Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-43qq-qw4x-28f8

больше 3 лет назад

Kirby CMS vulnerable to user enumeration in the code-based login and password reset forms

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-43qp-rp4g-mx9r

больше 3 лет назад

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

EPSS: Низкий
github логотип

GHSA-43qp-hphf-5rjw

больше 3 лет назад

Chakra Core vulnerable to privilege escalation due to reading an invalid pointer

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-43qp-56c9-mg75

почти 3 года назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17111.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43qm-4w5w-7m4c

около 3 лет назад

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-43qj-8555-mr85

больше 2 лет назад

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43qh-64c2-wvgp

7 месяцев назад

The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4wp' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-43qh-4rrx-cfw6

5 месяцев назад

Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management (DPM) functions resulting in an out of bounds read and loss of availability.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-43qg-hpjm-xmxr

больше 3 лет назад

Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.

EPSS: Низкий
github логотип

GHSA-43qf-qj5j-5r47

около 2 месяцев назад

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43qf-4rqw-9q2g

11 месяцев назад

Flask-CORS vulnerable to Improper Handling of Case Sensitivity

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43qc-p452-9j38

больше 3 лет назад

A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43qc-6x8c-rggm

больше 3 лет назад

The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-43qc-57r7-5r46

больше 3 лет назад

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-43q9-x7jp-29r7

больше 3 лет назад

The Celluloid (aka com.eurisko.celluloid) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-43q8-jq5v-77gp

больше 3 лет назад

Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-43q8-3fv7-pr5x

около 4 лет назад

Improper Validation of Integrity Check Value in TensorFlow

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-43q7-q5vp-3g68

больше 3 лет назад

Path Traversal in Eclipse Mojarra

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43q6-3r5v-55cg

около 4 лет назад

SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43q4-pf55-3xhc

почти 3 года назад

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43qq-qw4x-28f8

Kirby CMS vulnerable to user enumeration in the code-based login and password reset forms

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43qp-rp4g-mx9r

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-43qp-hphf-5rjw

Chakra Core vulnerable to privilege escalation due to reading an invalid pointer

CVSS3: 7.5
21%
Средний
больше 3 лет назад
github логотип
GHSA-43qp-56c9-mg75

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17111.

CVSS3: 5.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-43qm-4w5w-7m4c

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVSS3: 4.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-43qj-8555-mr85

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-43qh-64c2-wvgp

The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4wp' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-43qh-4rrx-cfw6

Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management (DPM) functions resulting in an out of bounds read and loss of availability.

CVSS3: 3.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-43qg-hpjm-xmxr

Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-43qf-qj5j-5r47

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-43qf-4rqw-9q2g

Flask-CORS vulnerable to Improper Handling of Case Sensitivity

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-43qc-p452-9j38

A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43qc-6x8c-rggm

The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43qc-57r7-5r46

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43q9-x7jp-29r7

The Celluloid (aka com.eurisko.celluloid) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43q8-jq5v-77gp

Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43q8-3fv7-pr5x

Improper Validation of Integrity Check Value in TensorFlow

CVSS3: 7
около 4 лет назад
github логотип
GHSA-43q7-q5vp-3g68

Path Traversal in Eclipse Mojarra

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-43q6-3r5v-55cg

SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-43q4-pf55-3xhc

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

CVSS3: 6.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу