Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 322 820

Количество 322 820

github логотип

GHSA-xxmc-92m2-3hhc

почти 4 года назад

Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0758, CVE-2018-0762, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0772, CVE-2018-0774, CVE-2018-0775, CVE-2018-0776, CVE-2018-0777, CVE-2018-0778, and CVE-2018-0781.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xxm9-gr2r-5m67

почти 4 года назад

Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxm8-g43m-x669

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Sidebar Manager Light allows Cross Site Request Forgery. This issue affects Sidebar Manager Light: from n/a through 1.18.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxm7-jh4x-3p4j

почти 4 года назад

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device nay need to be manually reloaded to recover. The vulnerability is due to lack of proper input throttling of ingress SNMP traffic over an internal interface. An attacker could exploit this vulnerability by sending a crafted, heavy stream of SNMP traffic to the targeted device. An exploit could allow the attacker to cause the device to reload unexpectedly, causing a DoS condition. Cisco Bug IDs: CSCvg22135.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-xxm7-5wvh-7jr4

почти 4 года назад

FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly handle a certain failure to allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash, and recovery failure) by specifying a large size value within TCP packet data. NOTE: this might overlap CVE-2010-3061.

EPSS: Низкий
github логотип

GHSA-xxm7-22wp-69jx

почти 4 года назад

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxm6-ff3x-v4vm

почти 3 года назад

thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via category field name parameter

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxm6-c9w6-3g54

почти 4 года назад

Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.

EPSS: Низкий
github логотип

GHSA-xxm5-p2jg-xh9g

почти 4 года назад

SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.

EPSS: Низкий
github логотип

GHSA-xxm5-g29j-f9vq

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

EPSS: Низкий
github логотип

GHSA-xxm4-m7f5-mqxf

7 месяцев назад

Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer allows Object Injection. This issue affects ThemeMakers Visual Content Composer: from n/a through 1.5.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxm4-g3v8-g83q

больше 2 лет назад

In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xxm4-8498-pwrr

почти 4 года назад

Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.

EPSS: Низкий
github логотип

GHSA-xxm4-3cqf-2pcc

почти 4 года назад

PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CFG[auth_phpbb_path] parameter.

EPSS: Низкий
github логотип

GHSA-xxm3-fp55-pm48

почти 4 года назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xxjw-vw5q-j33v

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxjw-q2gq-6w22

почти 4 года назад

Windows Kernel Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28309.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxjw-mqrg-2r3c

около 1 года назад

Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0.3.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xxjw-jpj3-73mg

больше 3 лет назад

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjw-jphq-5x96

почти 4 года назад

The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxmc-92m2-3hhc

Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0758, CVE-2018-0762, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0772, CVE-2018-0774, CVE-2018-0775, CVE-2018-0776, CVE-2018-0777, CVE-2018-0778, and CVE-2018-0781.

CVSS3: 7.5
24%
Средний
почти 4 года назад
github логотип
GHSA-xxm9-gr2r-5m67

Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxm8-g43m-x669

Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Sidebar Manager Light allows Cross Site Request Forgery. This issue affects Sidebar Manager Light: from n/a through 1.18.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxm7-jh4x-3p4j

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device nay need to be manually reloaded to recover. The vulnerability is due to lack of proper input throttling of ingress SNMP traffic over an internal interface. An attacker could exploit this vulnerability by sending a crafted, heavy stream of SNMP traffic to the targeted device. An exploit could allow the attacker to cause the device to reload unexpectedly, causing a DoS condition. Cisco Bug IDs: CSCvg22135.

CVSS3: 7.7
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxm7-5wvh-7jr4

FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly handle a certain failure to allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash, and recovery failure) by specifying a large size value within TCP packet data. NOTE: this might overlap CVE-2010-3061.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xxm7-22wp-69jx

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxm6-ff3x-v4vm

thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via category field name parameter

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxm6-c9w6-3g54

Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.

8%
Низкий
почти 4 года назад
github логотип
GHSA-xxm5-p2jg-xh9g

SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxm5-g29j-f9vq

Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxm4-m7f5-mqxf

Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer allows Object Injection. This issue affects ThemeMakers Visual Content Composer: from n/a through 1.5.8.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-xxm4-g3v8-g83q

In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxm4-8498-pwrr

Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxm4-3cqf-2pcc

PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CFG[auth_phpbb_path] parameter.

8%
Низкий
почти 4 года назад
github логотип
GHSA-xxm3-fp55-pm48

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 8.1
2%
Низкий
почти 4 года назад
github логотип
GHSA-xxjw-vw5q-j33v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-xxjw-q2gq-6w22

Windows Kernel Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-28309.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxjw-mqrg-2r3c

Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0.3.

CVSS3: 9.9
0%
Низкий
около 1 года назад
github логотип
GHSA-xxjw-jpj3-73mg

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxjw-jphq-5x96

The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу