Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-445m-8cc6-89hr

больше 3 лет назад

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-445m-62c2-rw3m

больше 3 лет назад

Baramundi Management Suite 7.5 through 8.9 uses cleartext for (1) client-server communication and (2) data storage, which allows remote attackers to obtain sensitive information by sniffing the network, and allows context-dependent attackers to obtain sensitive information by reading a file.

EPSS: Низкий
github логотип

GHSA-445m-27cf-gr3x

10 месяцев назад

Crawl4AI SSRF vulnerability

EPSS: Низкий
github логотип

GHSA-445j-hjgc-x696

больше 3 лет назад

Modem segments are unlocked after authentication, leaving modem segments open to all in Snapdragon Mobile, Snapdragon Wear in version MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-445j-3fj5-rxgh

почти 3 года назад

The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-445h-32ch-3r5v

около 4 лет назад

There is a Null pointer dereference in Smartphones.Successful exploitation of this vulnerability may cause the kernel to break down.

EPSS: Низкий
github логотип

GHSA-445h-22pr-cp5g

больше 3 лет назад

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.

EPSS: Низкий
github логотип

GHSA-445g-h2v6-5fxw

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AppStudioUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13894.

EPSS: Низкий
github логотип

GHSA-445f-cm55-gq8v

около 2 лет назад

D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-445f-486h-qh76

3 месяца назад

Unrestricted Upload of File with Dangerous Type vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Using Malicious Files.This issue affects Atarim: from n/a through <= 4.2.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-445c-hfjr-5j56

почти 3 года назад

siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4459-qrcc-vfcf

больше 1 года назад

TYPO3 Cross-Site Scripting in Form Framework

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4458-ww2x-8wwm

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

EPSS: Низкий
github логотип

GHSA-4458-hg2w-xw4j

почти 4 года назад

PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4457-rx56-p82r

больше 3 лет назад

Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4457-c63h-fr7m

больше 2 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4457-8q65-98hw

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: hibmcge: fix rtnl deadlock issue Currently, the hibmcge netdev acquires the rtnl_lock in pci_error_handlers.reset_prepare() and releases it in pci_error_handlers.reset_done(). However, in the PCI framework: pci_reset_bus - __pci_reset_slot - pci_slot_save_and_disable_locked - pci_dev_save_and_disable - err_handler->reset_prepare(dev); In pci_slot_save_and_disable_locked(): list_for_each_entry(dev, &slot->bus->devices, bus_list) { if (!dev->slot || dev->slot!= slot) continue; pci_dev_save_and_disable(dev); if (dev->subordinate) pci_bus_save_and_disable_locked(dev->subordinate); } This will iterate through all devices under the current bus and execute err_handler->reset_prepare(), causing two devices of the hibmcge driver to sequentially request the rtnl_lock, leading to a deadlock. Since the driver now executes netif_device_detach() before the reset process, it will not concurrently with oth...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4456-w38r-m53x

больше 3 лет назад

Besu VM vulnerable to gas allocation error in CALL operations

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4456-f89c-g4p5

больше 3 лет назад

An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2014-8451.

EPSS: Средний
github логотип

GHSA-4456-4h4r-g935

больше 3 лет назад

Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-445m-8cc6-89hr

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

5%
Низкий
больше 3 лет назад
github логотип
GHSA-445m-62c2-rw3m

Baramundi Management Suite 7.5 through 8.9 uses cleartext for (1) client-server communication and (2) data storage, which allows remote attackers to obtain sensitive information by sniffing the network, and allows context-dependent attackers to obtain sensitive information by reading a file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-445m-27cf-gr3x

Crawl4AI SSRF vulnerability

0%
Низкий
10 месяцев назад
github логотип
GHSA-445j-hjgc-x696

Modem segments are unlocked after authentication, leaving modem segments open to all in Snapdragon Mobile, Snapdragon Wear in version MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-445j-3fj5-rxgh

The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-445h-32ch-3r5v

There is a Null pointer dereference in Smartphones.Successful exploitation of this vulnerability may cause the kernel to break down.

0%
Низкий
около 4 лет назад
github логотип
GHSA-445h-22pr-cp5g

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-445g-h2v6-5fxw

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the AppStudioUploadHandler class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-13894.

2%
Низкий
около 4 лет назад
github логотип
GHSA-445f-cm55-gq8v

D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

CVSS3: 9.8
4%
Низкий
около 2 лет назад
github логотип
GHSA-445f-486h-qh76

Unrestricted Upload of File with Dangerous Type vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Using Malicious Files.This issue affects Atarim: from n/a through <= 4.2.

CVSS3: 4.8
0%
Низкий
3 месяца назад
github логотип
GHSA-445c-hfjr-5j56

siteproxy v1.0 was discovered to contain a path traversal vulnerability via the component index.js.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-4459-qrcc-vfcf

TYPO3 Cross-Site Scripting in Form Framework

CVSS3: 6.1
больше 1 года назад
github логотип
GHSA-4458-ww2x-8wwm

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4458-hg2w-xw4j

PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-4457-rx56-p82r

Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4457-c63h-fr7m

Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4457-8q65-98hw

In the Linux kernel, the following vulnerability has been resolved: net: hibmcge: fix rtnl deadlock issue Currently, the hibmcge netdev acquires the rtnl_lock in pci_error_handlers.reset_prepare() and releases it in pci_error_handlers.reset_done(). However, in the PCI framework: pci_reset_bus - __pci_reset_slot - pci_slot_save_and_disable_locked - pci_dev_save_and_disable - err_handler->reset_prepare(dev); In pci_slot_save_and_disable_locked(): list_for_each_entry(dev, &slot->bus->devices, bus_list) { if (!dev->slot || dev->slot!= slot) continue; pci_dev_save_and_disable(dev); if (dev->subordinate) pci_bus_save_and_disable_locked(dev->subordinate); } This will iterate through all devices under the current bus and execute err_handler->reset_prepare(), causing two devices of the hibmcge driver to sequentially request the rtnl_lock, leading to a deadlock. Since the driver now executes netif_device_detach() before the reset process, it will not concurrently with oth...

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4456-w38r-m53x

Besu VM vulnerable to gas allocation error in CALL operations

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4456-f89c-g4p5

An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2014-8451.

28%
Средний
больше 3 лет назад
github логотип
GHSA-4456-4h4r-g935

Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу