Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 360

Количество 324 360

github логотип

GHSA-xv3h-pcqm-3253

около 1 года назад

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv3h-4844-9h36

почти 3 года назад

HTTP Multiline Header Termination

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv3f-rvh8-r59c

почти 4 года назад

Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument to the xmlrpc_set_type function or (2) a crafted argument to the xmlrpc_decode function, related to an out-of-bounds read operation.

EPSS: Низкий
github логотип

GHSA-xv3f-8p4h-3w2r

почти 4 года назад

In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitable by an admin user because a .php file can be present in the extracted ZIP archive.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xv38-ph7h-p3qw

около 4 лет назад

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-xv38-944c-p763

почти 4 года назад

Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xv37-xpc4-25wq

почти 4 года назад

Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4372.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv37-j243-7jfv

почти 3 года назад

Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers to launch processes with elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv36-fxmx-5mpc

12 месяцев назад

A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-platform/src/main/java/top/aias/training/controller/LocalStorageController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xv35-w389-wr74

11 месяцев назад

HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv35-3wcg-v2qf

почти 2 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xv34-wq27-w2wm

почти 4 года назад

tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv34-vpcm-23p2

11 месяцев назад

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xv34-39fc-6ghr

почти 4 года назад

There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv33-m47j-6p6j

почти 4 года назад

Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.

EPSS: Низкий
github логотип

GHSA-xv33-44vw-w3qg

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to inject arbitrary web script or HTML via (1) the v, show, or sec_name parameters to main.php, (2) the inadmin, newsev, or postid parameters to 5.php, or (3) the id parameter to 0.php.

EPSS: Низкий
github логотип

GHSA-xv32-q7h7-g7hp

почти 4 года назад

Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request.

EPSS: Низкий
github логотип

GHSA-xv32-hwgf-r7x9

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Hotel Listing hotel-listing allows Reflected XSS.This issue affects Hotel Listing: from n/a through <= 1.4.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xv32-fpqh-v67r

9 месяцев назад

An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv32-4rjr-hg8q

почти 4 года назад

An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv3h-pcqm-3253

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xv3h-4844-9h36

HTTP Multiline Header Termination

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xv3f-rvh8-r59c

Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument to the xmlrpc_set_type function or (2) a crafted argument to the xmlrpc_decode function, related to an out-of-bounds read operation.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv3f-8p4h-3w2r

In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitable by an admin user because a .php file can be present in the extracted ZIP archive.

CVSS3: 7.2
3%
Низкий
почти 4 года назад
github логотип
GHSA-xv38-ph7h-p3qw

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

8%
Низкий
около 4 лет назад
github логотип
GHSA-xv38-944c-p763

Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.

CVSS3: 9.8
14%
Средний
почти 4 года назад
github логотип
GHSA-xv37-xpc4-25wq

Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4372.

CVSS3: 9.8
8%
Низкий
почти 4 года назад
github логотип
GHSA-xv37-j243-7jfv

Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers to launch processes with elevated privileges.

CVSS3: 7.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xv36-fxmx-5mpc

A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-platform/src/main/java/top/aias/training/controller/LocalStorageController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-xv35-w389-wr74

HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xv35-3wcg-v2qf

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

CVSS3: 8.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv34-wq27-w2wm

tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv34-vpcm-23p2

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.

CVSS3: 7.1
1%
Низкий
11 месяцев назад
github логотип
GHSA-xv34-39fc-6ghr

There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xv33-m47j-6p6j

Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv33-44vw-w3qg

Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to inject arbitrary web script or HTML via (1) the v, show, or sec_name parameters to main.php, (2) the inadmin, newsev, or postid parameters to 5.php, or (3) the id parameter to 0.php.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xv32-q7h7-g7hp

Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv32-hwgf-r7x9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Hotel Listing hotel-listing allows Reflected XSS.This issue affects Hotel Listing: from n/a through <= 1.4.0.

CVSS3: 7.1
0%
Низкий
2 месяца назад
github логотип
GHSA-xv32-fpqh-v67r

An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise.

CVSS3: 9.8
10%
Низкий
9 месяцев назад
github логотип
GHSA-xv32-4rjr-hg8q

An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.

58%
Средний
почти 4 года назад

Уязвимостей на страницу