Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 185

Количество 326 185

github логотип

GHSA-xmr9-gm4r-2xr8

больше 3 лет назад

The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xmr9-3j8w-v8gw

около 1 года назад

A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xmr8-xw2g-rqh3

12 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection. This page is only accessible to authenticated users with high privileges. This issue affects Centreon BAM: from 24.10 before 24.10.1, from 24.04 before 24.04.5, from 23.10 before 23.10.10, from 23.04 before 23.04.10.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xmr8-m3g7-8q7w

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Kevin McCabe Kevin's allows Stored XSS.This issue affects Kevin's: from n/a through 2.0.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xmr8-fvh4-85cv

3 месяца назад

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmr8-c87m-jhw3

почти 4 года назад

An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. A heap-based buffer overflow bug in svgpp_agg_render may lead to code execution. In the render_scanlines_aa_solid function, the blend_hline function is called repeatedly multiple times. blend_hline is equivalent to a loop containing write operations. Each call writes a piece of heap data, and multiple calls overwrite the data in the heap.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmr7-w962-g66m

около 3 лет назад

jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmr7-v725-2jjr

больше 4 лет назад

Cross site scripting in comrak

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmr6-xwc6-6hv4

почти 4 года назад

The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.

EPSS: Средний
github логотип

GHSA-xmr6-rg25-v9gg

почти 4 года назад

The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.

EPSS: Низкий
github логотип

GHSA-xmr6-p3jv-fvww

почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs.

EPSS: Низкий
github логотип

GHSA-xmr6-mm5f-8mf2

2 месяца назад

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xmr3-m6h9-383p

почти 4 года назад

Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.

EPSS: Низкий
github логотип

GHSA-xmr3-fcjj-mc3v

почти 4 года назад

Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.

EPSS: Низкий
github логотип

GHSA-xmr2-xffw-xxmx

почти 4 года назад

iStock Management System 1.0 allows Arbitrary File Upload via user/profile.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xmr2-cqqm-jr8m

почти 4 года назад

Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-xmr2-c47x-rm4p

около 1 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Mobile Frontend Extension allows Shared Resource Manipulation.This issue affects Mediawiki - Mobile Frontend Extension: from 1.39 through 1.43.

EPSS: Низкий
github логотип

GHSA-xmr2-77rg-h53j

почти 4 года назад

AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmqx-8fv3-jc9q

почти 4 года назад

A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization enforcement for the creation of scheduled meeting templates. An attacker could exploit this vulnerability by sending a crafted request to the Webex Meetings interface to create a scheduled meeting template. A successful exploit could allow the attacker to create a scheduled meeting template that would belong to a user other than themselves.

EPSS: Низкий
github логотип

GHSA-xmqw-mq56-x22h

11 месяцев назад

Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Slider Pro: from n/a through 1.12. Affected action "woo_slide_pro_delete_slider".

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmr9-gm4r-2xr8

The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xmr9-3j8w-v8gw

A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xmr8-xw2g-rqh3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection. This page is only accessible to authenticated users with high privileges. This issue affects Centreon BAM: from 24.10 before 24.10.1, from 24.04 before 24.04.5, from 23.10 before 23.10.10, from 23.04 before 23.04.10.

CVSS3: 7.2
5%
Низкий
12 месяцев назад
github логотип
GHSA-xmr8-m3g7-8q7w

Cross-Site Request Forgery (CSRF) vulnerability in Kevin McCabe Kevin's allows Stored XSS.This issue affects Kevin's: from n/a through 2.0.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xmr8-fvh4-85cv

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xmr8-c87m-jhw3

An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. A heap-based buffer overflow bug in svgpp_agg_render may lead to code execution. In the render_scanlines_aa_solid function, the blend_hline function is called repeatedly multiple times. blend_hline is equivalent to a loop containing write operations. Each call writes a piece of heap data, and multiple calls overwrite the data in the heap.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xmr7-w962-g66m

jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.

CVSS3: 8.8
5%
Низкий
около 3 лет назад
github логотип
GHSA-xmr7-v725-2jjr

Cross site scripting in comrak

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xmr6-xwc6-6hv4

The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.

17%
Средний
почти 4 года назад
github логотип
GHSA-xmr6-rg25-v9gg

The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix 31, and Web Security Gateway Anywhere 7.7.3 before Hotfix 31 allows remote authenticated users to read cleartext passwords by replacing type="password" with type="text" in an INPUT element in the (1) Log Database or (2) User Directories component.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmr6-p3jv-fvww

Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmr6-mm5f-8mf2

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later

CVSS3: 4.9
0%
Низкий
2 месяца назад
github логотип
GHSA-xmr3-m6h9-383p

Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.

7%
Низкий
почти 4 года назад
github логотип
GHSA-xmr3-fcjj-mc3v

Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xmr2-xffw-xxmx

iStock Management System 1.0 allows Arbitrary File Upload via user/profile.

CVSS3: 9.8
18%
Средний
почти 4 года назад
github логотип
GHSA-xmr2-cqqm-jr8m

Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xmr2-c47x-rm4p

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Mobile Frontend Extension allows Shared Resource Manipulation.This issue affects Mediawiki - Mobile Frontend Extension: from 1.39 through 1.43.

0%
Низкий
около 1 года назад
github логотип
GHSA-xmr2-77rg-h53j

AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xmqx-8fv3-jc9q

A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization enforcement for the creation of scheduled meeting templates. An attacker could exploit this vulnerability by sending a crafted request to the Webex Meetings interface to create a scheduled meeting template. A successful exploit could allow the attacker to create a scheduled meeting template that would belong to a user other than themselves.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmqw-mq56-x22h

Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Slider Pro: from n/a through 1.12. Affected action "woo_slide_pro_delete_slider".

CVSS3: 6.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу