Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 305 434

Количество 305 434

github логотип

GHSA-3gcp-ghxf-55qh

больше 3 лет назад

A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, preventing subsequent print jobs until the printer is rebooted.

EPSS: Низкий
github логотип

GHSA-3gcp-58m3-9fp5

6 месяцев назад

An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the Broker VM and escalate their privileges to root.

EPSS: Низкий
github логотип

GHSA-3gcp-2ghh-2fp8

больше 3 лет назад

Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.

EPSS: Средний
github логотип

GHSA-3gcm-f6qx-ff7p

3 месяца назад

Flowise has Remote Code Execution vulnerability

CVSS3: 10
EPSS: Высокий
github логотип

GHSA-3gcm-72hc-3mgw

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the cha parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9718.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3gcm-3fg6-x94w

12 месяцев назад

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. This affects an unknown part of the file /admin/category.php. The manipulation of the argument state leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3gcj-mhjc-vr9j

5 месяцев назад

IrfanView CADImage Plugin CGM File Parsing Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26074.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3gcj-j65q-mrvj

больше 3 лет назад

An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).

EPSS: Низкий
github логотип

GHSA-3gcj-hw9g-gmm2

больше 3 лет назад

Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.

EPSS: Низкий
github логотип

GHSA-3gcj-473g-7xhq

11 месяцев назад

The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is vulnerable to arbitrary files uploads due to a missing capability check and file type validation on the add_image_to_library AJAX action function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files that make remote code execution possible.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3gcg-p5c5-qpcw

больше 1 года назад

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 4.15.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3gcg-chcp-rq42

почти 3 года назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kernel memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3gcg-c4cr-6g36

больше 3 лет назад

A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the ability to execute arbitrary code as the system user, through not checking the DLL signature.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3gcf-28pg-3vm2

больше 1 года назад

Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3gcc-j58h-xmv8

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix possible buffer overflow in wl1251_cmd_scan Function wl1251_cmd_scan calls memcpy without checking the length. Harden by checking the length is within the maximum allowed size.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3gcc-2rv5-mv32

больше 3 лет назад

Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.

EPSS: Низкий
github логотип

GHSA-3gc9-xgq4-mpq2

больше 1 года назад

Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3gc8-mch5-55gq

больше 3 лет назад

An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.

EPSS: Низкий
github логотип

GHSA-3gc7-fjrx-p6mg

8 месяцев назад

bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3gc7-47g4-v5w7

больше 3 лет назад

A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0884, CVE-2019-0911.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gcp-ghxf-55qh

A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, preventing subsequent print jobs until the printer is rebooted.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gcp-58m3-9fp5

An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the Broker VM and escalate their privileges to root.

0%
Низкий
6 месяцев назад
github логотип
GHSA-3gcp-2ghh-2fp8

Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.

19%
Средний
больше 3 лет назад
github логотип
GHSA-3gcm-f6qx-ff7p

Flowise has Remote Code Execution vulnerability

CVSS3: 10
79%
Высокий
3 месяца назад
github логотип
GHSA-3gcm-72hc-3mgw

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the cha parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9718.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3gcm-3fg6-x94w

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. This affects an unknown part of the file /admin/category.php. The manipulation of the argument state leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-3gcj-mhjc-vr9j

IrfanView CADImage Plugin CGM File Parsing Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26074.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3gcj-j65q-mrvj

An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gcj-hw9g-gmm2

Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3gcj-473g-7xhq

The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is vulnerable to arbitrary files uploads due to a missing capability check and file type validation on the add_image_to_library AJAX action function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files that make remote code execution possible.

CVSS3: 8.8
52%
Средний
11 месяцев назад
github логотип
GHSA-3gcg-p5c5-qpcw

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 4.15.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3gcg-chcp-rq42

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kernel memory.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3gcg-c4cr-6g36

A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the ability to execute arbitrary code as the system user, through not checking the DLL signature.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gcf-28pg-3vm2

Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3gcc-j58h-xmv8

In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix possible buffer overflow in wl1251_cmd_scan Function wl1251_cmd_scan calls memcpy without checking the length. Harden by checking the length is within the maximum allowed size.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3gcc-2rv5-mv32

Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3gc9-xgq4-mpq2

Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3gc8-mch5-55gq

An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3gc7-fjrx-p6mg

bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3gc7-47g4-v5w7

A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0884, CVE-2019-0911.

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу