Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 805

Количество 323 805

github логотип

GHSA-xvwm-fhx3-vrj9

почти 4 года назад

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xvwj-v9pv-cwjj

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mashiurz.com Plain Post allows Stored XSS.This issue affects Plain Post: from n/a through 1.0.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvwh-qhvg-2jjx

почти 4 года назад

While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvwg-32hp-p5p5

почти 4 года назад

The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.

EPSS: Низкий
github логотип

GHSA-xvwf-ffg2-9c6p

почти 4 года назад

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvwf-58fx-rg4f

около 1 года назад

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvwc-mxm8-8hqg

больше 1 года назад

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvwc-m4qj-9wr9

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in dan009 WP Bing Map Pro plugin < 5.0 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvw9-48jx-4p2f

11 месяцев назад

Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xvw9-3mhm-xjqq

больше 2 лет назад

Apache Airflow information disclosure vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvw8-w3w2-qpgq

почти 4 года назад

Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.

EPSS: Низкий
github логотип

GHSA-xvw8-mqg6-cchx

около 1 года назад

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvw8-h732-w84c

10 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-xvw6-gw98-7w9w

больше 2 лет назад

The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvw6-2phf-v6gr

9 месяцев назад

Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a through 1.0.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvw5-r9xw-9jjv

почти 4 года назад

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

EPSS: Низкий
github логотип

GHSA-xvw5-c4h4-r2rh

почти 4 года назад

Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvw3-v5p5-pf8m

больше 3 лет назад

A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not properly validate the RecordType-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvw3-ghj5-vvrf

почти 4 года назад

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).

EPSS: Средний
github логотип

GHSA-xvw3-fvp9-cwjw

больше 1 года назад

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvwm-fhx3-vrj9

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvwj-v9pv-cwjj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mashiurz.com Plain Post allows Stored XSS.This issue affects Plain Post: from n/a through 1.0.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvwh-qhvg-2jjx

While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvwg-32hp-p5p5

The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvwf-ffg2-9c6p

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvwf-58fx-rg4f

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xvwc-mxm8-8hqg

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvwc-m4qj-9wr9

Cross-Site Request Forgery (CSRF) vulnerability in dan009 WP Bing Map Pro plugin < 5.0 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvw9-48jx-4p2f

Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-xvw9-3mhm-xjqq

Apache Airflow information disclosure vulnerability

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvw8-w3w2-qpgq

Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvw8-mqg6-cchx

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xvw8-h732-w84c

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

10 месяцев назад
github логотип
GHSA-xvw6-gw98-7w9w

The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvw6-2phf-v6gr

Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a through 1.0.9.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xvw5-r9xw-9jjv

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvw5-c4h4-r2rh

Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.

CVSS3: 7.5
9%
Низкий
почти 4 года назад
github логотип
GHSA-xvw3-v5p5-pf8m

A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50). Affected devices do not properly validate the RecordType-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvw3-ghj5-vvrf

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).

11%
Средний
почти 4 года назад
github логотип
GHSA-xvw3-fvp9-cwjw

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

CVSS3: 7.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу