Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3qvh-3pw4-rwqj

больше 3 лет назад

Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-3qvg-9v4g-6r36

почти 4 года назад

Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3qvc-cqxx-gjpr

почти 3 года назад

A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. This affects an unknown part of the file /admin/positions_delete.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225939.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qv9-m92v-vjc6

8 месяцев назад

The ESV Bible Shortcode for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'esv' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3qv9-4g62-x4w2

больше 3 лет назад

A denial of service vulnerability in the NVIDIA camera driver could enable an attacker to cause a local permanent denial of service, which may require reflashing the operating system to repair the device. This issue is rated as High due to the possibility of local permanent denial of service. Product: Android. Versions: Kernel-3.10. Android ID: A-31403040. References: N-CVE-2016-8395.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3qv9-34qr-5g8r

больше 3 лет назад

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user to the driver is not correctly validated before it is dereferenced for a write operation, may lead to denial of service or potential escalation of privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qv8-w3q2-f3xx

почти 3 года назад

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3qv8-vwg9-439r

больше 1 года назад

WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the WithSecure plugin hosting service. By creating a symbolic link, an attacker can abuse the service to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23035.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3qv8-v62r-xfqv

больше 3 лет назад

The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unauthenticated remote attacker may be able to modify the POST request and insert a SQL query which may then be executed by the backend server. eTRAKiT 3.2.1.17 was tested, but other versions may also be vulnerable.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qv8-hqcp-vhrh

больше 3 лет назад

The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-3qv8-4pm7-wp59

почти 4 года назад

Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.

EPSS: Низкий
github логотип

GHSA-3qv8-368w-r69p

больше 3 лет назад

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qv7-rvwv-j55x

почти 4 года назад

SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

EPSS: Низкий
github логотип

GHSA-3qv7-9m5q-pf8g

около 1 года назад

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import plugin settings.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qv7-98vm-xx2v

больше 3 лет назад

MantisBT cross-site scripting (XSS) vulnerability through crafted PATH_INFO

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qv6-q4gp-2pm4

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

EPSS: Низкий
github логотип

GHSA-3qv6-5f5f-f89j

больше 1 года назад

User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3qv5-8wgg-g4c6

больше 2 лет назад

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qv5-55f8-3w6h

больше 3 лет назад

The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."

EPSS: Критический
github логотип

GHSA-3qv5-4cw7-x42h

больше 3 лет назад

The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an attacker to gain control by tricking a user into making a request.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qvh-3pw4-rwqj

Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

53%
Средний
больше 3 лет назад
github логотип
GHSA-3qvg-9v4g-6r36

Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3qvc-cqxx-gjpr

A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. This affects an unknown part of the file /admin/positions_delete.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225939.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3qv9-m92v-vjc6

The ESV Bible Shortcode for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'esv' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-3qv9-4g62-x4w2

A denial of service vulnerability in the NVIDIA camera driver could enable an attacker to cause a local permanent denial of service, which may require reflashing the operating system to repair the device. This issue is rated as High due to the possibility of local permanent denial of service. Product: Android. Versions: Kernel-3.10. Android ID: A-31403040. References: N-CVE-2016-8395.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qv9-34qr-5g8r

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user to the driver is not correctly validated before it is dereferenced for a write operation, may lead to denial of service or potential escalation of privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qv8-w3q2-f3xx

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3qv8-vwg9-439r

WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the WithSecure plugin hosting service. By creating a symbolic link, an attacker can abuse the service to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23035.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qv8-v62r-xfqv

The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unauthenticated remote attacker may be able to modify the POST request and insert a SQL query which may then be executed by the backend server. eTRAKiT 3.2.1.17 was tested, but other versions may also be vulnerable.

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-3qv8-hqcp-vhrh

The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.

CVSS3: 9.8
77%
Высокий
больше 3 лет назад
github логотип
GHSA-3qv8-4pm7-wp59

Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3qv8-368w-r69p

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3qv7-rvwv-j55x

SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3qv7-9m5q-pf8g

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import plugin settings.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3qv7-98vm-xx2v

MantisBT cross-site scripting (XSS) vulnerability through crafted PATH_INFO

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qv6-q4gp-2pm4

Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qv6-5f5f-f89j

User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qv5-8wgg-g4c6

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3qv5-55f8-3w6h

The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."

91%
Критический
больше 3 лет назад
github логотип
GHSA-3qv5-4cw7-x42h

The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an attacker to gain control by tricking a user into making a request.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу