Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-4296-mcph-c48g

больше 3 лет назад

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-12131.

EPSS: Низкий
github логотип

GHSA-4294-5ggf-cc4h

почти 4 года назад

linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.

EPSS: Низкий
github логотип

GHSA-4293-qv72-rrqq

3 месяца назад

A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4293-g9vj-h9qq

около 1 года назад

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'fieldfor', 'visibleParent' and 'id' parameters in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-4293-4hgr-xmh5

около 3 лет назад

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4292-w862-9w9c

больше 3 лет назад

Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.

EPSS: Низкий
github логотип

GHSA-4292-c56q-p736

6 месяцев назад

The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block's attributes in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-428x-9xc2-m8mj

почти 4 года назад

Division by zero in TFLite

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-428w-w772-h8gm

больше 3 лет назад

The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-428v-vxh3-r3c8

больше 3 лет назад

A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. By exploiting this issue, an attacker-controlled server can force the client to skip TLS certificate validation, leading to a man-in-the-middle attack against HTTPS and unauthenticated remote code execution.

EPSS: Низкий
github логотип

GHSA-428v-vcmp-3q56

больше 3 лет назад

Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-428v-fmp7-x6v2

почти 4 года назад

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microkernel(TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-428v-f3rc-x37x

больше 3 лет назад

The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image, related to imagew-jpeg.c.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-428r-jfg5-x94p

почти 4 года назад

Buffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command line argument.

EPSS: Низкий
github логотип

GHSA-428q-q3vv-3fq3

10 месяцев назад

GraphQL grant on a property might be cached with different objects

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-428q-fvjp-mhxg

больше 3 лет назад

A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5086 pertains to instances of fwrite in Sphider Pro and Sphider Plus only, but don’t exist in Sphider.

EPSS: Низкий
github логотип

GHSA-428q-4w9h-gx2c

больше 3 лет назад

The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an associated symbolic link and an open DACL.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-428j-q447-47rw

больше 3 лет назад

Apache Rave information disclosure vulnerability

EPSS: Высокий
github логотип

GHSA-428g-f7cq-pgp5

около 2 месяцев назад

Marshmallow has DoS in Schema.load(many)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-428g-3m2x-46jh

больше 1 года назад

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials.

CVSS3: 6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4296-mcph-c48g

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-12131.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4294-5ggf-cc4h

linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.

1%
Низкий
почти 4 года назад
github логотип
GHSA-4293-qv72-rrqq

A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4293-g9vj-h9qq

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'fieldfor', 'visibleParent' and 'id' parameters in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
0%
Низкий
около 1 года назад
github логотип
GHSA-4293-4hgr-xmh5

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-4292-w862-9w9c

Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-4292-c56q-p736

The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block's attributes in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-428x-9xc2-m8mj

Division by zero in TFLite

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-428w-w772-h8gm

The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-428v-vxh3-r3c8

A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. By exploiting this issue, an attacker-controlled server can force the client to skip TLS certificate validation, leading to a man-in-the-middle attack against HTTPS and unauthenticated remote code execution.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-428v-vcmp-3q56

Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-428v-fmp7-x6v2

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microkernel(TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-428v-f3rc-x37x

The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image, related to imagew-jpeg.c.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-428r-jfg5-x94p

Buffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command line argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-428q-q3vv-3fq3

GraphQL grant on a property might be cached with different objects

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-428q-fvjp-mhxg

A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5086 pertains to instances of fwrite in Sphider Pro and Sphider Plus only, but don’t exist in Sphider.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-428q-4w9h-gx2c

The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physical memory via specially crafted IOCTL requests and elevate system privileges. This occurs because the device object has an associated symbolic link and an open DACL.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-428j-q447-47rw

Apache Rave information disclosure vulnerability

87%
Высокий
больше 3 лет назад
github логотип
GHSA-428g-f7cq-pgp5

Marshmallow has DoS in Schema.load(many)

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-428g-3m2x-46jh

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials.

CVSS3: 6
1%
Низкий
больше 1 года назад

Уязвимостей на страницу