Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wfr-9gjx-63gf

больше 3 лет назад

iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.

EPSS: Низкий
github логотип

GHSA-3wfq-h43q-w8hw

больше 3 лет назад

IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive information due to easy to guess session identifier names. IBM X-Force ID: 162658.

EPSS: Низкий
github логотип

GHSA-3wfq-4hqg-3c4g

больше 3 лет назад

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112890242

EPSS: Низкий
github логотип

GHSA-3wfp-9jx5-5xmc

около 3 лет назад

The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3wfp-98cg-vgm9

больше 3 лет назад

Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3wfp-4xf2-2wr9

11 месяцев назад

A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wfp-4rwx-xmxg

около 2 лет назад

A vulnerability was found in SourceCodester Simple Image Stack Website 1.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument search with the input sy2ap%22%3e%3cscript%3ealert(1)%3c%2fscript%3etkxh1 leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248255.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3wfp-253j-5jxv

около 2 лет назад

SSRF & Credentials Leak

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wfm-93m9-mc3c

больше 3 лет назад

An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It allows an attacker to cause Denial of Service.

EPSS: Низкий
github логотип

GHSA-3wfj-vh84-732p

больше 3 лет назад

Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3wfj-3x8q-hrpg

больше 1 года назад

Kubean vulnerable to cluster-level privilege escalation

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3wfh-qwcv-pvx7

почти 3 года назад

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wfh-qf63-pj8r

больше 3 лет назад

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wfh-mxpq-hxqh

больше 3 лет назад

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wfh-36rx-9537

5 месяцев назад

Timing Attack Vulnerability in SCRAM Authentication

EPSS: Низкий
github логотип

GHSA-3wfg-xv96-62cq

больше 3 лет назад

On BIG-IP 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, SNMP may expose sensitive configuration objects over insecure transmission channels. This issue is exposed when a passphrase is used with various profile types and is accessed using SNMPv2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wfg-qqr3-6ppg

больше 3 лет назад

A vulnerability was found in SourceCodester Employee Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /process/aprocess.php. The manipulation of the argument mailuid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205837 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wfg-8w2f-r7qj

больше 3 лет назад

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3 - 12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-3wff-jp8x-6p8q

больше 3 лет назад

The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to executing external commands with the commands.getstatusoutput function.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3wf9-55j2-66rj

около 1 года назад

The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgsv' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wfr-9gjx-63gf

iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wfq-h43q-w8hw

IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive information due to easy to guess session identifier names. IBM X-Force ID: 162658.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wfq-4hqg-3c4g

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112890242

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wfp-9jx5-5xmc

The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3wfp-98cg-vgm9

Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.

CVSS3: 9.8
26%
Средний
больше 3 лет назад
github логотип
GHSA-3wfp-4xf2-2wr9

A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3wfp-4rwx-xmxg

A vulnerability was found in SourceCodester Simple Image Stack Website 1.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument search with the input sy2ap%22%3e%3cscript%3ealert(1)%3c%2fscript%3etkxh1 leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248255.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wfp-253j-5jxv

SSRF & Credentials Leak

CVSS3: 7.5
2%
Низкий
около 2 лет назад
github логотип
GHSA-3wfm-93m9-mc3c

An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It allows an attacker to cause Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wfj-vh84-732p

Improper Neutralization of Special Elements used in an OS Command in Apache ActiveMQ

CVSS3: 7.5
11%
Средний
больше 3 лет назад
github логотип
GHSA-3wfj-3x8q-hrpg

Kubean vulnerable to cluster-level privilege escalation

CVSS3: 6
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wfh-qwcv-pvx7

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3wfh-qf63-pj8r

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655.

CVSS3: 7.5
6%
Низкий
больше 3 лет назад
github логотип
GHSA-3wfh-mxpq-hxqh

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3wfh-36rx-9537

Timing Attack Vulnerability in SCRAM Authentication

0%
Низкий
5 месяцев назад
github логотип
GHSA-3wfg-xv96-62cq

On BIG-IP 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, SNMP may expose sensitive configuration objects over insecure transmission channels. This issue is exposed when a passphrase is used with various profile types and is accessed using SNMPv2.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wfg-qqr3-6ppg

A vulnerability was found in SourceCodester Employee Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /process/aprocess.php. The manipulation of the argument mailuid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205837 was assigned to this vulnerability.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wfg-8w2f-r7qj

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3 - 12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

4%
Низкий
больше 3 лет назад
github логотип
GHSA-3wff-jp8x-6p8q

The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to executing external commands with the commands.getstatusoutput function.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wf9-55j2-66rj

The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgsv' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу