Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-29rx-6x28-gmg7

больше 3 лет назад

Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command.

EPSS: Средний
github логотип

GHSA-29rx-6chj-44xc

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions While running the self-tests on a KASAN enabled kernel, I observed a slab-out-of-bounds splat very similar to the one reported in commit 821bbf79fe46 ("ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions"). We additionally need to take care of fib6_metrics initialization failure when the caller provides an nh. The fix is similar, explicitly free the route instead of calling fib6_info_release on a half-initialized object.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-29rw-r45r-xcv9

5 месяцев назад

Missing Authorization vulnerability in Uriahs Victor Printus allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printus: from n/a through 1.2.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29rw-jx9g-7h6h

больше 2 лет назад

Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. A local low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code on the operating system with high privileges.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-29rw-9f7v-mm2r

больше 3 лет назад

WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2013-0960.

EPSS: Низкий
github логотип

GHSA-29rw-7xhw-cxx2

7 месяцев назад

An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29rv-fqx2-4c9f

больше 3 лет назад

Deserialization of Untrusted Data in SinGooCMS.Utility

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29rr-mhwv-g7pr

больше 3 лет назад

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page (potentially through a authentication bypass such as CVE-2017-3191) may obtain administrator credentials for the device.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-29rq-jjgh-p8gh

больше 3 лет назад

Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Server 8.1 before FP1 have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-29rp-7r7x-62j8

около 3 лет назад

The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM.

EPSS: Средний
github логотип

GHSA-29rp-63rm-r6fr

больше 3 лет назад

Buffer overflow in ldcconn in Hewlett-Packard (HP) Controller for Cisco Local Director on HP-UX 11.11i allows remote attackers to execute arbitrary code via a long string to TCP port 17781.

EPSS: Средний
github логотип

GHSA-29rm-xc84-5q8f

7 дней назад

This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and analyzing the binary data to retrieve the hard-coded MQTT credentials and endpoints from the targeted device. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the MQTT broker and manipulate the communications of the targeted device.

EPSS: Низкий
github логотип

GHSA-29rm-vp9j-87qp

больше 3 лет назад

IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 allows remote authenticated users to obtain sensitive Java stack-trace information by providing invalid input data.

EPSS: Низкий
github логотип

GHSA-29rm-j4cx-hmc5

около 1 года назад

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29rm-7h6p-fjf3

больше 3 лет назад

An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-29rm-6752-gvwv

больше 3 лет назад

Code execution in Apache Struts 1 plugin

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-29rj-x2c5-pc2r

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in samsk WP DataTable allows DOM-Based XSS. This issue affects WP DataTable: from n/a through 0.2.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29rj-hpwg-g8vj

около 3 лет назад

In the Android kernel in the mnh driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-29rj-95hw-fhm9

больше 2 лет назад

The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information in its log files (which are publicly accessible), including DeepL API key.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29rj-6gfr-wmfc

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wipeout Media CSS & JavaScript Toolbox allows Stored XSS.This issue affects CSS & JavaScript Toolbox: from n/a through 11.7.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29rx-6x28-gmg7

Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command.

11%
Средний
больше 3 лет назад
github логотип
GHSA-29rx-6chj-44xc

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions While running the self-tests on a KASAN enabled kernel, I observed a slab-out-of-bounds splat very similar to the one reported in commit 821bbf79fe46 ("ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions"). We additionally need to take care of fib6_metrics initialization failure when the caller provides an nh. The fix is similar, explicitly free the route instead of calling fib6_info_release on a half-initialized object.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-29rw-r45r-xcv9

Missing Authorization vulnerability in Uriahs Victor Printus allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printus: from n/a through 1.2.6.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-29rw-jx9g-7h6h

Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. A local low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code on the operating system with high privileges.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29rw-9f7v-mm2r

WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2013-0960.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-29rw-7xhw-cxx2

An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-29rv-fqx2-4c9f

Deserialization of Untrusted Data in SinGooCMS.Utility

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29rr-mhwv-g7pr

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page (potentially through a authentication bypass such as CVE-2017-3191) may obtain administrator credentials for the device.

CVSS3: 9.8
40%
Средний
больше 3 лет назад
github логотип
GHSA-29rq-jjgh-p8gh

Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Server 8.1 before FP1 have unknown impact and attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-29rp-7r7x-62j8

The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM.

13%
Средний
около 3 лет назад
github логотип
GHSA-29rp-63rm-r6fr

Buffer overflow in ldcconn in Hewlett-Packard (HP) Controller for Cisco Local Director on HP-UX 11.11i allows remote attackers to execute arbitrary code via a long string to TCP port 17781.

15%
Средний
больше 3 лет назад
github логотип
GHSA-29rm-xc84-5q8f

This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and analyzing the binary data to retrieve the hard-coded MQTT credentials and endpoints from the targeted device. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the MQTT broker and manipulate the communications of the targeted device.

0%
Низкий
7 дней назад
github логотип
GHSA-29rm-vp9j-87qp

IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 allows remote authenticated users to obtain sensitive Java stack-trace information by providing invalid input data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29rm-j4cx-hmc5

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
9%
Низкий
около 1 года назад
github логотип
GHSA-29rm-7h6p-fjf3

An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-29rm-6752-gvwv

Code execution in Apache Struts 1 plugin

CVSS3: 9.8
94%
Критический
больше 3 лет назад
github логотип
GHSA-29rj-x2c5-pc2r

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in samsk WP DataTable allows DOM-Based XSS. This issue affects WP DataTable: from n/a through 0.2.7.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-29rj-hpwg-g8vj

In the Android kernel in the mnh driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-29rj-95hw-fhm9

The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information in its log files (which are publicly accessible), including DeepL API key.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-29rj-6gfr-wmfc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wipeout Media CSS & JavaScript Toolbox allows Stored XSS.This issue affects CSS & JavaScript Toolbox: from n/a through 11.7.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу