Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 290 712

Количество 290 712

github логотип

GHSA-xw27-78pr-xvhr

больше 2 лет назад

The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xw27-367x-744q

больше 3 лет назад

Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to suricata_rules_flowbits.php or (2) the returl parameter to suricata_select_alias.php.

EPSS: Низкий
github логотип

GHSA-xw26-rv7f-j6w8

больше 3 лет назад

Windows Update Stack Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xw24-w9w2-xw4q

больше 3 лет назад

A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to increased privileges. An attacker can send a malicious IRP to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xw24-fjv7-8w94

около 2 лет назад

A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xw24-f63w-vq32

больше 3 лет назад

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to obtain sensitive information by leveraging symlink mishandling.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xw24-98q7-5jvx

больше 3 лет назад

AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

EPSS: Высокий
github логотип

GHSA-xw22-wv29-3299

больше 4 лет назад

ApiKey secret could be revelated on network issue

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xvxx-vrh7-xh3v

больше 3 лет назад

A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvxv-v375-9q9p

больше 3 лет назад

The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xvxr-rrxw-rfp9

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: EDAC/highbank: Fix memory leak in highbank_mc_probe() When devres_open_group() fails, it returns -ENOMEM without freeing memory allocated by edac_mc_alloc(). Call edac_mc_free() on the error handling path to avoid a memory leak. [ bp: Massage commit message. ]

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvxr-fcpp-g423

больше 3 лет назад

The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.

EPSS: Низкий
github логотип

GHSA-xvxr-4f6g-g73v

больше 3 лет назад

SQL injection vulnerability in Epicor Procurement before 7.4 SP2 allows remote attackers to execute arbitrary SQL commands via the User field.

EPSS: Низкий
github логотип

GHSA-xvxq-r6r9-xm62

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in testingLibraryAction.do in the Training Center testing library in Cisco WebEx Training Center allows remote attackers to hijack the authentication of arbitrary users for requests that delete tests, aka Bug ID CSCzu81067.

EPSS: Низкий
github логотип

GHSA-xvxq-p298-r7fw

больше 3 лет назад

The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvxq-hq48-xphm

больше 3 лет назад

Sandbox bypass in Script Security Plugin

CVSS3: 9.9
EPSS: Критический
github логотип

GHSA-xvxq-g8hw-fx4g

10 месяцев назад

OctoPrint Vulnerable to Reflected XSS in Jinja2 Templates

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvxq-7q9x-g29m

больше 1 года назад

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvxp-rj85-x563

больше 3 лет назад

The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvxm-rm97-hmmp

около 3 лет назад

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30141, CVE-2022-30143, CVE-2022-30146, CVE-2022-30149, CVE-2022-30153, CVE-2022-30161.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw27-78pr-xvhr

The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xw27-367x-744q

Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to suricata_rules_flowbits.php or (2) the returl parameter to suricata_select_alias.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw26-rv7f-j6w8

Windows Update Stack Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xw24-w9w2-xw4q

A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to increased privileges. An attacker can send a malicious IRP to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xw24-fjv7-8w94

A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xw24-f63w-vq32

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "ATS" component. It allows attackers to obtain sensitive information by leveraging symlink mishandling.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xw24-98q7-5jvx

AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

88%
Высокий
больше 3 лет назад
github логотип
GHSA-xw22-wv29-3299

ApiKey secret could be revelated on network issue

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvxx-vrh7-xh3v

A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvxv-v375-9q9p

The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."

CVSS3: 3.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvxr-rrxw-rfp9

In the Linux kernel, the following vulnerability has been resolved: EDAC/highbank: Fix memory leak in highbank_mc_probe() When devres_open_group() fails, it returns -ENOMEM without freeing memory allocated by edac_mc_alloc(). Call edac_mc_free() on the error handling path to avoid a memory leak. [ bp: Massage commit message. ]

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xvxr-fcpp-g423

The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvxr-4f6g-g73v

SQL injection vulnerability in Epicor Procurement before 7.4 SP2 allows remote attackers to execute arbitrary SQL commands via the User field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvxq-r6r9-xm62

Cross-site request forgery (CSRF) vulnerability in testingLibraryAction.do in the Training Center testing library in Cisco WebEx Training Center allows remote attackers to hijack the authentication of arbitrary users for requests that delete tests, aka Bug ID CSCzu81067.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvxq-p298-r7fw

The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvxq-hq48-xphm

Sandbox bypass in Script Security Plugin

CVSS3: 9.9
91%
Критический
больше 3 лет назад
github логотип
GHSA-xvxq-g8hw-fx4g

OctoPrint Vulnerable to Reflected XSS in Jinja2 Templates

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xvxq-7q9x-g29m

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvxp-rj85-x563

The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvxm-rm97-hmmp

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30141, CVE-2022-30143, CVE-2022-30146, CVE-2022-30149, CVE-2022-30153, CVE-2022-30161.

CVSS3: 7.5
6%
Низкий
около 3 лет назад

Уязвимостей на страницу