Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3w5q-79rf-8vf9

больше 3 лет назад

SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.

EPSS: Низкий
github логотип

GHSA-3w5p-vghj-6qj4

почти 2 года назад

Kofax Power PDF GIF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of GIF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20488.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3w5p-rx33-772h

больше 3 лет назад

The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to gain privileges via a crafted application, aka internal bug 28815329.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3w5p-jhp5-c29q

больше 3 лет назад

.NET Core & .NET Framework Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w5m-p4xw-h642

больше 3 лет назад

A security feature bypass vulnerability exists in Microsoft Edge handles whitelisting, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-3w5m-mfmj-cpcf

больше 1 года назад

Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3w5m-3c69-745h

около 2 месяцев назад

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w5j-m9x3-4g6r

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandrika Sista WP Category Dropdown allows Stored XSS. This issue affects WP Category Dropdown: from n/a through 1.9.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3w5h-x4rh-hc28

около 4 лет назад

Exposure of sensitive information in Apache Ozone

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3w5h-vwcq-cggw

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0587.

EPSS: Низкий
github логотип

GHSA-3w5h-qwww-3fff

больше 3 лет назад

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-3w5g-989p-35r8

больше 3 лет назад

Apache Avro Rust SDK corrupted data read can cause crash

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w5g-8rr6-f44g

больше 3 лет назад

PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

EPSS: Низкий
github логотип

GHSA-3w5f-gpqh-rrhw

больше 3 лет назад

Incorrect Access Control in Hunesion i-oneNet 3.0.6042.1200 allows the local user to access other user's information which is unauthorized via brute force.

EPSS: Низкий
github логотип

GHSA-3w59-vx6f-4274

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: cdc_eem: fix tx fixup skb leak when usbnet transmit a skb, eem fixup it in eem_tx_fixup(), if skb_copy_expand() failed, it return NULL, usbnet_start_xmit() will have no chance to free original skb. fix it by free orginal skb in eem_tx_fixup() first, then check skb clone status, if failed, return NULL to usbnet.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3w59-vcg7-gcq2

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the KnowledgeView Editorial and Management application allows remote attackers to inject arbitrary web script or HTML via the username parameter.

EPSS: Низкий
github логотип

GHSA-3w59-rcgh-98r3

почти 4 года назад

Multiple buffer overflows in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via a (1) long command, (2) long server argument to the (a) connect or (b) server commands, (3) long nick argument to the (c) nick command, or a long (4) nick or (5) message argument to the (d) ctcp, (e) chat, (f) notice, (g) message (msg), or (h) query commands.

EPSS: Низкий
github логотип

GHSA-3w59-qgf8-pph5

10 месяцев назад

Missing Authorization vulnerability in FADI MED Editor Wysiwyg Background Color allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Editor Wysiwyg Background Color: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3w57-6469-585x

больше 3 лет назад

Etherpad Lite before 1.6.4 is exploitable for admin access.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3w57-3p47-w8ch

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SKB_FRAGS values Sabrina reported the following splat: WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_add_weight_locked+0x8f2/0xba0 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.14.0-rc1-net-00092-g011b03359038 #996 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014 RIP: 0010:netif_napi_add_weight_locked+0x8f2/0xba0 Code: e8 c3 e6 6a fe 48 83 c4 28 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc c7 44 24 10 ff ff ff ff e9 8f fb ff ff e8 9e e6 6a fe <0f> 0b e9 d3 fe ff ff e8 92 e6 6a fe 48 8b 04 24 be ff ff ff ff 48 RSP: 0000:ffffc9000001fc60 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff88806ce48128 RCX: 1ffff11001664b9e RDX: ffff888008f00040 RSI: ffffffff8317ca42 RDI: ffff88800b325cb6 RBP: ffff88800b325c40 R08: 0000000000000001 R09: ffffed100167502c ...

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w5q-79rf-8vf9

SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w5p-vghj-6qj4

Kofax Power PDF GIF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of GIF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20488.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3w5p-rx33-772h

The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 mishandles heap pointers, which allows attackers to gain privileges via a crafted application, aka internal bug 28815329.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w5p-jhp5-c29q

.NET Core & .NET Framework Denial of Service Vulnerability

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3w5m-p4xw-h642

A security feature bypass vulnerability exists in Microsoft Edge handles whitelisting, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.

CVSS3: 5.9
12%
Средний
больше 3 лет назад
github логотип
GHSA-3w5m-mfmj-cpcf

Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3w5m-3c69-745h

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3w5j-m9x3-4g6r

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandrika Sista WP Category Dropdown allows Stored XSS. This issue affects WP Category Dropdown: from n/a through 1.9.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3w5h-x4rh-hc28

Exposure of sensitive information in Apache Ozone

CVSS3: 9.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-3w5h-vwcq-cggw

Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0587.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3w5h-qwww-3fff

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w5g-989p-35r8

Apache Avro Rust SDK corrupted data read can cause crash

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3w5g-8rr6-f44g

PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3w5f-gpqh-rrhw

Incorrect Access Control in Hunesion i-oneNet 3.0.6042.1200 allows the local user to access other user's information which is unauthorized via brute force.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w59-vx6f-4274

In the Linux kernel, the following vulnerability has been resolved: net: cdc_eem: fix tx fixup skb leak when usbnet transmit a skb, eem fixup it in eem_tx_fixup(), if skb_copy_expand() failed, it return NULL, usbnet_start_xmit() will have no chance to free original skb. fix it by free orginal skb in eem_tx_fixup() first, then check skb clone status, if failed, return NULL to usbnet.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3w59-vcg7-gcq2

Cross-site scripting (XSS) vulnerability in the KnowledgeView Editorial and Management application allows remote attackers to inject arbitrary web script or HTML via the username parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3w59-rcgh-98r3

Multiple buffer overflows in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via a (1) long command, (2) long server argument to the (a) connect or (b) server commands, (3) long nick argument to the (c) nick command, or a long (4) nick or (5) message argument to the (d) ctcp, (e) chat, (f) notice, (g) message (msg), or (h) query commands.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3w59-qgf8-pph5

Missing Authorization vulnerability in FADI MED Editor Wysiwyg Background Color allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Editor Wysiwyg Background Color: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3w57-6469-585x

Etherpad Lite before 1.6.4 is exploitable for admin access.

CVSS3: 9.8
60%
Средний
больше 3 лет назад
github логотип
GHSA-3w57-3p47-w8ch

In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SKB_FRAGS values Sabrina reported the following splat: WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_add_weight_locked+0x8f2/0xba0 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.14.0-rc1-net-00092-g011b03359038 #996 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014 RIP: 0010:netif_napi_add_weight_locked+0x8f2/0xba0 Code: e8 c3 e6 6a fe 48 83 c4 28 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc c7 44 24 10 ff ff ff ff e9 8f fb ff ff e8 9e e6 6a fe <0f> 0b e9 d3 fe ff ff e8 92 e6 6a fe 48 8b 04 24 be ff ff ff ff 48 RSP: 0000:ffffc9000001fc60 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff88806ce48128 RCX: 1ffff11001664b9e RDX: ffff888008f00040 RSI: ffffffff8317ca42 RDI: ffff88800b325cb6 RBP: ffff88800b325c40 R08: 0000000000000001 R09: ffffed100167502c ...

CVSS3: 5.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу