Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 292 001

Количество 292 001

github логотип

GHSA-2hvr-43xf-39rx

больше 2 лет назад

Not used in 2022

EPSS: Низкий
github логотип

GHSA-2hvq-vmfm-c497

почти 3 года назад

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2hvm-7cm7-f4p9

около 3 лет назад

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hvj-wgq7-vx3c

больше 3 лет назад

WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.

EPSS: Низкий
github логотип

GHSA-2hvj-p59v-p559

6 месяцев назад

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2hvh-v6r6-v7r4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.

EPSS: Низкий
github логотип

GHSA-2hvh-c5c2-vj85

больше 3 лет назад

Zend Framework SQL injection vector using null byte for PDO

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hvh-29rf-rgx7

больше 3 лет назад

The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automatically installs software upon completing the download of a JAR file, which makes it easier for remote attackers to execute arbitrary code via a crafted URI record in an NDEF tag.

EPSS: Низкий
github логотип

GHSA-2hvg-x2p3-jfmj

больше 3 лет назад

An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.

EPSS: Низкий
github логотип

GHSA-2hvg-v2h5-m85r

больше 3 лет назад

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

EPSS: Низкий
github логотип

GHSA-2hvg-pfw9-r56c

больше 3 лет назад

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2hvc-hwg3-hpvw

больше 2 лет назад

PaddlePaddle Out-of-bounds Read vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2hv7-f89v-j5wh

больше 2 лет назад

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. An app may be able to gain root privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hv6-pqf3-c2j2

больше 3 лет назад

Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.

EPSS: Низкий
github логотип

GHSA-2hv6-9hx6-7j2g

6 месяцев назад

Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2hv6-78vc-qvw9

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.

EPSS: Низкий
github логотип

GHSA-2hv6-3c5r-xmfv

больше 3 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Set3G param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hv5-x9f5-6mfx

больше 3 лет назад

A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.

EPSS: Низкий
github логотип

GHSA-2hv5-x25m-j674

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2hv5-gqgx-ppf5

больше 3 лет назад

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hvr-43xf-39rx

Not used in 2022

больше 2 лет назад
github логотип
GHSA-2hvq-vmfm-c497

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2hvm-7cm7-f4p9

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2hvj-wgq7-vx3c

WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvj-p59v-p559

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-2hvh-v6r6-v7r4

Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvh-c5c2-vj85

Zend Framework SQL injection vector using null byte for PDO

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvh-29rf-rgx7

The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automatically installs software upon completing the download of a JAR file, which makes it easier for remote attackers to execute arbitrary code via a crafted URI record in an NDEF tag.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvg-x2p3-jfmj

An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.6. Local attackers able to access the Aspeed LPC control interface could overwrite memory in the kernel and potentially execute privileges, aka CID-b49a0e69a7b1. This occurs because a certain comparison uses values that are not memory sizes.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvg-v2h5-m85r

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvg-pfw9-r56c

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

CVSS3: 9.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hvc-hwg3-hpvw

PaddlePaddle Out-of-bounds Read vulnerability

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2hv7-f89v-j5wh

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. An app may be able to gain root privileges.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2hv6-pqf3-c2j2

Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-2hv6-9hx6-7j2g

Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

CVSS3: 4.9
0%
Низкий
6 месяцев назад
github логотип
GHSA-2hv6-78vc-qvw9

Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hv6-3c5r-xmfv

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Set3G param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hv5-x9f5-6mfx

A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hv5-x25m-j674

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
94%
Критический
больше 3 лет назад
github логотип
GHSA-2hv5-gqgx-ppf5

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу