Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-xvrg-83h8-x5v4

почти 4 года назад

Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.

EPSS: Низкий
github логотип

GHSA-xvrf-q22w-5f48

почти 4 года назад

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvrf-gvhf-wxf6

почти 4 года назад

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

EPSS: Низкий
github логотип

GHSA-xvrf-3569-2x76

почти 2 года назад

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvrc-cwrh-jw5g

6 месяцев назад

Deserialization of Untrusted Data vulnerability in rascals Noisa allows Object Injection. This issue affects Noisa: from n/a through 2.6.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvrc-2wvh-49vc

около 2 лет назад

Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-xvr9-jr9p-grf3

больше 3 лет назад

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

EPSS: Низкий
github логотип

GHSA-xvr9-h38m-rc5q

около 4 лет назад

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

EPSS: Низкий
github логотип

GHSA-xvr9-7fjx-5335

почти 4 года назад

Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xvr9-244h-6gg8

около 1 года назад

Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvr8-rhg7-pv7w

больше 3 лет назад

Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvr7-xmmp-p9vr

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing allows Reflected XSS. This issue affects Classified Listing: from n/a through 4.0.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvr7-p2c6-j83w

6 месяцев назад

swift-nio-http2 affected by HTTP/2 MadeYouReset vulnerability

EPSS: Низкий
github логотип

GHSA-xvr7-j937-8w46

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.

EPSS: Низкий
github логотип

GHSA-xvr7-55fh-xx8f

почти 4 года назад

Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

EPSS: Низкий
github логотип

GHSA-xvr6-m6gq-m42f

больше 3 лет назад

SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvr6-486p-g4pg

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arevico WP Tactical Popup wp-tactical-popup allows Reflected XSS.This issue affects WP Tactical Popup: from n/a through <= 1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvr5-pqwf-8crh

больше 3 лет назад

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvr5-gpgm-56cv

почти 4 года назад

Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.

EPSS: Средний
github логотип

GHSA-xvr4-pc95-4727

больше 3 лет назад

A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvrg-83h8-x5v4

Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvrf-q22w-5f48

ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvrf-gvhf-wxf6

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvrf-3569-2x76

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvrc-cwrh-jw5g

Deserialization of Untrusted Data vulnerability in rascals Noisa allows Object Injection. This issue affects Noisa: from n/a through 2.6.0.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xvrc-2wvh-49vc

Gitsign's Rekor public keys fetched from upstream API instead of local TUF client.

CVSS3: 4.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvr9-jr9p-grf3

PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicious code.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr9-h38m-rc5q

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

0%
Низкий
около 4 лет назад
github логотип
GHSA-xvr9-7fjx-5335

Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvr9-244h-6gg8

Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xvr8-rhg7-pv7w

Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr7-xmmp-p9vr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing allows Reflected XSS. This issue affects Classified Listing: from n/a through 4.0.1.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-xvr7-p2c6-j83w

swift-nio-http2 affected by HTTP/2 MadeYouReset vulnerability

6 месяцев назад
github логотип
GHSA-xvr7-j937-8w46

Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xvr7-55fh-xx8f

Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvr6-m6gq-m42f

SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr6-486p-g4pg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arevico WP Tactical Popup wp-tactical-popup allows Reflected XSS.This issue affects WP Tactical Popup: from n/a through <= 1.1.

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-xvr5-pqwf-8crh

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xvr5-gpgm-56cv

Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.

26%
Средний
почти 4 года назад
github логотип
GHSA-xvr4-pc95-4727

A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу