8qq-x8jr

In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel

0%
Низкий
почти 4 года назад

Уязвимостей на страницу