Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xg6r-5gx4-qxjm

больше 4 лет назад

invoiceninja is vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xg6r-4v3x-wfq6

около 4 лет назад

Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi (save parameter) and cgi-bin/ddns.cgi.

EPSS: Низкий
github логотип

GHSA-xg6p-ppf2-6wj6

около 1 года назад

Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Push Notifications: from n/a through 1.1.9.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xg6p-7989-gjfr

больше 4 лет назад

A heap buffer overflow was discovered in the device control ioctl in the Linux driver for Nvidia graphics cards, which may allow an attacker to overflow 49 bytes. This issue was fixed in version 295.53.

EPSS: Низкий
github логотип

GHSA-xg6m-ppmj-29wf

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Genkisan Genki Announcement allows Cross Site Request Forgery.This issue affects Genki Announcement: from n/a through 1.4.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xg6m-4668-h9qh

около 4 лет назад

Protection mechanism failure in all processes in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows local users to stop certain McAfee ENS processes, reducing the protection offered.

EPSS: Низкий
github логотип

GHSA-xg6j-xg44-rp8p

больше 4 лет назад

SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter.

EPSS: Низкий
github логотип

GHSA-xg6j-wc94-hhxg

около 4 лет назад

The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

EPSS: Низкий
github логотип

GHSA-xg6j-v8rf-4p7v

8 месяцев назад

A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-student-profile.php of the component Student Registration Page. The manipulation of the argument photo results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xg6j-fjj2-gv89

больше 1 года назад

An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg6j-7h2x-x54g

больше 4 лет назад

TeaKKi 2.7 allows XSS via a crafted onerror attribute for a picture's URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xg6j-69w9-f6xv

около 4 лет назад

Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.

EPSS: Низкий
github логотип

GHSA-xg6h-wxm2-f777

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/.

EPSS: Низкий
github логотип

GHSA-xg6h-wx3v-863v

около 4 лет назад

Improper access control in the Intel(R) HD Graphics Control Panel before version 15.40.46.5144 and 15.36.39.5143 may allow an authenticated user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-xg6h-qgc7-qqr7

15 дней назад

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xg6g-c9x2-64w2

8 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xg6g-4cpc-5wf2

больше 2 лет назад

A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file course_ajax.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251553 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xg6g-3jwv-7334

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asdqwe Dev Ajax Domain Checker plugin <= 1.3.0 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xg6f-394q-j4f9

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

EPSS: Средний
github логотип

GHSA-xg6c-x6rj-pf7r

больше 4 лет назад

An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is rated as High because it could be used to access sensitive data. Product: Android. Versions: Kernel-3.18. Android ID: A-32369621.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg6r-5gx4-qxjm

invoiceninja is vulnerable to Cross-site Scripting

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6r-4v3x-wfq6

Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi (save parameter) and cgi-bin/ddns.cgi.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xg6p-ppf2-6wj6

Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Push Notifications: from n/a through 1.1.9.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xg6p-7989-gjfr

A heap buffer overflow was discovered in the device control ioctl in the Linux driver for Nvidia graphics cards, which may allow an attacker to overflow 49 bytes. This issue was fixed in version 295.53.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6m-ppmj-29wf

Cross-Site Request Forgery (CSRF) vulnerability in Genkisan Genki Announcement allows Cross Site Request Forgery.This issue affects Genki Announcement: from n/a through 1.4.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xg6m-4668-h9qh

Protection mechanism failure in all processes in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows local users to stop certain McAfee ENS processes, reducing the protection offered.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xg6j-xg44-rp8p

SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6j-wc94-hhxg

The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xg6j-v8rf-4p7v

A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-student-profile.php of the component Student Registration Page. The manipulation of the argument photo results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xg6j-fjj2-gv89

An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xg6j-7h2x-x54g

TeaKKi 2.7 allows XSS via a crafted onerror attribute for a picture's URL.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6j-69w9-f6xv

Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.

8%
Низкий
около 4 лет назад
github логотип
GHSA-xg6h-wxm2-f777

Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg6h-wx3v-863v

Improper access control in the Intel(R) HD Graphics Control Panel before version 15.40.46.5144 and 15.36.39.5143 may allow an authenticated user to potentially enable escalation of privilege via local access.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xg6h-qgc7-qqr7

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.

CVSS3: 6.5
0%
Низкий
15 дней назад
github логотип
GHSA-xg6g-c9x2-64w2

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xg6g-4cpc-5wf2

A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file course_ajax.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251553 was assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xg6g-3jwv-7334

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asdqwe Dev Ajax Domain Checker plugin <= 1.3.0 versions.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xg6f-394q-j4f9

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

16%
Средний
больше 4 лет назад
github логотип
GHSA-xg6c-x6rj-pf7r

An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is rated as High because it could be used to access sensitive data. Product: Android. Versions: Kernel-3.18. Android ID: A-32369621.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу