Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3xr7-8857-qq4j

больше 3 лет назад

A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3xr7-46q2-56ff

больше 3 лет назад

A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3xr6-pm2j-p9qj

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always drain health in shutdown callback There is no point in recovery during device shutdown. if health work started need to wait for it to avoid races and NULL pointer access. Hence, drain health WQ on shutdown callback.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3xr6-hf43-f79h

почти 4 года назад

AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.

EPSS: Низкий
github логотип

GHSA-3xr6-f4mj-vjrm

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary label.

EPSS: Низкий
github логотип

GHSA-3xr6-6369-7394

почти 4 года назад

Multiple buffer overflows in BigAnt Server 2.50 SP6 and earlier allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted ZIP file that is not properly handled when the victim uses the (1) Update or (2) Plug-In console menu item.

EPSS: Низкий
github логотип

GHSA-3xr5-7rvh-x3v2

почти 2 года назад

There is a cross site scripting vulnerability in the Esri Portal for ArcGIS Experience Builder 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are low. 

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3xr4-xhxj-vcwg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-5631. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3xr4-xcg2-6xq7

больше 3 лет назад

An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.

EPSS: Низкий
github логотип

GHSA-3xr4-h6r4-mqv2

больше 3 лет назад

The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3xr3-vrm2-6jc7

больше 1 года назад

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3xr3-phjp-g6p2

почти 4 года назад

Drupal core access bypass vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xqx-95w6-xjv4

почти 3 года назад

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR) service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xqx-3w36-qfg8

больше 3 лет назад

SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing application's binaries and configuration files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xqw-4m9h-8f2c

около 1 года назад

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3xqw-45h8-m398

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

EPSS: Низкий
github логотип

GHSA-3xqv-qr6j-75m6

8 месяцев назад

A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3xqv-2ccr-mmcc

почти 2 года назад

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: REST Services). Supported versions that are affected are 12.2.9-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3xqq-gq4x-8c9g

около 1 года назад

Some parameters of the weather module are improperly stored, leaking some sensitive information.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3xqq-8r3c-qc6w

7 месяцев назад

The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3xr7-8857-qq4j

A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xr7-46q2-56ff

A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xr6-pm2j-p9qj

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always drain health in shutdown callback There is no point in recovery during device shutdown. if health work started need to wait for it to avoid races and NULL pointer access. Hence, drain health WQ on shutdown callback.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3xr6-hf43-f79h

AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3xr6-f4mj-vjrm

Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary label.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xr6-6369-7394

Multiple buffer overflows in BigAnt Server 2.50 SP6 and earlier allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted ZIP file that is not properly handled when the victim uses the (1) Update or (2) Plug-In console menu item.

8%
Низкий
почти 4 года назад
github логотип
GHSA-3xr5-7rvh-x3v2

There is a cross site scripting vulnerability in the Esri Portal for ArcGIS Experience Builder 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are low. 

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3xr4-xhxj-vcwg

Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-5631. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-3xr4-xcg2-6xq7

An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xr4-h6r4-mqv2

The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xr3-vrm2-6jc7

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3xr3-phjp-g6p2

Drupal core access bypass vulnerability

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3xqx-95w6-xjv4

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR) service.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3xqx-3w36-qfg8

SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing application's binaries and configuration files.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3xqw-4m9h-8f2c

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3xqw-45h8-m398

Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xqv-qr6j-75m6

A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-3xqv-2ccr-mmcc

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: REST Services). Supported versions that are affected are 12.2.9-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-3xqq-gq4x-8c9g

Some parameters of the weather module are improperly stored, leaking some sensitive information.

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-3xqq-8r3c-qc6w

The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
7 месяцев назад

Уязвимостей на страницу