Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xp5q-77mh-6hm2

почти 5 лет назад

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp5q-5q7g-q26r

3 месяца назад

Ludwig framework is vulnerable to insecure deserialization in its model serving component

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xp5p-m9rq-h59j

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects PJ News Ticker: from n/a through 1.9.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp5p-5cr9-v76h

7 месяцев назад

Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp5m-682p-74cw

больше 4 лет назад

eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.

EPSS: Низкий
github логотип

GHSA-xp5m-4c9f-498q

около 8 лет назад

django-epiceditor vulnerable to XSS in form field

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp5m-3m34-5m96

больше 4 лет назад

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp5j-wj4h-2jq9

больше 4 лет назад

Injection and Improper Input Validation in Apache Unomi

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xp5j-hrqw-xvpc

около 4 лет назад

In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp5j-75x6-qx28

около 4 лет назад

awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.

EPSS: Низкий
github логотип

GHSA-xp5h-f8jf-rc8q

около 3 лет назад

rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xp5g-whvx-3f7g

около 4 лет назад

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp5g-v8fx-97mv

около 4 лет назад

An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xp5g-jhg3-3rg2

около 3 лет назад

Double spend in snarkjs

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp5g-gff9-qvvx

10 месяцев назад

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp5f-4q2v-q3xf

около 1 года назад

A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xp5c-p5xg-fx95

около 4 лет назад

Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.

EPSS: Низкий
github логотип

GHSA-xp58-v8qq-x8jr

около 4 лет назад

In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel

EPSS: Низкий
github логотип

GHSA-xp58-h76m-67p4

около 4 лет назад

Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."

EPSS: Низкий
github логотип

GHSA-xp57-8544-jh3m

около 4 лет назад

WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp5q-77mh-6hm2

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-xp5q-5q7g-q26r

Ludwig framework is vulnerable to insecure deserialization in its model serving component

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xp5p-m9rq-h59j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects PJ News Ticker: from n/a through 1.9.5.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xp5p-5cr9-v76h

Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allows attackers to execute arbitrary JavaScript in the context of a victim s browser session

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-xp5m-682p-74cw

eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xp5m-4c9f-498q

django-epiceditor vulnerable to XSS in form field

CVSS3: 6.1
1%
Низкий
около 8 лет назад
github логотип
GHSA-xp5m-3m34-5m96

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xp5j-wj4h-2jq9

Injection and Improper Input Validation in Apache Unomi

CVSS3: 9.8
68%
Средний
больше 4 лет назад
github логотип
GHSA-xp5j-hrqw-xvpc

In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xp5j-75x6-qx28

awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xp5h-f8jf-rc8q

rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-xp5g-whvx-3f7g

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xp5g-v8fx-97mv

An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

CVSS3: 7.5
42%
Средний
около 4 лет назад
github логотип
GHSA-xp5g-jhg3-3rg2

Double spend in snarkjs

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xp5g-gff9-qvvx

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xp5f-4q2v-q3xf

A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xp5c-p5xg-fx95

Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xp58-v8qq-x8jr

In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel

0%
Низкий
около 4 лет назад
github логотип
GHSA-xp58-h76m-67p4

Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."

6%
Низкий
около 4 лет назад
github логотип
GHSA-xp57-8544-jh3m

WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CVSS3: 8.8
2%
Низкий
около 4 лет назад

Уязвимостей на страницу