Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-44vr-phh9-75gf

больше 2 лет назад

Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44vr-jgwf-45qh

больше 3 лет назад

Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows remote attackers to cause a denial of service (apparent browser locking) via a crafted web site.

EPSS: Низкий
github логотип

GHSA-44vq-rpm7-q5q6

больше 1 года назад

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'end' in '/admin/mod_reports/printreport.php' parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-44vq-656c-r27f

около 2 лет назад

Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-44vp-vgqf-7p46

почти 4 года назад

Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a .. (dot dot) in the wfe_download parameter to index.fpl.

EPSS: Низкий
github логотип

GHSA-44vp-c93r-6656

около 1 месяца назад

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-44vp-7rx3-4q44

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-2005-2441.

EPSS: Низкий
github логотип

GHSA-44vm-vqjx-569p

больше 3 лет назад

The Atecea (aka com.atecea) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-44vm-qvr4-f42v

больше 3 лет назад

IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159186.

EPSS: Низкий
github логотип

GHSA-44vm-4hjc-7h7x

больше 3 лет назад

NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-44vj-x828-cfmj

11 месяцев назад

Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-44vj-whpr-3frv

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: netlink: do not hard code device address lenth in fdb dumps syzbot reports that some netdev devices do not have a six bytes address [1] Replace ETH_ALEN by dev->addr_len. [1] (Case of a device where dev->addr_len = 4) BUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline] BUG: KMSAN: kernel-infoleak in copyout+0xb8/0x100 lib/iov_iter.c:169 instrument_copy_to_user include/linux/instrumented.h:114 [inline] copyout+0xb8/0x100 lib/iov_iter.c:169 _copy_to_iter+0x6d8/0x1d00 lib/iov_iter.c:536 copy_to_iter include/linux/uio.h:206 [inline] simple_copy_to_iter+0x68/0xa0 net/core/datagram.c:513 __skb_datagram_iter+0x123/0xdc0 net/core/datagram.c:419 skb_copy_datagram_iter+0x5c/0x200 net/core/datagram.c:527 skb_copy_datagram_msg include/linux/skbuff.h:3960 [inline] netlink_recvmsg+0x4ae/0x15a0 net/netlink/af_netlink.c:1970 sock_recvmsg_nosec net/socket.c:1019 [inline] sock_recvmsg...

EPSS: Низкий
github логотип

GHSA-44vj-49qr-87q3

2 дня назад

The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags without authorization checks. This makes it possible for unauthenticated attackers to extract arbitrary post metadata from any post on the site, including sensitive data such as WooCommerce billing emails, API keys, private tokens, and customer personal information via the `nf_ajax_submit` AJAX action.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-44vj-36hg-g8rr

больше 3 лет назад

An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

EPSS: Низкий
github логотип

GHSA-44vh-88m4-ph9w

12 месяцев назад

This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other user accounts.

EPSS: Низкий
github логотип

GHSA-44vh-63c5-9hxh

23 дня назад

Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the Orders page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-44vh-5qrj-pfch

больше 3 лет назад

Improper buffer restrictions for some Intel(R) NUC 9 Extreme Laptop Kit drivers before version 2.2.0.22 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-44vf-h2q2-97cq

больше 3 лет назад

The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute arbitrary unsigned code via a crafted app.

EPSS: Низкий
github логотип

GHSA-44vf-8ffm-v2qh

больше 5 лет назад

Sensitive Data Exposure in rails-session-decoder

EPSS: Низкий
github логотип

GHSA-44vf-6vfg-98jr

28 дней назад

Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-44vr-phh9-75gf

Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-44vr-jgwf-45qh

Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows remote attackers to cause a denial of service (apparent browser locking) via a crafted web site.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-44vq-rpm7-q5q6

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'end' in '/admin/mod_reports/printreport.php' parameter.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-44vq-656c-r27f

Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.

CVSS3: 9.8
2%
Низкий
около 2 лет назад
github логотип
GHSA-44vp-vgqf-7p46

Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a .. (dot dot) in the wfe_download parameter to index.fpl.

0%
Низкий
почти 4 года назад
github логотип
GHSA-44vp-c93r-6656

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-44vp-7rx3-4q44

Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-2005-2441.

1%
Низкий
почти 4 года назад
github логотип
GHSA-44vm-vqjx-569p

The Atecea (aka com.atecea) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-44vm-qvr4-f42v

IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159186.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-44vm-4hjc-7h7x

NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.

CVSS3: 9.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44vj-x828-cfmj

Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.

CVSS3: 4.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-44vj-whpr-3frv

In the Linux kernel, the following vulnerability has been resolved: netlink: do not hard code device address lenth in fdb dumps syzbot reports that some netdev devices do not have a six bytes address [1] Replace ETH_ALEN by dev->addr_len. [1] (Case of a device where dev->addr_len = 4) BUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline] BUG: KMSAN: kernel-infoleak in copyout+0xb8/0x100 lib/iov_iter.c:169 instrument_copy_to_user include/linux/instrumented.h:114 [inline] copyout+0xb8/0x100 lib/iov_iter.c:169 _copy_to_iter+0x6d8/0x1d00 lib/iov_iter.c:536 copy_to_iter include/linux/uio.h:206 [inline] simple_copy_to_iter+0x68/0xa0 net/core/datagram.c:513 __skb_datagram_iter+0x123/0xdc0 net/core/datagram.c:419 skb_copy_datagram_iter+0x5c/0x200 net/core/datagram.c:527 skb_copy_datagram_msg include/linux/skbuff.h:3960 [inline] netlink_recvmsg+0x4ae/0x15a0 net/netlink/af_netlink.c:1970 sock_recvmsg_nosec net/socket.c:1019 [inline] sock_recvmsg...

0%
Низкий
2 месяца назад
github логотип
GHSA-44vj-49qr-87q3

The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags without authorization checks. This makes it possible for unauthenticated attackers to extract arbitrary post metadata from any post on the site, including sensitive data such as WooCommerce billing emails, API keys, private tokens, and customer personal information via the `nf_ajax_submit` AJAX action.

CVSS3: 7.5
0%
Низкий
2 дня назад
github логотип
GHSA-44vj-36hg-g8rr

An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-44vh-88m4-ph9w

This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other user accounts.

0%
Низкий
12 месяцев назад
github логотип
GHSA-44vh-63c5-9hxh

Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the Orders page.

CVSS3: 6.5
0%
Низкий
23 дня назад
github логотип
GHSA-44vh-5qrj-pfch

Improper buffer restrictions for some Intel(R) NUC 9 Extreme Laptop Kit drivers before version 2.2.0.22 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44vf-h2q2-97cq

The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute arbitrary unsigned code via a crafted app.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-44vf-8ffm-v2qh

Sensitive Data Exposure in rails-session-decoder

больше 5 лет назад
github логотип
GHSA-44vf-6vfg-98jr

Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

CVSS3: 7.5
0%
Низкий
28 дней назад

Уязвимостей на страницу