Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-4223-qj94-7x9p

больше 3 лет назад

elFinder command injection vulnerability in the PHP connector

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-4222-x45c-hh2q

больше 3 лет назад

A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function decode_slice_header of the file libavcodec/h64.c. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4222-4jfx-7q2p

почти 4 года назад

Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file.

EPSS: Низкий
github логотип

GHSA-3xxx-crf3-jm97

больше 3 лет назад

Unspecified vulnerability in the olch2x32 ActiveX control in IBM SPSS SamplePower 3.0 before 3.0-IM-S3SAMPC-WIN32-FP001 allows remote attackers to execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3xxx-9v43-6x26

около 2 лет назад

APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3xxw-cpf8-x9hq

7 месяцев назад

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3xxw-5cqg-mq5w

около 2 месяцев назад

Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in user may execute arbitrary code. As for the details of the affected products and versions, see the information provided by the vendor under [References].

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3xxw-4ppg-gf75

около 4 лет назад

On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS: Низкий
github логотип

GHSA-3xxv-p78r-4fc6

больше 4 лет назад

Cross-site Scripting in Apache Airflow

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3xxr-x7rp-pc4x

больше 3 лет назад

Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-3xxr-vfgj-3gw3

больше 3 лет назад

In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3xxr-729f-x6v9

почти 4 года назад

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3xxp-73wf-27cp

больше 3 лет назад

DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3xxm-pww7-gf82

больше 3 лет назад

In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-124524315

EPSS: Низкий
github логотип

GHSA-3xxm-cx7p-m4p6

больше 3 лет назад

joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3xxm-3g3c-w579

около 2 лет назад

Moodle Code Injection vulnerability

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3xxj-wpwj-gxhm

больше 3 лет назад

An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xxj-rfjr-w6h5

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3xxj-pcr2-rvh7

почти 4 года назад

NULL Pointer Dereference in Homebrew mruby prior to 3.2.

EPSS: Низкий
github логотип

GHSA-3xxh-w577-324m

почти 3 года назад

The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4223-qj94-7x9p

elFinder command injection vulnerability in the PHP connector

CVSS3: 9.8
93%
Критический
больше 3 лет назад
github логотип
GHSA-4222-x45c-hh2q

A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function decode_slice_header of the file libavcodec/h64.c. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4222-4jfx-7q2p

Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file.

10%
Низкий
почти 4 года назад
github логотип
GHSA-3xxx-crf3-jm97

Unspecified vulnerability in the olch2x32 ActiveX control in IBM SPSS SamplePower 3.0 before 3.0-IM-S3SAMPC-WIN32-FP001 allows remote attackers to execute arbitrary code via unknown vectors.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-3xxx-9v43-6x26

APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-3xxw-cpf8-x9hq

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-3xxw-5cqg-mq5w

Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in user may execute arbitrary code. As for the details of the affected products and versions, see the information provided by the vendor under [References].

CVSS3: 7.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3xxw-4ppg-gf75

On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3xxv-p78r-4fc6

Cross-site Scripting in Apache Airflow

CVSS3: 6.1
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3xxr-x7rp-pc4x

Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.

CVSS3: 2.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xxr-vfgj-3gw3

In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xxr-729f-x6v9

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3xxp-73wf-27cp

DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xxm-pww7-gf82

In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-124524315

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xxm-cx7p-m4p6

joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xxm-3g3c-w579

Moodle Code Injection vulnerability

CVSS3: 4.7
2%
Низкий
около 2 лет назад
github логотип
GHSA-3xxj-wpwj-gxhm

An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xxj-rfjr-w6h5

Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3xxj-pcr2-rvh7

NULL Pointer Dereference in Homebrew mruby prior to 3.2.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3xxh-w577-324m

The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.

CVSS3: 5.4
0%
Низкий
почти 3 года назад

Уязвимостей на страницу