Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 392

Количество 289 392

github логотип

GHSA-xwjq-2p97-r884

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and WebLogic Express 9.0, 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allow remote attackers to inject arbitrary web script or HTML and gain administrative privileges via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-xwjp-hc68-95rc

больше 3 лет назад

** DISPUTED ** Race condition in PrivateFirewall 7.0.20.37 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xwjm-qj7j-73qw

больше 3 лет назад

OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie.

EPSS: Низкий
github логотип

GHSA-xwjm-m85h-4ff8

больше 3 лет назад

Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.

EPSS: Низкий
github логотип

GHSA-xwjm-4v2q-p47f

больше 3 лет назад

istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

EPSS: Низкий
github логотип

GHSA-xwjj-jxqw-mr62

около 1 года назад

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwjh-cp99-cj8q

больше 6 лет назад

Path Traversal in cordova-plugin-ionic-webview

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xwjg-qxv6-28rv

около 3 лет назад

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwjf-whc7-vgr2

больше 3 лет назад

Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCum16749.

EPSS: Низкий
github логотип

GHSA-xwjf-v823-v896

больше 3 лет назад

drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.

EPSS: Низкий
github логотип

GHSA-xwjc-m85h-pr32

больше 2 лет назад

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwjc-4jxh-j5p8

около 3 лет назад

Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1653, CVE-2021-1654, CVE-2021-1655, CVE-2021-1659, CVE-2021-1688, CVE-2021-1693.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwj9-9vmw-m922

около 3 лет назад

A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwj7-29j7-rw76

около 3 лет назад

Cross site scripting in Elefant CMS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwj6-mjhc-r3jc

больше 3 лет назад

Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files.

EPSS: Низкий
github логотип

GHSA-xwj6-f3wq-283g

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Twerdy Genesis Style Shortcodes allows DOM-Based XSS.This issue affects Genesis Style Shortcodes: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwj5-gj8r-8hr8

больше 3 лет назад

Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of service (disk consumption) via certain malformed HTTP headers.

EPSS: Низкий
github логотип

GHSA-xwj5-fxxc-gf36

9 дней назад

The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xwj5-5q25-vqmg

около 1 года назад

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xwj3-m7ch-j848

больше 1 года назад

Memory corruption in HLOS while checking for the storage type.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwjq-2p97-r884

Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and WebLogic Express 9.0, 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allow remote attackers to inject arbitrary web script or HTML and gain administrative privileges via unknown attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjp-hc68-95rc

** DISPUTED ** Race condition in PrivateFirewall 7.0.20.37 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjm-qj7j-73qw

OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjm-m85h-4ff8

Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjm-4v2q-p47f

istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjj-jxqw-mr62

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
7%
Низкий
около 1 года назад
github логотип
GHSA-xwjh-cp99-cj8q

Path Traversal in cordova-plugin-ionic-webview

CVSS3: 8.6
1%
Низкий
больше 6 лет назад
github логотип
GHSA-xwjg-qxv6-28rv

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xwjf-whc7-vgr2

Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCum16749.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjf-v823-v896

drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjc-m85h-pr32

A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will be called repeatedly and can lead to an infinite loop, resulting in a Denial of Service in the application linked to the library.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xwjc-4jxh-j5p8

Windows CSC Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1653, CVE-2021-1654, CVE-2021-1655, CVE-2021-1659, CVE-2021-1688, CVE-2021-1693.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xwj9-9vmw-m922

A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xwj7-29j7-rw76

Cross site scripting in Elefant CMS

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xwj6-mjhc-r3jc

Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwj6-f3wq-283g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Twerdy Genesis Style Shortcodes allows DOM-Based XSS.This issue affects Genesis Style Shortcodes: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xwj5-gj8r-8hr8

Unspecified vulnerability in BEA WebLogic Server 6.1 Gold through SP7 and 7.0 Gold through SP7 allows remote attackers to cause a denial of service (disk consumption) via certain malformed HTTP headers.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xwj5-fxxc-gf36

The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
9 дней назад
github логотип
GHSA-xwj5-5q25-vqmg

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.

CVSS3: 9.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xwj3-m7ch-j848

Memory corruption in HLOS while checking for the storage type.

CVSS3: 5.9
0%
Низкий
больше 1 года назад

Уязвимостей на страницу