Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-xvw3-v5p5-pf8m

больше 3 лет назад

A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not properly validate the RecordType-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvw3-ghj5-vvrf

почти 4 года назад

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).

EPSS: Средний
github логотип

GHSA-xvw3-fvp9-cwjw

около 1 года назад

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvw3-6q4f-2gcv

почти 3 года назад

A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvw2-m4qw-qqh5

около 2 месяцев назад

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_networkId_merge.lua.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvvx-wf8m-v58j

около 1 месяца назад

The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] parameter in all versions up to, and including, 0.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvvx-jmvr-f8rg

больше 3 лет назад

The sell function of a smart contract implementation for Nectar (NCTR), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvvx-g2mg-wqw5

21 день назад

A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in the library clay.h. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xvvw-m6mf-m9hw

почти 2 года назад

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvvw-7mhx-953j

больше 3 лет назад

The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 26404525.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xvvv-wj7j-r9jm

около 4 лет назад

Cross-site Scripting in Netgen Tags Bundle

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvvv-9ch3-x72q

3 месяца назад

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked storage device.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xvvv-2v53-5hxv

около 2 лет назад

Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvvr-j3h8-fxhr

больше 3 лет назад

A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP) connections, aka "Windows FTP Server Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xvvr-9vfw-4qv3

больше 3 лет назад

cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).

EPSS: Низкий
github логотип

GHSA-xvvq-jrv9-gg3p

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: mlxbf_gige: stop interface during shutdown The mlxbf_gige driver intermittantly encounters a NULL pointer exception while the system is shutting down via "reboot" command. The mlxbf_driver will experience an exception right after executing its shutdown() method. One example of this exception is: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000070 Mem abort info: ESR = 0x0000000096000004 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000004 CM = 0, WnR = 0 user pgtable: 4k pages, 48-bit VAs, pgdp=000000011d373000 [0000000000000070] pgd=0000000000000000, p4d=0000000000000000 Internal error: Oops: 96000004 [#1] SMP CPU: 0 PID: 13 Comm: ksoftirqd/0 Tainted: G S OE 5.15.0-bf.6.gef6992a #1 Hardware name: https://www.mellanox.com BlueField SoC/BlueField SoC,...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvvq-jr85-m2g9

почти 4 года назад

Unspecified vulnerability in Internet Directory in Oracle Database Server 9i up to 9.2.0.6 and Application Server 9.0.2.3 up to 10.1.2.0 has unknown impact and attack vectors, aka Oracle Vuln# DB32 and AS06.

EPSS: Низкий
github логотип

GHSA-xvvq-9gm4-v7vp

больше 3 лет назад

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX+0x0000000000007236."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvvp-cjh4-8phq

почти 2 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-xvvj-jq67-6g88

почти 3 года назад

The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvw3-v5p5-pf8m

A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not properly validate the RecordType-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvw3-ghj5-vvrf

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).

17%
Средний
почти 4 года назад
github логотип
GHSA-xvw3-fvp9-cwjw

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xvw3-6q4f-2gcv

A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xvw2-m4qw-qqh5

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_networkId_merge.lua.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xvvx-wf8m-v58j

The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] parameter in all versions up to, and including, 0.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xvvx-jmvr-f8rg

The sell function of a smart contract implementation for Nectar (NCTR), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvvx-g2mg-wqw5

A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in the library clay.h. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.3
0%
Низкий
21 день назад
github логотип
GHSA-xvvw-m6mf-m9hw

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.

CVSS3: 6.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-xvvw-7mhx-953j

The Qualcomm MDP driver in Android before 2016-05-01 on Nexus 5 and Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 26404525.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvvv-wj7j-r9jm

Cross-site Scripting in Netgen Tags Bundle

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-xvvv-9ch3-x72q

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked storage device.

CVSS3: 4.4
0%
Низкий
3 месяца назад
github логотип
GHSA-xvvv-2v53-5hxv

Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvvr-j3h8-fxhr

A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP) connections, aka "Windows FTP Server Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 7.5
15%
Средний
больше 3 лет назад
github логотип
GHSA-xvvr-9vfw-4qv3

cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvvq-jrv9-gg3p

In the Linux kernel, the following vulnerability has been resolved: mlxbf_gige: stop interface during shutdown The mlxbf_gige driver intermittantly encounters a NULL pointer exception while the system is shutting down via "reboot" command. The mlxbf_driver will experience an exception right after executing its shutdown() method. One example of this exception is: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000070 Mem abort info: ESR = 0x0000000096000004 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000004 CM = 0, WnR = 0 user pgtable: 4k pages, 48-bit VAs, pgdp=000000011d373000 [0000000000000070] pgd=0000000000000000, p4d=0000000000000000 Internal error: Oops: 96000004 [#1] SMP CPU: 0 PID: 13 Comm: ksoftirqd/0 Tainted: G S OE 5.15.0-bf.6.gef6992a #1 Hardware name: https://www.mellanox.com BlueField SoC/BlueField SoC,...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvvq-jr85-m2g9

Unspecified vulnerability in Internet Directory in Oracle Database Server 9i up to 9.2.0.6 and Application Server 9.0.2.3 up to 10.1.2.0 has unknown impact and attack vectors, aka Oracle Vuln# DB32 and AS06.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xvvq-9gm4-v7vp

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX+0x0000000000007236."

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvvp-cjh4-8phq

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

почти 2 года назад
github логотип
GHSA-xvvj-jq67-6g88

The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.

CVSS3: 9.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу