Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3x7g-rh72-3g94

8 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3x7c-c6rj-mhq6

8 месяцев назад

A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the file src/mme/emm-sm.c of the component AMF/MME. The manipulation of the argument ran_ue_id leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 62cb99755243c9c38e4c060c5d8d0e158fe8cdd5. It is recommended to apply a patch to fix this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3x7c-249g-p329

почти 4 года назад

A version of rusers is running that exposes valid user information to any entity on the network.

EPSS: Низкий
github логотип

GHSA-3x79-rfwc-8cjp

больше 3 лет назад

Improper conditions check in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable information disclosure and denial of service via local

EPSS: Низкий
github логотип

GHSA-3x79-3x7f-qrvm

около 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

EPSS: Низкий
github логотип

GHSA-3x79-282m-jh8f

23 дня назад

The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 21.0.9 via the MfaGoogleAuthToggle class due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable Google Authenticator for any user.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x78-vqmp-hr8w

больше 3 лет назад

Directory traversal vulnerability in the web interface in the Health Monitor service in MatrikonOPC A&E Historian 1.0.0.0 allows remote attackers to read and delete arbitrary files via a crafted URL.

EPSS: Низкий
github логотип

GHSA-3x78-7j32-qc4w

больше 3 лет назад

kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.

EPSS: Низкий
github логотип

GHSA-3x77-v8f7-wp2v

больше 2 лет назад

Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3x77-qmhw-v3hg

больше 3 лет назад

p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x77-52mc-3mpg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the "Search Site" field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3x76-j3jj-439j

больше 3 лет назад

MoinMoin Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3x76-36rv-8v95

больше 2 лет назад

In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue ID: ALPS07340108.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3x74-wgfj-fp94

больше 3 лет назад

An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September 2020).

EPSS: Низкий
github логотип

GHSA-3x74-v64j-qc3f

больше 2 лет назад

Withdrawn Advisory: CraftCMS Server-Side Template Injection vulnerability

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3x74-43v8-rvp5

больше 3 лет назад

In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x73-wm98-jh2g

больше 3 лет назад

Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x73-qc77-ff3v

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3x73-p8v6-p37w

больше 3 лет назад

A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x73-p3qx-cwqw

больше 3 лет назад

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x7g-rh72-3g94

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-3x7c-c6rj-mhq6

A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the file src/mme/emm-sm.c of the component AMF/MME. The manipulation of the argument ran_ue_id leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 62cb99755243c9c38e4c060c5d8d0e158fe8cdd5. It is recommended to apply a patch to fix this issue.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3x7c-249g-p329

A version of rusers is running that exposes valid user information to any entity on the network.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3x79-rfwc-8cjp

Improper conditions check in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable information disclosure and denial of service via local

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x79-3x7f-qrvm

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3x79-282m-jh8f

The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 21.0.9 via the MfaGoogleAuthToggle class due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable Google Authenticator for any user.

CVSS3: 4.3
0%
Низкий
23 дня назад
github логотип
GHSA-3x78-vqmp-hr8w

Directory traversal vulnerability in the web interface in the Health Monitor service in MatrikonOPC A&E Historian 1.0.0.0 allows remote attackers to read and delete arbitrary files via a crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x78-7j32-qc4w

kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x77-v8f7-wp2v

Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3x77-qmhw-v3hg

p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x77-52mc-3mpg

Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the "Search Site" field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3x76-j3jj-439j

MoinMoin Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x76-36rv-8v95

In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue ID: ALPS07340108.

CVSS3: 4.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3x74-wgfj-fp94

An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September 2020).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x74-v64j-qc3f

Withdrawn Advisory: CraftCMS Server-Side Template Injection vulnerability

CVSS3: 7.2
4%
Низкий
больше 2 лет назад
github логотип
GHSA-3x74-43v8-rvp5

In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x73-wm98-jh2g

Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x73-qc77-ff3v

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3x73-p8v6-p37w

A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3x73-p3qx-cwqw

ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу