Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-453m-fcx3-j43g

около 1 года назад

An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-453j-q27h-5p8x

7 месяцев назад

NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-453j-gwgw-838r

больше 2 лет назад

Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-453j-2h25-w552

около 4 лет назад

There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-453h-cfq2-hp69

больше 3 лет назад

The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted XSS can also leak into the frontpage.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-453g-g6g4-pqp9

больше 3 лет назад

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion engine when processing Enhanced Metafile Format Plus (EMF+) data. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-453g-5mrh-qccr

около 1 года назад

Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-453c-xr7g-2ph7

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-453c-q86v-w8mr

больше 3 лет назад

The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.

EPSS: Низкий
github логотип

GHSA-453c-jgvw-m9c9

больше 3 лет назад

The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-453c-hx6c-v5gq

больше 3 лет назад

IBM Cloud App Management 2019.3.0 and 2019.4.0 reveals a stack trace on certain API requests which can allow an attacker further information about the implementation of the offering. IBM X-Force ID: 173311.

EPSS: Низкий
github логотип

GHSA-453c-44v9-38fg

почти 4 года назад

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could cause the files to be extracted with less restrictive permissions than intended.

EPSS: Низкий
github логотип

GHSA-4539-59fr-99v5

больше 3 лет назад

Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4538-wpvw-289w

больше 3 лет назад

A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'.

EPSS: Низкий
github логотип

GHSA-4538-g7mm-6mqj

почти 4 года назад

The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.

EPSS: Низкий
github логотип

GHSA-4538-79hx-662c

больше 3 лет назад

An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4537-mgq5-cjx2

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the _hosting_task_log_table function in modules/hosting/task/hosting_task.module in the Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a Drush log message in a provision task log.

EPSS: Низкий
github логотип

GHSA-4537-99v8-qchg

почти 4 года назад

AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) does not properly validate the origin of the configuration web page (options2.html), which allows user-assisted remote attackers to provide a web page that contains disguised checkboxes that trick the user into reconfiguring the toolbar.

EPSS: Низкий
github логотип

GHSA-4537-7frr-vvgx

почти 4 года назад

SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter.

EPSS: Низкий
github логотип

GHSA-4536-pp2v-fh9m

больше 3 лет назад

An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-453m-fcx3-j43g

An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.1
1%
Низкий
около 1 года назад
github логотип
GHSA-453j-q27h-5p8x

NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix

CVSS3: 5.9
0%
Низкий
7 месяцев назад
github логотип
GHSA-453j-gwgw-838r

Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-453j-2h25-w552

There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

CVSS3: 9.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-453h-cfq2-hp69

The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted XSS can also leak into the frontpage.

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-453g-g6g4-pqp9

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion engine when processing Enhanced Metafile Format Plus (EMF+) data. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-453g-5mrh-qccr

Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

CVSS3: 8.1
1%
Низкий
около 1 года назад
github логотип
GHSA-453c-xr7g-2ph7

Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-453c-q86v-w8mr

The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-453c-jgvw-m9c9

The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-453c-hx6c-v5gq

IBM Cloud App Management 2019.3.0 and 2019.4.0 reveals a stack trace on certain API requests which can allow an attacker further information about the implementation of the offering. IBM X-Force ID: 173311.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-453c-44v9-38fg

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could cause the files to be extracted with less restrictive permissions than intended.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4539-59fr-99v5

Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4538-wpvw-289w

A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-4538-g7mm-6mqj

The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.

1%
Низкий
почти 4 года назад
github логотип
GHSA-4538-79hx-662c

An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4537-mgq5-cjx2

Cross-site scripting (XSS) vulnerability in the _hosting_task_log_table function in modules/hosting/task/hosting_task.module in the Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a Drush log message in a provision task log.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4537-99v8-qchg

AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) does not properly validate the origin of the configuration web page (options2.html), which allows user-assisted remote attackers to provide a web page that contains disguised checkboxes that trick the user into reconfiguring the toolbar.

1%
Низкий
почти 4 года назад
github логотип
GHSA-4537-7frr-vvgx

SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-4536-pp2v-fh9m

An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу