Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 648

Количество 324 648

github логотип

GHSA-xrc8-fqhc-595v

почти 4 года назад

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to execute arbitrary code with kernel privileges.

EPSS: Низкий
github логотип

GHSA-xrc8-933j-f74c

3 дня назад

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-xrc8-4cqr-4x7c

почти 4 года назад

Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firmware version prior to Ver.1.22 allow an attacker on the same network segment to bypass authentication to perform administrative operations via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrc5-wm9f-xf92

почти 3 года назад

The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function in versions up to, and including, 3.0.4. This makes it possible for authenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xrc4-pj8p-r2hh

почти 4 года назад

Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging the ability to read these files.

EPSS: Низкий
github логотип

GHSA-xrc4-75vx-v89g

почти 4 года назад

Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.

EPSS: Низкий
github логотип

GHSA-xrc4-737v-9q75

больше 3 лет назад

OpenZeppelin Contracts's GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrc3-9jj6-mqcm

около 1 года назад

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-xrc2-5gr8-655q

почти 4 года назад

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xr9x-fhcv-6qm7

около 3 лет назад

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr9w-x6gw-c9mj

около 3 лет назад

Duplicate advisory: Deno vulnerable to Regular Expression Denial of Service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr9w-r8gw-wjhw

4 месяца назад

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xr9r-hxj6-96p6

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: cifs: fix small mempool leak in SMB2_negotiate() In some cases of failure (dialect mismatches) in SMB2_negotiate(), after the request is sent, the checks would return -EIO when they should be rather setting rc = -EIO and jumping to neg_exit to free the response buffer from mempool.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr9r-3v5q-97c3

почти 4 года назад

The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.

EPSS: Низкий
github логотип

GHSA-xr9q-qqh9-m7h3

почти 4 года назад

The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.

EPSS: Низкий
github логотип

GHSA-xr9q-p253-xqxh

почти 4 года назад

In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137102479

EPSS: Низкий
github логотип

GHSA-xr9q-h9c7-xw8q

около 1 года назад

Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xr9q-85p6-f6xr

9 месяцев назад

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr9p-wqhw-3w78

почти 4 года назад

Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.

EPSS: Низкий
github логотип

GHSA-xr9p-qj4x-c6c7

почти 4 года назад

The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrc8-fqhc-595v

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to execute arbitrary code with kernel privileges.

5%
Низкий
почти 4 года назад
github логотип
GHSA-xrc8-933j-f74c

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 10
0%
Низкий
3 дня назад
github логотип
GHSA-xrc8-4cqr-4x7c

Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firmware version prior to Ver.1.22 allow an attacker on the same network segment to bypass authentication to perform administrative operations via unspecified vectors.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrc5-wm9f-xf92

The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function in versions up to, and including, 3.0.4. This makes it possible for authenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 8.8
11%
Средний
почти 3 года назад
github логотип
GHSA-xrc4-pj8p-r2hh

Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging the ability to read these files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrc4-75vx-v89g

Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrc4-737v-9q75

OpenZeppelin Contracts's GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrc3-9jj6-mqcm

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.

CVSS3: 7.5
72%
Высокий
около 1 года назад
github логотип
GHSA-xrc2-5gr8-655q

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr9x-fhcv-6qm7

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xr9w-x6gw-c9mj

Duplicate advisory: Deno vulnerable to Regular Expression Denial of Service

CVSS3: 7.5
около 3 лет назад
github логотип
GHSA-xr9w-r8gw-wjhw

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xr9r-hxj6-96p6

In the Linux kernel, the following vulnerability has been resolved: cifs: fix small mempool leak in SMB2_negotiate() In some cases of failure (dialect mismatches) in SMB2_negotiate(), after the request is sent, the checks would return -EIO when they should be rather setting rc = -EIO and jumping to neg_exit to free the response buffer from mempool.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xr9r-3v5q-97c3

The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xr9q-qqh9-m7h3

The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xr9q-p253-xqxh

In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137102479

0%
Низкий
почти 4 года назад
github логотип
GHSA-xr9q-h9c7-xw8q

Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API

CVSS3: 8.2
0%
Низкий
около 1 года назад
github логотип
GHSA-xr9q-85p6-f6xr

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

CVSS3: 9.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-xr9p-wqhw-3w78

Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xr9p-qj4x-c6c7

The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу