Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-29p6-95r6-cqqg

больше 3 лет назад

Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.

EPSS: Низкий
github логотип

GHSA-29p6-49p2-4mg8

больше 1 года назад

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-29p5-jqph-prvj

около 3 лет назад

Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-29p5-chfq-8h6j

около 3 лет назад

Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclosure of certain sensitive information. The attacker may be able to use the exposed information to access and further vulnerability research.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29p4-j6wv-3g22

больше 3 лет назад

Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with the infrastructure mode.

EPSS: Низкий
github логотип

GHSA-29p3-gxfx-6jvv

больше 3 лет назад

CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.

EPSS: Низкий
github логотип

GHSA-29p3-gqrh-c7mr

больше 3 лет назад

The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.

EPSS: Низкий
github логотип

GHSA-29p2-p4jq-qf4p

больше 3 лет назад

An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29p2-mh35-x8wh

около 3 лет назад

Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.

EPSS: Низкий
github логотип

GHSA-29p2-7jvf-2jvf

больше 1 года назад

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'roll_no' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29mx-jm4m-v9x5

около 3 лет назад

Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29mx-gmwr-vhpf

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."

EPSS: Низкий
github логотип

GHSA-29mx-8r38-hfxq

около 2 лет назад

** UNSUPPORTED WHEN ASSIGNED ** Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29mx-4gvm-rgfp

почти 2 года назад

Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29mw-wpgm-hmr9

больше 3 лет назад

Regular Expression Denial of Service (ReDoS) in lodash

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29mv-gccw-23pv

больше 3 лет назад

The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-29mr-mxx6-f3f5

больше 3 лет назад

SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

EPSS: Низкий
github логотип

GHSA-29mr-gr4c-vf9c

около 3 лет назад

Magento 2 Community Edition XSS Vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-29mr-2jgg-289p

больше 3 лет назад

PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29mq-gwwx-vg5f

больше 3 лет назад

Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) dwpage.php or (2) wantedpages.php, different vectors than CVE-2006-4074. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29p6-95r6-cqqg

Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29p6-49p2-4mg8

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-29p5-jqph-prvj

Adobe After Effects version 18.2.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1%
Низкий
около 3 лет назад
github логотип
GHSA-29p5-chfq-8h6j

Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclosure of certain sensitive information. The attacker may be able to use the exposed information to access and further vulnerability research.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-29p4-j6wv-3g22

Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with the infrastructure mode.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29p3-gxfx-6jvv

CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29p3-gqrh-c7mr

The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29p2-p4jq-qf4p

An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29p2-mh35-x8wh

Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.

0%
Низкий
около 3 лет назад
github логотип
GHSA-29p2-7jvf-2jvf

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'roll_no' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
больше 1 года назад
github логотип
GHSA-29mx-jm4m-v9x5

Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability.

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-29mx-gmwr-vhpf

Cross-site scripting (XSS) vulnerability in MyBB before 1.6.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "usernames via AJAX."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29mx-8r38-hfxq

** UNSUPPORTED WHEN ASSIGNED ** Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-29mx-4gvm-rgfp

Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-29mw-wpgm-hmr9

Regular Expression Denial of Service (ReDoS) in lodash

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29mv-gccw-23pv

The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.

CVSS3: 9.8
64%
Средний
больше 3 лет назад
github логотип
GHSA-29mr-mxx6-f3f5

SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-29mr-gr4c-vf9c

Magento 2 Community Edition XSS Vulnerability

CVSS3: 4.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-29mr-2jgg-289p

PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29mq-gwwx-vg5f

Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) dwpage.php or (2) wantedpages.php, different vectors than CVE-2006-4074. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу