Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wm8-ccjv-8v3m

около 4 лет назад

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6250 before 1.0.4.48, R7000 before 1.0.11.116, R7100LG before 1.0.0.64, R7900 before 1.0.4.38, R8300 before 1.0.2.144, R8500 before 1.0.2.144, XR300 before 1.0.3.68, R7000P before 1.3.2.132, and R6900P before 1.3.2.132.

EPSS: Низкий
github логотип

GHSA-3wm7-jw5g-v3gq

около 1 месяца назад

Missing Authorization vulnerability in Emraan Cheema CubeWP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CubeWP: from n/a through 1.1.27.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wm7-c6q7-cvwm

4 месяца назад

The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3wm7-5h33-f92f

почти 3 года назад

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wm6-5f35-v4rp

около 3 лет назад

An issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the return value of kmalloc().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3wm5-3g94-xp54

больше 2 лет назад

Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-3wm4-c4h2-6mcg

почти 4 года назад

Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3wm3-m3jr-6jpv

больше 3 лет назад

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

EPSS: Низкий
github логотип

GHSA-3wm3-96hr-g3vq

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Clayton Feed Comments Number allows Upload a Web Shell to a Web Server.This issue affects Feed Comments Number: from n/a through 0.2.1.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3wjx-vqf3-h2px

около 2 лет назад

In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896; Issue ID: ALPS08163896.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3wjw-f8gp-589c

больше 3 лет назад

SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-3wjw-649j-2hjx

больше 3 лет назад

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wjv-m5rx-86vp

больше 3 лет назад

Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk.

EPSS: Низкий
github логотип

GHSA-3wjv-2739-3h75

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential glock use-after-free on unmount When a DLM lockspace is released and there ares still locks in that lockspace, DLM will unlock those locks automatically. Commit fb6791d100d1b started exploiting this behavior to speed up filesystem unmount: gfs2 would simply free glocks it didn't want to unlock and then release the lockspace. This didn't take the bast callbacks for asynchronous lock contention notifications into account, which remain active until until a lock is unlocked or its lockspace is released. To prevent those callbacks from accessing deallocated objects, put the glocks that should not be unlocked on the sd_dead_glocks list, release the lockspace, and only then free those glocks. As an additional measure, ignore unexpected ast and bast callbacks if the receiving glock is dead.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wjr-p76q-rg8q

больше 2 лет назад

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3wjr-j39j-wfg8

больше 2 лет назад

An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.

CVSS3: 1.8
EPSS: Низкий
github логотип

GHSA-3wjr-cm4f-gg8r

больше 3 лет назад

The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3wjr-3jc2-hr84

около 1 года назад

A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3wjq-jhph-jc7q

около 1 года назад

A vulnerability, which was classified as problematic, was found in Trimble SPS851 488.01. This affects an unknown part of the component Ethernet Configuration Menu. The manipulation of the argument Hostname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-3wjq-88q9-5hmg

больше 3 лет назад

An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.18. Android ID: A-31251973. References: N-CVE-2016-6789.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wm8-ccjv-8v3m

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6250 before 1.0.4.48, R7000 before 1.0.11.116, R7100LG before 1.0.0.64, R7900 before 1.0.4.38, R8300 before 1.0.2.144, R8500 before 1.0.2.144, XR300 before 1.0.3.68, R7000P before 1.3.2.132, and R6900P before 1.3.2.132.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3wm7-jw5g-v3gq

Missing Authorization vulnerability in Emraan Cheema CubeWP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CubeWP: from n/a through 1.1.27.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3wm7-c6q7-cvwm

The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-3wm7-5h33-f92f

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3wm6-5f35-v4rp

An issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the return value of kmalloc().

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3wm5-3g94-xp54

Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

CVSS3: 6.1
48%
Средний
больше 2 лет назад
github логотип
GHSA-3wm4-c4h2-6mcg

Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive information via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wm3-m3jr-6jpv

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wm3-96hr-g3vq

Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Clayton Feed Comments Number allows Upload a Web Shell to a Web Server.This issue affects Feed Comments Number: from n/a through 0.2.1.

CVSS3: 10
1%
Низкий
больше 1 года назад
github логотип
GHSA-3wjx-vqf3-h2px

In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896; Issue ID: ALPS08163896.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wjw-f8gp-589c

SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wjw-649j-2hjx

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wjv-m5rx-86vp

Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wjv-2739-3h75

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential glock use-after-free on unmount When a DLM lockspace is released and there ares still locks in that lockspace, DLM will unlock those locks automatically. Commit fb6791d100d1b started exploiting this behavior to speed up filesystem unmount: gfs2 would simply free glocks it didn't want to unlock and then release the lockspace. This didn't take the bast callbacks for asynchronous lock contention notifications into account, which remain active until until a lock is unlocked or its lockspace is released. To prevent those callbacks from accessing deallocated objects, put the glocks that should not be unlocked on the sd_dead_glocks list, release the lockspace, and only then free those glocks. As an additional measure, ignore unexpected ast and bast callbacks if the receiving glock is dead.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wjr-p76q-rg8q

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
48%
Средний
больше 2 лет назад
github логотип
GHSA-3wjr-j39j-wfg8

An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.

CVSS3: 1.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wjr-cm4f-gg8r

The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wjr-3jc2-hr84

A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3wjq-jhph-jc7q

A vulnerability, which was classified as problematic, was found in Trimble SPS851 488.01. This affects an unknown part of the component Ethernet Configuration Menu. The manipulation of the argument Hostname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3wjq-88q9-5hmg

An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.18. Android ID: A-31251973. References: N-CVE-2016-6789.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу