Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-438m-xgcg-7xx6

почти 4 года назад

SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.

EPSS: Низкий
github логотип

GHSA-438m-xg9x-7hw2

больше 1 года назад

C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an array of 50 elements.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-438m-gffq-9866

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.

EPSS: Низкий
github логотип

GHSA-438m-6mhw-hq5w

5 месяцев назад

Mautic vulnerable to secret data extraction via elfinder

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-438j-gj6m-538p

больше 3 лет назад

In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111450531

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-438j-8gh2-h5w4

около 3 лет назад

The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-438j-3c2r-rp4p

4 месяца назад

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-438j-26hg-98wc

почти 4 года назад

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

EPSS: Низкий
github логотип

GHSA-438h-h6xr-v2p3

больше 3 лет назад

In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-438h-3pc3-hx6p

больше 3 лет назад

Buffer overflow in the sixel_decode function in coders/sixel.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-438g-rq2f-384h

больше 1 года назад

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-438g-mj2j-8f54

больше 1 года назад

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-438g-fxpm-cv6v

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/.

EPSS: Низкий
github логотип

GHSA-438g-fx34-4h9m

больше 4 лет назад

Out of bounds read in simple-slab

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-438g-ffmc-cm86

больше 3 лет назад

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1121, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-438g-9pr9-j76p

больше 3 лет назад

The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.

EPSS: Низкий
github логотип

GHSA-438f-r8m8-h4gg

7 месяцев назад

The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the olws_handle_verify_phone() function not utilizing a strong enough OTP value, exposing the hash needed to generate the OTP value, and no restrictions on the number of attempts to submit the code. This makes it possible for unauthenticated attackers to log in as other users, including administrators, if they have access to their phone number.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-438f-ccw8-g93r

больше 3 лет назад

An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-438c-f5p2-jch8

больше 3 лет назад

DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-438c-3975-5x3f

почти 2 года назад

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-438m-xgcg-7xx6

SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.

1%
Низкий
почти 4 года назад
github логотип
GHSA-438m-xg9x-7hw2

C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, which may affect common use cases such as sorting an array of 50 elements.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-438m-gffq-9866

Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-438m-6mhw-hq5w

Mautic vulnerable to secret data extraction via elfinder

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-438j-gj6m-538p

In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111450531

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-438j-8gh2-h5w4

The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-438j-3c2r-rp4p

Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.2
0%
Низкий
4 месяца назад
github логотип
GHSA-438j-26hg-98wc

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

0%
Низкий
почти 4 года назад
github логотип
GHSA-438h-h6xr-v2p3

In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-438h-3pc3-hx6p

Buffer overflow in the sixel_decode function in coders/sixel.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-438g-rq2f-384h

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.

CVSS3: 9.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-438g-mj2j-8f54

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-438g-fxpm-cv6v

Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-438g-fx34-4h9m

Out of bounds read in simple-slab

CVSS3: 9.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-438g-ffmc-cm86

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1121, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-438g-9pr9-j76p

The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-438f-r8m8-h4gg

The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the olws_handle_verify_phone() function not utilizing a strong enough OTP value, exposing the hash needed to generate the OTP value, and no restrictions on the number of attempts to submit the code. This makes it possible for unauthenticated attackers to log in as other users, including administrators, if they have access to their phone number.

CVSS3: 8.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-438f-ccw8-g93r

An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-438c-f5p2-jch8

DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-438c-3975-5x3f

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

CVSS3: 4.3
1%
Низкий
почти 2 года назад

Уязвимостей на страницу