Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wwx-rqjr-vjcc

больше 1 года назад

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity violations. Confidentiality and Availability are not impacted.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wwx-c927-c5wg

больше 3 лет назад

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

EPSS: Высокий
github логотип

GHSA-3wwx-8m7x-49qc

больше 3 лет назад

Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wwx-63fv-pfq6

больше 1 года назад

Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-3wwx-33h5-h9f5

больше 3 лет назад

CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when running ccn-lite-sim, which trigger an out-of-bounds access.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3www-q54h-9529

больше 3 лет назад

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data Descriptor IE in an artificially crafted 802.11 frame with IE length more than 255, an infinite loop may potentially occur resulting in a denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wwr-wv4x-4gxg

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in the hwrng device read path. This triggers when the user reads from /dev/hwrng into memory also mmap-ed from /dev/hwrng. The resulting page fault triggers a recursive read which then dead-locks. Fix this by using a stack buffer when calling copy_to_user.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3wwr-3g9f-9gc7

около 1 года назад

ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3wwm-hjv7-23r3

6 месяцев назад

Pyload log Injection via API /json/add_package in add_name parameter

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wwj-wh2w-g4xp

почти 4 года назад

CRLF Injection in microweber

CVSS3: 7.6
EPSS: Средний
github логотип

GHSA-3wwj-m72m-pxmg

больше 3 лет назад

The mintToken function of a smart contract implementation for GMile, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wwj-66cm-595v

больше 3 лет назад

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wwh-pgg6-388g

около 1 года назад

The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.3 via the 'dpp_duplicate_as_draft' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wwh-6q6g-6h9m

больше 2 лет назад

The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3wwh-3w44-g9jf

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to memory leak .

EPSS: Низкий
github логотип

GHSA-3wwg-wvhq-f8q7

больше 2 лет назад

Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wwg-h2fr-3v7w

больше 3 лет назад

The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wwg-cr75-7x49

больше 3 лет назад

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.

EPSS: Низкий
github логотип

GHSA-3wwc-wp82-fpv7

больше 2 лет назад

A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-230081 was assigned to this vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3wwc-wj68-5rvm

почти 4 года назад

Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wwx-rqjr-vjcc

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity violations. Confidentiality and Availability are not impacted.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wwx-c927-c5wg

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

86%
Высокий
больше 3 лет назад
github логотип
GHSA-3wwx-8m7x-49qc

Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wwx-63fv-pfq6

Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wwx-33h5-h9f5

CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when running ccn-lite-sim, which trigger an out-of-bounds access.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3www-q54h-9529

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data Descriptor IE in an artificially crafted 802.11 frame with IE length more than 255, an infinite loop may potentially occur resulting in a denial of service.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wwr-wv4x-4gxg

In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in the hwrng device read path. This triggers when the user reads from /dev/hwrng into memory also mmap-ed from /dev/hwrng. The resulting page fault triggers a recursive read which then dead-locks. Fix this by using a stack buffer when calling copy_to_user.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3wwr-3g9f-9gc7

ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape

CVSS3: 8.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3wwm-hjv7-23r3

Pyload log Injection via API /json/add_package in add_name parameter

CVSS3: 4.3
6 месяцев назад
github логотип
GHSA-3wwj-wh2w-g4xp

CRLF Injection in microweber

CVSS3: 7.6
29%
Средний
почти 4 года назад
github логотип
GHSA-3wwj-m72m-pxmg

The mintToken function of a smart contract implementation for GMile, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wwj-66cm-595v

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

CVSS3: 7.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-3wwh-pgg6-388g

The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.3 via the 'dpp_duplicate_as_draft' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3wwh-6q6g-6h9m

The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wwh-3w44-g9jf

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to memory leak .

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3wwg-wvhq-f8q7

Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3wwg-h2fr-3v7w

The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wwg-cr75-7x49

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-3wwc-wp82-fpv7

A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-230081 was assigned to this vulnerability.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wwc-wj68-5rvm

Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу