Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3qmf-fj65-6vmf

около 2 лет назад

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qmf-6344-4f7m

больше 3 лет назад

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).

EPSS: Низкий
github логотип

GHSA-3qmc-vv7g-wccj

больше 2 лет назад

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3qmc-2r76-4rqp

около 3 лет назад

Redwood is vulnerable to account takeover via dbAuth "forgot-password"

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3qm9-v325-gx6g

около 4 лет назад

OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.

EPSS: Низкий
github логотип

GHSA-3qm9-8m3h-5r34

больше 3 лет назад

In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: Android. Versions: Android kernel. Android ID: A-139354541

EPSS: Низкий
github логотип

GHSA-3qm9-52c7-2c7g

больше 3 лет назад

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qm7-r4x4-c73f

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Morris Bryant, Ruben Sargsyan Outbound Link Manager plugin <= 1.2 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qm7-c6pm-5769

8 месяцев назад

Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qm7-9jrc-h4gp

больше 3 лет назад

Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.

EPSS: Низкий
github логотип

GHSA-3qm6-wcp5-fx9f

около 1 года назад

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3qm5-69j8-vpx9

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Luis Rock Master Bar allows Reflected XSS.This issue affects Master Bar: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3qm4-fxpg-422m

больше 3 лет назад

Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier, Yayoi Aoiro Shinkoku 17 Ver.23.1.1 and earlier, Yayoi Kyuuyo 17 Ver.20.1.4 and earlier, Yayoi Kyuuyo Keisan 17 Ver.20.1.4 and earlier, Yayoi Hanbai 17 Series Ver. 20.0.2 and earlier, and Yayoi Kokyaku Kanri 17 Ver.11.0.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. This flaw exists within the handling of msjet49.dll loaded by the vulnerable products.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qm4-fcww-95qr

больше 3 лет назад

The RADIUS parser in tcpdump before 4.9.2 has a buffer over-read in print-radius.c:print_attr_string().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qm4-89p4-vrg6

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a direct request to secure/ConfigureReleaseNote.jspa, which are not sanitized before being returned in an error page.

EPSS: Низкий
github логотип

GHSA-3qm4-437h-r2px

7 месяцев назад

An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.

EPSS: Низкий
github логотип

GHSA-3qm2-rfqw-fmrw

больше 3 лет назад

move_elements can double-free objects on panic

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qm2-9p8h-pxf4

больше 3 лет назад

A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3qm2-4r9g-fg69

5 месяцев назад

A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3qjx-hh6f-4fvq

больше 3 лет назад

Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qmf-fj65-6vmf

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.

CVSS3: 4.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-3qmf-6344-4f7m

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qmc-vv7g-wccj

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qmc-2r76-4rqp

Redwood is vulnerable to account takeover via dbAuth "forgot-password"

CVSS3: 8.2
около 3 лет назад
github логотип
GHSA-3qm9-v325-gx6g

OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3qm9-8m3h-5r34

In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: Android. Versions: Android kernel. Android ID: A-139354541

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qm9-52c7-2c7g

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspecified vectors.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qm7-r4x4-c73f

Cross-Site Request Forgery (CSRF) vulnerability in Morris Bryant, Ruben Sargsyan Outbound Link Manager plugin <= 1.2 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qm7-c6pm-5769

Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3qm7-9jrc-h4gp

Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qm6-wcp5-fx9f

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.

CVSS3: 7.2
0%
Низкий
около 1 года назад
github логотип
GHSA-3qm5-69j8-vpx9

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Luis Rock Master Bar allows Reflected XSS.This issue affects Master Bar: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3qm4-fxpg-422m

Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier, Yayoi Aoiro Shinkoku 17 Ver.23.1.1 and earlier, Yayoi Kyuuyo 17 Ver.20.1.4 and earlier, Yayoi Kyuuyo Keisan 17 Ver.20.1.4 and earlier, Yayoi Hanbai 17 Series Ver. 20.0.2 and earlier, and Yayoi Kokyaku Kanri 17 Ver.11.0.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. This flaw exists within the handling of msjet49.dll loaded by the vulnerable products.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qm4-fcww-95qr

The RADIUS parser in tcpdump before 4.9.2 has a buffer over-read in print-radius.c:print_attr_string().

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qm4-89p4-vrg6

Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a direct request to secure/ConfigureReleaseNote.jspa, which are not sanitized before being returned in an error page.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3qm4-437h-r2px

An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.

0%
Низкий
7 месяцев назад
github логотип
GHSA-3qm2-rfqw-fmrw

move_elements can double-free objects on panic

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qm2-9p8h-pxf4

A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

CVSS3: 9.8
13%
Средний
больше 3 лет назад
github логотип
GHSA-3qm2-4r9g-fg69

A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3qjx-hh6f-4fvq

Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу