Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 388

Количество 288 388

github логотип

GHSA-27h2-vr79-q7cq

около 3 лет назад

The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows Server DHCP service, aka "Windows DHCP Server Remote Code Execution Vulnerability".

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27h2-hvpr-p74q

больше 2 лет назад

jsonwebtoken has insecure input validation in jwt.verify function

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-27h2-5v2f-w3w2

около 3 лет назад

Adobe InDesign versions 13.0 and below have an exploitable Memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27gx-f94v-f7hr

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E4J s.r.l. VikAppointments Services Booking Calendar allows Stored XSS. This issue affects VikAppointments Services Booking Calendar: from n/a through 1.2.16.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-27gx-92r4-wr88

около 3 лет назад

A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS). The vulnerability is due to incomplete input validation of the 802.11 GAS frames that are processed by an affected device. An attacker could exploit this vulnerability by sending a crafted 802.11 GAS frame over the air to an access point (AP), and that frame would then be relayed to the affected WLC. Also, an attacker with Layer 3 connectivity to the WLC could exploit this vulnerability by sending a malicious 802.11 GAS payload in a Control and Provisioning of Wireless Access Points (CAPWAP) packet to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS.

EPSS: Низкий
github логотип

GHSA-27gx-7jvx-fj3g

около 3 лет назад

Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, and CVE-2015-0329.

EPSS: Средний
github логотип

GHSA-27gw-h248-gvvq

около 3 лет назад

Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm parameter in a load_combo_data action to sam-ajax-admin.php; or the (4) subscriber, (5) contributor, (6) author, (7) editor, (8) admin, or (9) sadmin parameter in a load_users action to sam-ajax-admin.php.

EPSS: Средний
github логотип

GHSA-27gv-mg7w-mm34

3 дня назад

Shopware race condition bypasses voucher restrictions

EPSS: Низкий
github логотип

GHSA-27gv-hmxx-3r2x

около 3 лет назад

TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote attackers to obtain telephone number or e-mail address information via a facetime-audio: URL.

EPSS: Средний
github логотип

GHSA-27gv-5xfq-qrc6

около 3 лет назад

Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

EPSS: Низкий
github логотип

GHSA-27gr-q69r-42hr

больше 3 лет назад

Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-27gp-rrp2-6hg8

больше 3 лет назад

SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-27gp-h89j-594r

9 месяцев назад

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27gp-8389-hm4w

10 дней назад

Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27gm-h9hm-9289

около 3 лет назад

In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.

EPSS: Низкий
github логотип

GHSA-27gm-ghr9-4v95

больше 5 лет назад

Cross-site scripting vulnerability in TinyMCE

EPSS: Низкий
github логотип

GHSA-27gj-wf7m-cw9x

больше 1 года назад

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-27gj-3475-hjqq

около 3 лет назад

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-27gg-xq5x-7qq6

11 месяцев назад

The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces and nodes. There is low impact on integrity and availability of the application.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-27gg-q2pj-f574

9 месяцев назад

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27h2-vr79-q7cq

The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows Server DHCP service, aka "Windows DHCP Server Remote Code Execution Vulnerability".

CVSS3: 9.8
7%
Низкий
около 3 лет назад
github логотип
GHSA-27h2-hvpr-p74q

jsonwebtoken has insecure input validation in jwt.verify function

CVSS3: 7.6
больше 2 лет назад
github логотип
GHSA-27h2-5v2f-w3w2

Adobe InDesign versions 13.0 and below have an exploitable Memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 7.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-27gx-f94v-f7hr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E4J s.r.l. VikAppointments Services Booking Calendar allows Stored XSS. This issue affects VikAppointments Services Booking Calendar: from n/a through 1.2.16.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-27gx-92r4-wr88

A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS). The vulnerability is due to incomplete input validation of the 802.11 GAS frames that are processed by an affected device. An attacker could exploit this vulnerability by sending a crafted 802.11 GAS frame over the air to an access point (AP), and that frame would then be relayed to the affected WLC. Also, an attacker with Layer 3 connectivity to the WLC could exploit this vulnerability by sending a malicious 802.11 GAS payload in a Control and Provisioning of Wireless Access Points (CAPWAP) packet to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS.

1%
Низкий
около 3 лет назад
github логотип
GHSA-27gx-7jvx-fj3g

Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, and CVE-2015-0329.

11%
Средний
около 3 лет назад
github логотип
GHSA-27gw-h248-gvvq

Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm parameter in a load_combo_data action to sam-ajax-admin.php; or the (4) subscriber, (5) contributor, (6) author, (7) editor, (8) admin, or (9) sadmin parameter in a load_users action to sam-ajax-admin.php.

12%
Средний
около 3 лет назад
github логотип
GHSA-27gv-mg7w-mm34

Shopware race condition bypasses voucher restrictions

0%
Низкий
3 дня назад
github логотип
GHSA-27gv-hmxx-3r2x

TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote attackers to obtain telephone number or e-mail address information via a facetime-audio: URL.

27%
Средний
около 3 лет назад
github логотип
GHSA-27gv-5xfq-qrc6

Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

2%
Низкий
около 3 лет назад
github логотип
GHSA-27gr-q69r-42hr

Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27gp-rrp2-6hg8

SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27gp-h89j-594r

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-27gp-8389-hm4w

Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)

CVSS3: 6.5
0%
Низкий
10 дней назад
github логотип
GHSA-27gm-h9hm-9289

In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.

0%
Низкий
около 3 лет назад
github логотип
GHSA-27gm-ghr9-4v95

Cross-site scripting vulnerability in TinyMCE

1%
Низкий
больше 5 лет назад
github логотип
GHSA-27gj-wf7m-cw9x

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-27gj-3475-hjqq

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.

CVSS3: 5.3
16%
Средний
около 3 лет назад
github логотип
GHSA-27gg-xq5x-7qq6

The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces and nodes. There is low impact on integrity and availability of the application.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-27gg-q2pj-f574

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVSS3: 5.9
0%
Низкий
9 месяцев назад

Уязвимостей на страницу