Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-424j-rr9q-xrp9

больше 2 лет назад

Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and data after logging out.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-424h-xj87-m937

4 месяца назад

Mattermost has an Incorrect Authorization vulnerability

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-424g-xp8r-prc3

почти 4 года назад

Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.

EPSS: Низкий
github логотип

GHSA-424g-rgq3-f8r9

больше 3 лет назад

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-424g-qc5w-mhw6

7 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Player Wordpress & WooCommerce allows Path Traversal. This issue affects Easy Video Player Wordpress & WooCommerce: from n/a through 10.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-424g-5pjh-pv8j

больше 3 лет назад

IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1747.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-424f-vwfw-m7pm

почти 4 года назад

sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.

EPSS: Низкий
github логотип

GHSA-424f-vg9g-p97j

больше 1 года назад

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /inccatadd.php. The manipulation of the argument title leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-424f-mqpf-66f3

больше 3 лет назад

Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QMBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QLBDE CoreOS version ’05.65.00.BD’ and earlier, GT1455HS-QTBDE CoreOS version ’05.65.00.BD’ and earlier, and GT1450HS-QMBDE CoreOS version ’05.65.00.BD’ and earlier) allows a remote unauthenticated attacker to stop the network functions of the products via a specially crafted packet.

EPSS: Низкий
github логотип

GHSA-424f-g622-9cvv

23 дня назад

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-424f-2594-fw2c

больше 3 лет назад

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-424c-xcc5-xgcj

больше 3 лет назад

Multiple directory traversal vulnerabilities in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote authenticated users to include and execute certain PHP files via (1) .. (dot dot) sequences in the PATH_INFO to index.php or (2) vectors involving a block value in the ___directive parameter to the Cms_Wysiwyg controller in the Adminhtml module, related to the blockDirective function and the auto loading mechanism. NOTE: vector 2 might not cross privilege boundaries, since administrators might already have the privileges to execute code and upload files.

EPSS: Средний
github логотип

GHSA-4249-gjr8-jpq3

3 месяца назад

Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values

EPSS: Низкий
github логотип

GHSA-4248-p65p-hcrm

около 2 лет назад

Insecure random string generator used for sensitive data

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4248-p64f-3j9w

больше 3 лет назад

VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.

EPSS: Низкий
github логотип

GHSA-4248-cpjp-j3jq

9 месяцев назад

A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/add-doctor.php. The manipulation of the argument Doctorspecialization leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4247-fw2x-jv5v

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MetricThemes Header Footer Composer for Elementor allows DOM-Based XSS.This issue affects Header Footer Composer for Elementor: from n/a through 1.0.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4245-83wj-fq56

больше 3 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing the QCA_NL80211_VENDOR_SUBCMD_GET_CHAIN_RSSI vendor command, in which attribute QCA_WLAN_VENDOR_ATTR_MAC_ADDR contains fewer than 6 bytes, a buffer overrun occurs.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4245-33hh-r4j6

3 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-4244-wg8v-q7j8

почти 4 года назад

BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII). BD Viper LT system versions 4.0 and later utilize Microsoft Windows 10 and have additional Operating System hardening configurations which increase the attack complexity required to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-424j-rr9q-xrp9

Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and data after logging out.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-424h-xj87-m937

Mattermost has an Incorrect Authorization vulnerability

CVSS3: 3.1
0%
Низкий
4 месяца назад
github логотип
GHSA-424g-xp8r-prc3

Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-424g-rgq3-f8r9

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-424g-qc5w-mhw6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Player Wordpress & WooCommerce allows Path Traversal. This issue affects Easy Video Player Wordpress & WooCommerce: from n/a through 10.0.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-424g-5pjh-pv8j

IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1747.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-424f-vwfw-m7pm

sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-424f-vg9g-p97j

A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /inccatadd.php. The manipulation of the argument title leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-424f-mqpf-66f3

Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QMBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QLBDE CoreOS version ’05.65.00.BD’ and earlier, GT1455HS-QTBDE CoreOS version ’05.65.00.BD’ and earlier, and GT1450HS-QMBDE CoreOS version ’05.65.00.BD’ and earlier) allows a remote unauthenticated attacker to stop the network functions of the products via a specially crafted packet.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-424f-g622-9cvv

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

CVSS3: 5.3
0%
Низкий
23 дня назад
github логотип
GHSA-424f-2594-fw2c

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-424c-xcc5-xgcj

Multiple directory traversal vulnerabilities in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote authenticated users to include and execute certain PHP files via (1) .. (dot dot) sequences in the PATH_INFO to index.php or (2) vectors involving a block value in the ___directive parameter to the Cms_Wysiwyg controller in the Adminhtml module, related to the blockDirective function and the auto loading mechanism. NOTE: vector 2 might not cross privilege boundaries, since administrators might already have the privileges to execute code and upload files.

33%
Средний
больше 3 лет назад
github логотип
GHSA-4249-gjr8-jpq3

Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values

3 месяца назад
github логотип
GHSA-4248-p65p-hcrm

Insecure random string generator used for sensitive data

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4248-p64f-3j9w

VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-4248-cpjp-j3jq

A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/add-doctor.php. The manipulation of the argument Doctorspecialization leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-4247-fw2x-jv5v

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MetricThemes Header Footer Composer for Elementor allows DOM-Based XSS.This issue affects Header Footer Composer for Elementor: from n/a through 1.0.4.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4245-83wj-fq56

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing the QCA_NL80211_VENDOR_SUBCMD_GET_CHAIN_RSSI vendor command, in which attribute QCA_WLAN_VENDOR_ATTR_MAC_ADDR contains fewer than 6 bytes, a buffer overrun occurs.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4245-33hh-r4j6

Rejected reason: Not used

3 месяца назад
github логотип
GHSA-4244-wg8v-q7j8

BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII). BD Viper LT system versions 4.0 and later utilize Microsoft Windows 10 and have additional Operating System hardening configurations which increase the attack complexity required to exploit this vulnerability.

CVSS3: 7.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу