Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 311 677

Количество 311 677

github логотип

GHSA-xx4r-v983-p5jq

больше 3 лет назад

The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xx4r-5265-48j6

больше 1 года назад

silverstripe/framework SQL injection in full text search

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx4q-xvq8-pqjv

8 месяцев назад

A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xx4q-9h3q-wpv9

почти 4 года назад

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx4p-cqfx-r6v6

больше 2 лет назад

In initiateTdlsTeardownInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262235951

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xx4m-rfhv-5rx3

больше 3 лет назад

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to complete a transition from Low Integrity to Medium Integrity by leveraging incorrect permissions.

EPSS: Низкий
github логотип

GHSA-xx4m-fcjj-4mc6

почти 4 года назад

Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions.

EPSS: Низкий
github логотип

GHSA-xx4m-763q-h8x3

около 2 лет назад

Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a through 1.8.0.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xx4j-rvcc-2vhr

больше 3 лет назад

Capstone SEGV caused by a read memory access

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx4j-phh8-wvv3

больше 3 лет назад

The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx4j-jmqq-fqvx

больше 2 лет назад

In the module "Referral and Affiliation Program" (referralbyphone) version 3.5.1 and before from Snegurka for PrestaShop, a guest can perform SQL injection. Method `ReferralByPhoneDefaultModuleFrontController::ajaxProcessCartRuleValidate` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx4g-r65p-3qf2

5 месяцев назад

mpregular vulnerable to prototype pollution

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx4g-qrfc-m589

больше 3 лет назад

In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.

EPSS: Низкий
github логотип

GHSA-xx4g-mv9m-95fg

почти 4 года назад

The Dojo framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

EPSS: Низкий
github логотип

GHSA-xx4g-62m6-v2w7

11 месяцев назад

In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xx4c-xhpg-hcw2

больше 2 лет назад

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx4c-ww79-386v

4 месяца назад

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx4c-jj58-r7x6

около 4 лет назад

Inefficient Regular Expression Complexity in Validator.js

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx49-hmrj-2wm5

больше 3 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx49-8f9w-5r74

почти 4 года назад

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx4r-v983-p5jq

The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

CVSS3: 9.8
43%
Средний
больше 3 лет назад
github логотип
GHSA-xx4r-5265-48j6

silverstripe/framework SQL injection in full text search

CVSS3: 8.8
больше 1 года назад
github логотип
GHSA-xx4q-xvq8-pqjv

A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xx4q-9h3q-wpv9

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xx4p-cqfx-r6v6

In initiateTdlsTeardownInternal of sta_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262235951

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx4m-rfhv-5rx3

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to complete a transition from Low Integrity to Medium Integrity by leveraging incorrect permissions.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-xx4m-fcjj-4mc6

Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx4m-763q-h8x3

Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a through 1.8.0.

CVSS3: 9.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-xx4j-rvcc-2vhr

Capstone SEGV caused by a read memory access

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx4j-phh8-wvv3

The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx4j-jmqq-fqvx

In the module "Referral and Affiliation Program" (referralbyphone) version 3.5.1 and before from Snegurka for PrestaShop, a guest can perform SQL injection. Method `ReferralByPhoneDefaultModuleFrontController::ajaxProcessCartRuleValidate` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx4g-r65p-3qf2

mpregular vulnerable to prototype pollution

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xx4g-qrfc-m589

In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx4g-mv9m-95fg

The Dojo framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx4g-62m6-v2w7

In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.

CVSS3: 4.6
0%
Низкий
11 месяцев назад
github логотип
GHSA-xx4c-xhpg-hcw2

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx4c-ww79-386v

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xx4c-jj58-r7x6

Inefficient Regular Expression Complexity in Validator.js

CVSS3: 5.3
около 4 лет назад
github логотип
GHSA-xx49-hmrj-2wm5

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx49-8f9w-5r74

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу