Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-xxp7-f9hw-8j74

больше 3 лет назад

Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxp7-423f-hcp4

больше 3 лет назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-xxp6-vwcq-7x73

около 3 лет назад

Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy Measurement Unit, Refrigerator, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, Ventilating Fan, Range hood fan, Energy Measurement Unit and Air Purifier) allows a remote unauthenticated attacker to disclose information in the products or cause a denial of service (DoS) condition as a result by sniffing credential information (username and password). The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is list...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxp6-fq36-p8jx

11 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shamalli Web Directory Free allows Blind SQL Injection. This issue affects Web Directory Free: from n/a through 1.7.6.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-xxp6-493w-583x

почти 4 года назад

A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle malformed Multicast LLC frames. This could allow an attacker to trigger a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxp5-q6rf-mmr6

больше 2 лет назад

Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2200HP all versions allows a attacker to obtain specific files in the product .

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxp5-f86m-3v5v

больше 3 лет назад

Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxp5-8cpw-353h

больше 3 лет назад

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxp5-838q-65wj

почти 4 года назад

cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack.

EPSS: Низкий
github логотип

GHSA-xxp5-7q7f-j96c

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters.

EPSS: Низкий
github логотип

GHSA-xxp4-q5hx-j33x

больше 3 лет назад

WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-3 and APPLE-SA-2015-04-08-4.

EPSS: Низкий
github логотип

GHSA-xxp4-mf4h-6cwm

больше 2 лет назад

Moodle vulnerable to Server Side Request Forgery

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxp4-hw2v-2vcr

больше 3 лет назад

In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxp3-mm76-hhf2

больше 3 лет назад

EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xxp3-fcv5-mx3m

больше 3 лет назад

JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data.

EPSS: Низкий
github логотип

GHSA-xxp2-cp36-7xm7

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.

EPSS: Низкий
github логотип

GHSA-xxp2-9c9g-7wmj

почти 2 года назад

XWiki Platform: Remote code execution from edit in multilingual wikis via translations

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-xxmw-m6v2-9h47

около 2 лет назад

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxmv-v72m-r6w4

почти 4 года назад

The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.

EPSS: Низкий
github логотип

GHSA-xxmv-mjx9-wg53

больше 3 лет назад

Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxp7-f9hw-8j74

Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxp7-423f-hcp4

ChakraCore RCE Vulnerability

CVSS3: 7.5
80%
Высокий
больше 3 лет назад
github логотип
GHSA-xxp6-vwcq-7x73

Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy Measurement Unit, Refrigerator, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, Ventilating Fan, Range hood fan, Energy Measurement Unit and Air Purifier) allows a remote unauthenticated attacker to disclose information in the products or cause a denial of service (DoS) condition as a result by sniffing credential information (username and password). The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is list...

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xxp6-fq36-p8jx

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shamalli Web Directory Free allows Blind SQL Injection. This issue affects Web Directory Free: from n/a through 1.7.6.

CVSS3: 9.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxp6-493w-583x

A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle malformed Multicast LLC frames. This could allow an attacker to trigger a denial of service condition.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxp5-q6rf-mmr6

Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2200HP all versions allows a attacker to obtain specific files in the product .

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxp5-f86m-3v5v

Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxp5-8cpw-353h

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxp5-838q-65wj

cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xxp5-7q7f-j96c

Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xxp4-q5hx-j33x

WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-3 and APPLE-SA-2015-04-08-4.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xxp4-mf4h-6cwm

Moodle vulnerable to Server Side Request Forgery

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxp4-hw2v-2vcr

In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxp3-mm76-hhf2

EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxp3-fcv5-mx3m

JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxp2-cp36-7xm7

Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxp2-9c9g-7wmj

XWiki Platform: Remote code execution from edit in multilingual wikis via translations

CVSS3: 9.9
36%
Средний
почти 2 года назад
github логотип
GHSA-xxmw-m6v2-9h47

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxmv-v72m-r6w4

The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.

7%
Низкий
почти 4 года назад
github логотип
GHSA-xxmv-mjx9-wg53

Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу