Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-xwqx-x38c-cw95

больше 3 лет назад

Snipe-IT 6.0.2 vulnerable to Cross-site Scripting

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xwqx-rpjh-4w5r

больше 3 лет назад

delqueueask in rccp 0.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cccp_tmp.txt temporary file.

EPSS: Низкий
github логотип

GHSA-xwqx-m66h-v4hc

почти 4 года назад

Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact. NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.

EPSS: Низкий
github логотип

GHSA-xwqx-h938-xp3h

больше 3 лет назад

The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."

EPSS: Критический
github логотип

GHSA-xwqw-rf2q-xmhf

больше 5 лет назад

Cross-Site Scripting in buefy

EPSS: Низкий
github логотип

GHSA-xwqw-68pp-fwpc

6 месяцев назад

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwqv-pr7g-x8xf

почти 4 года назад

SQL injection vulnerability in the Book Reviews (sk_bookreview) extension 0.0.12 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xwqr-xmgg-j69q

около 4 лет назад

Integer overflow in solana_rbpf

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwqp-mjjh-p3v2

почти 4 года назад

David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_png_transform_scanline() in "/ok_png.c:533".

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwqp-6c5w-h6q9

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: tipc: improve size validations for received domain records The function tipc_mon_rcv() allows a node to receive and process domain_record structs from peer nodes to track their views of the network topology. This patch verifies that the number of members in a received domain record does not exceed the limit defined by MAX_MON_DOMAIN, something that may otherwise lead to a stack overflow. tipc_mon_rcv() is called from the function tipc_link_proto_rcv(), where we are reading a 32 bit message data length field into a uint16. To avert any risk of bit overflow, we add an extra sanity check for this in that function. We cannot see that happen with the current code, but future designers being unaware of this risk, may introduce it by allowing delivery of very large (> 64k) sk buffers from the bearer layer. This potential problem was identified by Eric Dumazet. This fixes CVE-2022-0435

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xwqj-8xp2-hxw6

около 2 месяцев назад

Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form: from n/a through <= 2.7.8.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwqj-7mqr-967j

почти 4 года назад

Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.

EPSS: Средний
github логотип

GHSA-xwqh-w6gg-25hm

8 месяцев назад

A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Admin/Property.php. The manipulation of the argument cmbCat leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xwqg-f8mp-8w9c

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in falselight Exchange Rates allows Stored XSS. This issue affects Exchange Rates: from n/a through 1.2.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwqg-3xfc-gp8v

около 3 лет назад

Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xwqf-qfg6-f88w

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwqf-9xwh-6vj2

больше 3 лет назад

Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undesired web page. The vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected service. An attacker could exploit these vulnerabilities by persuading a user to click a malicious link or by sending an HTTP request that could cause the affected service to redirect the request to a specified malicious URL. A successful exploit could allow the attacker to execute arbitrary script code in the context of the web interface of the affected system or allow the attacker to access sensitive browser-based information on the affected system. These types of exploits could also be used in phishing attacks that send users to malicious websites without their knowledge. Cisco Bu...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwq7-4cc2-m2p8

больше 3 лет назад

IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.

EPSS: Низкий
github логотип

GHSA-xwq6-j9m4-9grh

почти 4 года назад

The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.

EPSS: Низкий
github логотип

GHSA-xwq4-m3ff-5w2g

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in llamaman Simple Pull Quote simple-pull-quote allows Stored XSS.This issue affects Simple Pull Quote: from n/a through <= 1.6.3.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwqx-x38c-cw95

Snipe-IT 6.0.2 vulnerable to Cross-site Scripting

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwqx-rpjh-4w5r

delqueueask in rccp 0.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cccp_tmp.txt temporary file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwqx-m66h-v4hc

Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact. NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xwqx-h938-xp3h

The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, then conducting a man-in-the-middle (MITM) attack to hijack database connections, aka "TNS Poison."

92%
Критический
больше 3 лет назад
github логотип
GHSA-xwqw-rf2q-xmhf

Cross-Site Scripting in buefy

больше 5 лет назад
github логотип
GHSA-xwqw-68pp-fwpc

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xwqv-pr7g-x8xf

SQL injection vulnerability in the Book Reviews (sk_bookreview) extension 0.0.12 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xwqr-xmgg-j69q

Integer overflow in solana_rbpf

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xwqp-mjjh-p3v2

David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_png_transform_scanline() in "/ok_png.c:533".

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xwqp-6c5w-h6q9

In the Linux kernel, the following vulnerability has been resolved: tipc: improve size validations for received domain records The function tipc_mon_rcv() allows a node to receive and process domain_record structs from peer nodes to track their views of the network topology. This patch verifies that the number of members in a received domain record does not exceed the limit defined by MAX_MON_DOMAIN, something that may otherwise lead to a stack overflow. tipc_mon_rcv() is called from the function tipc_link_proto_rcv(), where we are reading a 32 bit message data length field into a uint16. To avert any risk of bit overflow, we add an extra sanity check for this in that function. We cannot see that happen with the current code, but future designers being unaware of this risk, may introduce it by allowing delivery of very large (> 64k) sk buffers from the bearer layer. This potential problem was identified by Eric Dumazet. This fixes CVE-2022-0435

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwqj-8xp2-hxw6

Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form: from n/a through <= 2.7.8.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xwqj-7mqr-967j

Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.

14%
Средний
почти 4 года назад
github логотип
GHSA-xwqh-w6gg-25hm

A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Admin/Property.php. The manipulation of the argument cmbCat leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xwqg-f8mp-8w9c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in falselight Exchange Rates allows Stored XSS. This issue affects Exchange Rates: from n/a through 1.2.5.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xwqg-3xfc-gp8v

Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability.

CVSS3: 7
0%
Низкий
около 3 лет назад
github логотип
GHSA-xwqf-qfg6-f88w

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwqf-9xwh-6vj2

Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undesired web page. The vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected service. An attacker could exploit these vulnerabilities by persuading a user to click a malicious link or by sending an HTTP request that could cause the affected service to redirect the request to a specified malicious URL. A successful exploit could allow the attacker to execute arbitrary script code in the context of the web interface of the affected system or allow the attacker to access sensitive browser-based information on the affected system. These types of exploits could also be used in phishing attacks that send users to malicious websites without their knowledge. Cisco Bu...

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwq7-4cc2-m2p8

IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwq6-j9m4-9grh

The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xwq4-m3ff-5w2g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in llamaman Simple Pull Quote simple-pull-quote allows Stored XSS.This issue affects Simple Pull Quote: from n/a through <= 1.6.3.

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу