Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 896

Количество 288 896

github логотип

GHSA-288r-47q4-jvxj

около 2 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wow-Company Hover Effects allows SQL Injection. This issue affects Hover Effects: from n/a through 2.1.2.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-288p-75q5-6gj7

11 месяцев назад

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour configuration page in the web interface of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-288m-xm7h-p3xh

около 3 лет назад

Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.

EPSS: Низкий
github логотип

GHSA-288h-hv2q-fwrv

около 3 лет назад

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. This may be used to corrupt nearby heap contents (leading to a query-of-death scenario) or may be used to bypass Envoy's access control mechanisms such as path based routing. An attacker can also modify requests from other users that happen to be proximal temporally and spatially.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-288h-h8hx-vvqm

больше 1 года назад

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-288h-f6gm-4vf9

больше 3 лет назад

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

EPSS: Средний
github логотип

GHSA-288h-4m8f-x8cf

около 3 лет назад

Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-288f-gh2h-9j8q

больше 3 лет назад

Mumble: murmur-server has DoS due to malformed client query

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-288c-fr85-5qmw

около 3 лет назад

The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authentication of users via a rogue access point and a man-in-the-middle attack.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-288c-cq4h-88gq

больше 4 лет назад

XML External Entity (XXE) Injection in Jackson Databind

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-288c-8vm9-x4gr

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

EPSS: Низкий
github логотип

GHSA-2889-44x2-9xg5

около 3 лет назад

, aka 'Windows Overlay Filter Security Feature Bypass Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2888-q29x-2g3p

больше 2 лет назад

A man in the middle can redirect traffic to a malicious server in a compromised configuration.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2888-p547-jrjr

2 месяца назад

Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bs_SetDNSInfo function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2888-gm7h-x2rw

10 месяцев назад

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2887-wp98-w322

около 3 лет назад

Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2887-hwqc-wcg8

больше 3 лет назад

Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.

EPSS: Низкий
github логотип

GHSA-2886-x646-53fj

больше 3 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2886-fxgx-g9vm

около 3 лет назад

An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.

EPSS: Низкий
github логотип

GHSA-2885-vc9p-8279

7 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Event Espresso Event Espresso 4 Decaf allows Cross Site Request Forgery.This issue affects Event Espresso 4 Decaf: from n/a through 5.0.28.decaf.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-288r-47q4-jvxj

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wow-Company Hover Effects allows SQL Injection. This issue affects Hover Effects: from n/a through 2.1.2.

CVSS3: 7.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-288p-75q5-6gj7

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour configuration page in the web interface of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-288m-xm7h-p3xh

Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.

5%
Низкий
около 3 лет назад
github логотип
GHSA-288h-hv2q-fwrv

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. This may be used to corrupt nearby heap contents (leading to a query-of-death scenario) or may be used to bypass Envoy's access control mechanisms such as path based routing. An attacker can also modify requests from other users that happen to be proximal temporally and spatially.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-288h-h8hx-vvqm

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-288h-f6gm-4vf9

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

37%
Средний
больше 3 лет назад
github логотип
GHSA-288h-4m8f-x8cf

Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.

CVSS3: 4.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-288f-gh2h-9j8q

Mumble: murmur-server has DoS due to malformed client query

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-288c-fr85-5qmw

The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authentication of users via a rogue access point and a man-in-the-middle attack.

CVSS3: 8.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-288c-cq4h-88gq

XML External Entity (XXE) Injection in Jackson Databind

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-288c-8vm9-x4gr

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-2889-44x2-9xg5

, aka 'Windows Overlay Filter Security Feature Bypass Vulnerability'.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2888-q29x-2g3p

A man in the middle can redirect traffic to a malicious server in a compromised configuration.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2888-p547-jrjr

Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bs_SetDNSInfo function.

CVSS3: 9.8
1%
Низкий
2 месяца назад
github логотип
GHSA-2888-gm7h-x2rw

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-2887-wp98-w322

Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2887-hwqc-wcg8

Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2886-x646-53fj

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 8.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-2886-fxgx-g9vm

An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.

1%
Низкий
около 3 лет назад
github логотип
GHSA-2885-vc9p-8279

Cross-Site Request Forgery (CSRF) vulnerability in Event Espresso Event Espresso 4 Decaf allows Cross Site Request Forgery.This issue affects Event Espresso 4 Decaf: from n/a through 5.0.28.decaf.

CVSS3: 4.3
0%
Низкий
7 месяцев назад

Уязвимостей на страницу