Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-xp3g-2729-rxm3

около 3 лет назад

Froxlor is vulnerable to path traversal

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp3f-f794-84fg

около 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeoSOFT Software TeoBASE allows SQL Injection.This issue affects TeoBASE: through 27032024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xp3f-7vhv-p42p

12 месяцев назад

The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up to, and including, .6.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp3c-x693-rrgv

почти 4 года назад

Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

EPSS: Средний
github логотип

GHSA-xp3c-c34p-32qp

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp39-whpp-93gx

почти 4 года назад

An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-16938.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xp39-vp6q-phvj

2 месяца назад

In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xp38-x25m-8fpq

9 месяцев назад

The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-xp38-vhvm-v2x7

больше 3 лет назад

A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xp38-pxxv-x3pr

почти 4 года назад

Cross-site scripting (XSS) vulnerability in htdocs/php.php in OpenConcept Back-End CMS 0.4.7 allows remote attackers to inject arbitrary web script or HTML via the page[] parameter.

EPSS: Низкий
github логотип

GHSA-xp37-x766-f7v4

около 1 года назад

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xp37-p5rq-3c53

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: add NULL check in automount_fullpath page is checked for null in __build_path_from_dentry_optional_prefix when tcon->origin_fullpath is not set. However, the check is missing when it is set. Add a check to prevent a potential NULL pointer dereference.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp36-55ph-526f

почти 4 года назад

A cross-site scripting vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xp35-9crr-2x99

почти 4 года назад

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. watchOS before 3.2.3 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service (memory consumption and application crash).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp33-mgvv-9242

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() If new_asoc->peer.adaptation_ind=0 and sctp_ulpevent_make_authkey=0 and sctp_ulpevent_make_authkey() returns 0, then the variable ai_ev remains zero and the zero will be dereferenced in the sctp_ulpevent_free() function.

EPSS: Низкий
github логотип

GHSA-xp32-h6c2-42q9

почти 2 года назад

A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264461 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xp32-64gc-9mv5

около 1 года назад

A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xp32-4pp4-j2w2

почти 4 года назад

admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xp2v-rf5w-rh2c

около 2 лет назад

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 269686.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-xp2v-pp4q-q7jv

7 месяцев назад

Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp3g-2729-rxm3

Froxlor is vulnerable to path traversal

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xp3f-f794-84fg

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeoSOFT Software TeoBASE allows SQL Injection.This issue affects TeoBASE: through 27032024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xp3f-7vhv-p42p

The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up to, and including, .6.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-xp3c-x693-rrgv

Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

13%
Средний
почти 4 года назад
github логотип
GHSA-xp3c-c34p-32qp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xp39-whpp-93gx

An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-16938.

CVSS3: 5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xp39-vp6q-phvj

In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).

CVSS3: 5.9
0%
Низкий
2 месяца назад
github логотип
GHSA-xp38-x25m-8fpq

The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.

CVSS3: 9.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xp38-vhvm-v2x7

A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter after clicking "Add".

CVSS3: 5.4
6%
Низкий
больше 3 лет назад
github логотип
GHSA-xp38-pxxv-x3pr

Cross-site scripting (XSS) vulnerability in htdocs/php.php in OpenConcept Back-End CMS 0.4.7 allows remote attackers to inject arbitrary web script or HTML via the page[] parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xp37-x766-f7v4

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xp37-p5rq-3c53

In the Linux kernel, the following vulnerability has been resolved: smb: client: add NULL check in automount_fullpath page is checked for null in __build_path_from_dentry_optional_prefix when tcon->origin_fullpath is not set. However, the check is missing when it is set. Add a check to prevent a potential NULL pointer dereference.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xp36-55ph-526f

A cross-site scripting vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp35-9crr-2x99

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. watchOS before 3.2.3 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service (memory consumption and application crash).

CVSS3: 7.5
2%
Низкий
почти 4 года назад
github логотип
GHSA-xp33-mgvv-9242

In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() If new_asoc->peer.adaptation_ind=0 and sctp_ulpevent_make_authkey=0 and sctp_ulpevent_make_authkey() returns 0, then the variable ai_ev remains zero and the zero will be dereferenced in the sctp_ulpevent_free() function.

0%
Низкий
5 месяцев назад
github логотип
GHSA-xp32-h6c2-42q9

A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264461 was assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xp32-64gc-9mv5

A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
около 1 года назад
github логотип
GHSA-xp32-4pp4-j2w2

admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.

CVSS3: 7.2
2%
Низкий
почти 4 года назад
github логотип
GHSA-xp2v-rf5w-rh2c

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 269686.

CVSS3: 4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xp2v-pp4q-q7jv

Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.

CVSS3: 6.8
0%
Низкий
7 месяцев назад

Уязвимостей на страницу