Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-43p3-cf56-rpqr

больше 3 лет назад

The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to upload and execute files with the `.php6`, `.php7`, `.phtml`, and `.phpt` extensions. Additionally, JHelperMedia::canUpload() did not blacklist these file extensions as uploadable file types.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43p2-q7g7-857m

больше 3 лет назад

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2730.

EPSS: Низкий
github логотип

GHSA-43mx-p8wf-wh27

больше 1 года назад

An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Several configuration statements meant to enforce limits on MAC learning and moves can be configured but do not take effect. This can lead to control plane overload situations which will severely impact the ability of the device to processes legitimate traffic. This issue affects Junos OS Evolved on QFX5000 Series: * All versions before 21.4R3-S8-EVO, * 22.2-EVO versions before 22.2R3-S5-EVO, * 22.4-EVO versions before 22.4R3-EVO, * 23.2-EVO versions before 23.2R2-EVO.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43mx-8xm7-7p46

почти 4 года назад

AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43mx-35xv-4r2v

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation allows Reflected XSS. This issue affects ReDi Restaurant Reservation: from n/a through 24.1209.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43mw-w97r-j4p7

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tomroyal Stop Registration Spam allows Reflected XSS. This issue affects Stop Registration Spam: from n/a through 1.24.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43mw-858p-8pf4

6 месяцев назад

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system wide instead of an account-by-account basis, potentially leading to a Denial of Service (DoS) via resource exhaustion.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43mw-6w68-5pvw

больше 3 лет назад

Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.

EPSS: Высокий
github логотип

GHSA-43mv-m2vr-rqqc

больше 3 лет назад

An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43mv-gcv3-rmpw

больше 3 лет назад

Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.

EPSS: Низкий
github логотип

GHSA-43mv-f787-vp98

почти 4 года назад

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43mv-86p8-mrjm

больше 3 лет назад

WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-43mv-63pp-x6jr

около 2 лет назад

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43mv-4mpj-gj4v

почти 3 года назад

Visual Studio Remote Code Execution Vulnerability

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-43mr-mm46-m2qq

почти 2 года назад

A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-43mr-gg87-qwf3

больше 3 лет назад

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.

EPSS: Низкий
github логотип

GHSA-43mq-6xmg-29vm

около 1 года назад

Apache Struts file upload logic is flawed

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-43mp-rw63-xf4q

почти 4 года назад

SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-43mp-m7qp-jhq5

больше 3 лет назад

In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result in stack overflow.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-43mm-w7h4-j7r2

4 месяца назад

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce verification on the `login_form_indieauth()` function and the authorization endpoint at wp-login.php?action=indieauth. This makes it possible for unauthenticated attackers to force authenticated users to approve OAuth authorization requests for attacker-controlled applications via a forged request granted they can trick a user into performing an action such as clicking on a link or visiting a malicious page while logged in. The attacker can then exchange the stolen authorization code for an access token, effectively taking over the victim's account with the granted scopes (create, update, delete).

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43p3-cf56-rpqr

The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to upload and execute files with the `.php6`, `.php7`, `.phtml`, and `.phpt` extensions. Additionally, JHelperMedia::canUpload() did not blacklist these file extensions as uploadable file types.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43p2-q7g7-857m

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2730.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-43mx-p8wf-wh27

An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Several configuration statements meant to enforce limits on MAC learning and moves can be configured but do not take effect. This can lead to control plane overload situations which will severely impact the ability of the device to processes legitimate traffic. This issue affects Junos OS Evolved on QFX5000 Series: * All versions before 21.4R3-S8-EVO, * 22.2-EVO versions before 22.2R3-S5-EVO, * 22.4-EVO versions before 22.4R3-EVO, * 23.2-EVO versions before 23.2R2-EVO.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-43mx-8xm7-7p46

AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-43mx-35xv-4r2v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation allows Reflected XSS. This issue affects ReDi Restaurant Reservation: from n/a through 24.1209.

CVSS3: 7.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-43mw-w97r-j4p7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tomroyal Stop Registration Spam allows Reflected XSS. This issue affects Stop Registration Spam: from n/a through 1.24.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-43mw-858p-8pf4

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system wide instead of an account-by-account basis, potentially leading to a Denial of Service (DoS) via resource exhaustion.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-43mw-6w68-5pvw

Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.

89%
Высокий
больше 3 лет назад
github логотип
GHSA-43mv-m2vr-rqqc

An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43mv-gcv3-rmpw

Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43mv-f787-vp98

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-43mv-86p8-mrjm

WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.

CVSS3: 9.8
14%
Средний
больше 3 лет назад
github логотип
GHSA-43mv-63pp-x6jr

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-43mv-4mpj-gj4v

Visual Studio Remote Code Execution Vulnerability

CVSS3: 8.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-43mr-mm46-m2qq

A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.

CVSS3: 8.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-43mr-gg87-qwf3

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43mq-6xmg-29vm

Apache Struts file upload logic is flawed

CVSS3: 9.8
93%
Критический
около 1 года назад
github логотип
GHSA-43mp-rw63-xf4q

SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-43mp-m7qp-jhq5

In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result in stack overflow.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43mm-w7h4-j7r2

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce verification on the `login_form_indieauth()` function and the authorization endpoint at wp-login.php?action=indieauth. This makes it possible for unauthenticated attackers to force authenticated users to approve OAuth authorization requests for attacker-controlled applications via a forged request granted they can trick a user into performing an action such as clicking on a link or visiting a malicious page while logged in. The attacker can then exchange the stolen authorization code for an access token, effectively taking over the victim's account with the granted scopes (create, update, delete).

CVSS3: 8.8
0%
Низкий
4 месяца назад

Уязвимостей на страницу