Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 305 434

Количество 305 434

github логотип

GHSA-3gj4-c93j-g529

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an interface user. These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by persuading an interface user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

EPSS: Низкий
github логотип

GHSA-3gj4-2qc3-888r

больше 1 года назад

Windows Telephony Server Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3gj4-2f6h-gghr

9 месяцев назад

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3gj3-p68v-v295

больше 3 лет назад

The instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS.

EPSS: Низкий
github логотип

GHSA-3gj2-3664-8r38

больше 3 лет назад

Multiple unspecified vulnerabilities in SPINE before 1.2 have unknown impact and attack vectors, related to (1) "Placeholders in database handler" and (2) "Macro admin security."

EPSS: Низкий
github логотип

GHSA-3ghx-8gmm-9rg3

больше 1 года назад

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3ghw-r8fh-hc2p

больше 3 лет назад

Buffer overflow in the strval function in PHP before 5.3.6, when the precision configuration option has a large value, might allow context-dependent attackers to cause a denial of service (application crash) via a small numerical value in the argument.

EPSS: Низкий
github логотип

GHSA-3ghw-4xg5-hgw2

почти 4 года назад

Android images for T210 provided by NVIDIA contain a vulnerability in BROM, where failure to limit access to AHB-DMA when BROM fails may allow an unprivileged attacker with physical access to cause denial of service or impact integrity and confidentiality beyond the security scope of BROM.

EPSS: Низкий
github логотип

GHSA-3ghw-3m72-v6jr

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: coresight: trbe: remove cpuhp instance node before remove cpuhp state cpuhp_state_add_instance() and cpuhp_state_remove_instance() should be used in pairs. Or there will lead to the warn on cpuhp_remove_multi_state() since the cpuhp_step list is not empty. The following is the error log with 'rmmod coresight-trbe': Error: Removing state 215 which has instances left. Call trace: __cpuhp_remove_state_cpuslocked+0x144/0x160 __cpuhp_remove_state+0xac/0x100 arm_trbe_device_remove+0x2c/0x60 [coresight_trbe] platform_remove+0x34/0x70 device_remove+0x54/0x90 device_release_driver_internal+0x1e4/0x250 driver_detach+0x5c/0xb0 bus_remove_driver+0x64/0xc0 driver_unregister+0x3c/0x70 platform_driver_unregister+0x20/0x30 arm_trbe_exit+0x1c/0x658 [coresight_trbe] __arm64_sys_delete_module+0x1ac/0x24c invoke_syscall+0x50/0x120 el0_svc_common.constprop.0+0x58/0x1a0 do_el0_svc+0x38/0xd0 el0_svc+0x2c...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3ghv-w9fm-536c

больше 3 лет назад

IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ghv-qqmp-p6c4

около 1 месяца назад

The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3ghv-75mw-fc8f

больше 3 лет назад

Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3ghq-rfpw-jhqx

3 месяца назад

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ghq-g9vp-wwq2

больше 2 лет назад

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3ghq-53cj-qqmp

около 1 месяца назад

An issue was discovered in AnyDesk through 9.0.4. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3ghq-3f49-fr98

около 3 лет назад

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ghp-2qxv-j2hr

больше 3 лет назад

Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.

EPSS: Низкий
github логотип

GHSA-3ghj-wv9w-7vp9

около 2 лет назад

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3ghj-f9w6-vh8h

больше 3 лет назад

SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.php.

EPSS: Низкий
github логотип

GHSA-3ghh-rm9h-rjcv

больше 3 лет назад

Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long ID3 tag in an MP3 file. NOTE: some of these details are obtained from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gj4-c93j-g529

Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an interface user. These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by persuading an interface user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gj4-2qc3-888r

Windows Telephony Server Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3gj4-2f6h-gghr

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.

CVSS3: 9.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-3gj3-p68v-v295

The instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gj2-3664-8r38

Multiple unspecified vulnerabilities in SPINE before 1.2 have unknown impact and attack vectors, related to (1) "Placeholders in database handler" and (2) "Macro admin security."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ghx-8gmm-9rg3

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3ghw-r8fh-hc2p

Buffer overflow in the strval function in PHP before 5.3.6, when the precision configuration option has a large value, might allow context-dependent attackers to cause a denial of service (application crash) via a small numerical value in the argument.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3ghw-4xg5-hgw2

Android images for T210 provided by NVIDIA contain a vulnerability in BROM, where failure to limit access to AHB-DMA when BROM fails may allow an unprivileged attacker with physical access to cause denial of service or impact integrity and confidentiality beyond the security scope of BROM.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3ghw-3m72-v6jr

In the Linux kernel, the following vulnerability has been resolved: coresight: trbe: remove cpuhp instance node before remove cpuhp state cpuhp_state_add_instance() and cpuhp_state_remove_instance() should be used in pairs. Or there will lead to the warn on cpuhp_remove_multi_state() since the cpuhp_step list is not empty. The following is the error log with 'rmmod coresight-trbe': Error: Removing state 215 which has instances left. Call trace: __cpuhp_remove_state_cpuslocked+0x144/0x160 __cpuhp_remove_state+0xac/0x100 arm_trbe_device_remove+0x2c/0x60 [coresight_trbe] platform_remove+0x34/0x70 device_remove+0x54/0x90 device_release_driver_internal+0x1e4/0x250 driver_detach+0x5c/0xb0 bus_remove_driver+0x64/0xc0 driver_unregister+0x3c/0x70 platform_driver_unregister+0x20/0x30 arm_trbe_exit+0x1c/0x658 [coresight_trbe] __arm64_sys_delete_module+0x1ac/0x24c invoke_syscall+0x50/0x120 el0_svc_common.constprop.0+0x58/0x1a0 do_el0_svc+0x38/0xd0 el0_svc+0x2c...

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3ghv-w9fm-536c

IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ghv-qqmp-p6c4

The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3ghv-75mw-fc8f

Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ghq-rfpw-jhqx

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-3ghq-g9vp-wwq2

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3ghq-53cj-qqmp

An issue was discovered in AnyDesk through 9.0.4. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3ghq-3f49-fr98

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3ghp-2qxv-j2hr

Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3ghj-wv9w-7vp9

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

CVSS3: 9.8
19%
Средний
около 2 лет назад
github логотип
GHSA-3ghj-f9w6-vh8h

SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3ghh-rm9h-rjcv

Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long ID3 tag in an MP3 file. NOTE: some of these details are obtained from third party information.

8%
Низкий
больше 3 лет назад

Уязвимостей на страницу