Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-xmw9-6v8p-w6jg

почти 4 года назад

Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."

EPSS: Низкий
github логотип

GHSA-xmw9-6r43-x9ww

18 дней назад

SiYuan has directory traversal within its publishing service

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmw7-wmp8-hj98

почти 4 года назад

Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.

EPSS: Низкий
github логотип

GHSA-xmw7-pfh7-ccxp

почти 4 года назад

The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmw7-848p-p95w

почти 4 года назад

Airbnb Knowledge Repo XSS In Comments

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmw5-45v9-pxqx

почти 4 года назад

XSS vulnerability in Jenkins TICS Plugin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmw4-wxv9-hm5g

больше 1 года назад

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xmw3-64p4-g77h

около 1 месяца назад

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection.This issue affects Frick Controls Quantum HD version 10.22 and prior.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmw2-mw3c-793w

почти 4 года назад

Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination.

EPSS: Низкий
github логотип

GHSA-xmw2-h4mh-h75v

почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xmw2-9pgq-w58j

почти 4 года назад

The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.

EPSS: Низкий
github логотип

GHSA-xmw2-9fv2-vx29

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xmw2-8pp9-3q4c

почти 4 года назад

SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-xmw2-2pgj-jq4h

почти 4 года назад

Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

EPSS: Низкий
github логотип

GHSA-xmvx-xxj4-g48f

больше 3 лет назад

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xmvx-vh6j-5wm2

почти 4 года назад

A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmvw-m3jj-qhfh

почти 4 года назад

The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xmvv-w44w-j8wx

около 1 года назад

Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xmvv-4vx6-5fqj

почти 4 года назад

The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.

EPSS: Низкий
github логотип

GHSA-xmvq-j2gc-q94f

почти 4 года назад

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmw9-6v8p-w6jg

Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmw9-6r43-x9ww

SiYuan has directory traversal within its publishing service

CVSS3: 9.8
0%
Низкий
18 дней назад
github логотип
GHSA-xmw7-wmp8-hj98

Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmw7-pfh7-ccxp

The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xmw7-848p-p95w

Airbnb Knowledge Repo XSS In Comments

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xmw5-45v9-pxqx

XSS vulnerability in Jenkins TICS Plugin

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xmw4-wxv9-hm5g

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Database. CVSS 3.1 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xmw3-64p4-g77h

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection.This issue affects Frick Controls Quantum HD version 10.22 and prior.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xmw2-mw3c-793w

Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmw2-h4mh-h75v

Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmw2-9pgq-w58j

The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmw2-9fv2-vx29

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xmw2-8pp9-3q4c

SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xmw2-2pgj-jq4h

Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmvx-xxj4-g48f

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xmvx-vh6j-5wm2

A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.

CVSS3: 9.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-xmvw-m3jj-qhfh

The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmvv-w44w-j8wx

Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection

CVSS3: 3.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xmvv-4vx6-5fqj

The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.

4%
Низкий
почти 4 года назад
github логотип
GHSA-xmvq-j2gc-q94f

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
6%
Низкий
почти 4 года назад

Уязвимостей на страницу