GitHub
GitHub is a web-based hosting service for version control using Git.
54,019 tracked projects
Public Registry
github.comPublic registry metadata is sourced from known upstream package ecosystems.
Find Project in GitHub
| Project | Description |
|---|---|
Synology NAS API client written in Ruby | |
In Paradox Security System IPR512 web panel, an unauthenticated user can input JavaScript string, such as </script> that will overwrite configurations in the file "login.xml" and cause the login form to crash and make it unavailable. | |
A rule-based tunnel in Go. | |
A SQL Injection issue in Simple Onlne Public Access Catalog (OPAC) v.1.0 allows an attacker to log in into admin account. | |
SSRF Vulnerability on Website Link Extractor | |
This flaw enables attackers to manipulate SQL queries and exfiltrate sensitive data (e.g., administrative credentials), which can lead to complete system compromise. | |
This PoC allows for boolean-based blind, time-based blind, and UNION-based injection techniques, enabling database enumeration and data exfiltration. | |
This flaw enables attackers to manipulate SQL queries and exfiltrate sensitive data (e.g., administrative credentials), which can lead to complete system compromise. | |
The Personal Time Tracker web application is vulnerable to Reflected Cross-Site Scripting (XSS) in the project name input. | |
An authenticated attacker can upload arbitrary files, including PHP code, instead of restricted image files. This results in Remote Code Execution (RCE) on the hosting server. | |
An attacker can upload files to arbitrary directories under ../media/, including hidden ones. Though execution isn't possible, this can flood directories, exhaust disk space, and degrade performance or cause denial-of-service. | |
The user_search_ajax.php file is vulnerable to SQL injection due to improper handling of user-supplied input. User inputs are passed directly to the database query without proper parameterization or prepared statements. | |
This flaw allows attackers to perform time-based inference attacks to extract database content, including usernames and password hashes, ultimately leading to full compromise of authentication credentials. | |
Cinema 4D out-of-bounds write vulnerability when parsing c4d files | |
Mirror of http://drupal.org/project/email_registration provided by hubdrop. | |
Manage time synchronization, NTP server and timezone | |
Philipinho Simple-PHP-Blog//new.phpxss注入漏洞 | |
¯\_(ツ)_/¯ | |
Get a grip on stdout in your async code | |
res.json() for connect, with JSONP. | |
Official Source of public vulnerability disclosures published by DTS Researchers |