Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-28qj-36f6-4995

больше 3 лет назад

JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28qh-hp2x-hp83

около 1 года назад

Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23173.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-28qh-gf6m-p898

5 дней назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks allows PHP Local File Inclusion. This issue affects Gutenberg Blocks: from n/a through 3.3.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28qh-fm59-ff8g

больше 3 лет назад

The HTTP server in Linksys SPA-921 VoIP Desktop Phone allows remote attackers to cause a denial of service (reboot) via (1) a long URL, or a long (2) username or (3) password during Basic Authentication.

EPSS: Низкий
github логотип

GHSA-28qf-h8m9-4x6x

5 месяцев назад

Luxion KeyShot USDC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of usdc files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23709.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28qc-xv4f-hpq9

больше 3 лет назад

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.

EPSS: Средний
github логотип

GHSA-28qc-v7xx-3vpf

больше 1 года назад

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28qc-jxm4-f2f8

больше 3 лет назад

Directory traversal vulnerability in Cybozu Dezie 8.0.2 to 8.1.2 allows remote attackers to read arbitrary files via HTTP requests.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-28q9-rp4x-j7g7

больше 3 лет назад

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-28q9-9cw2-qq2c

больше 3 лет назад

The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a denial of service via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-28q9-9c3g-v3f9

почти 3 года назад

lakeFS vulnerable to authenticated users deleting files they are not authorized to delete

EPSS: Низкий
github логотип

GHSA-28q8-f96p-q62j

9 месяцев назад

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-28q8-3hq4-6hmv

больше 3 лет назад

Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 Gold through SP6 allows remote authenticated users to gain privileges via unknown vectors.

EPSS: Низкий
github логотип

GHSA-28q7-ffc5-gfjp

больше 1 года назад

Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-28q6-w24q-3hph

около 1 года назад

Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-28q6-prfq-9g82

около 3 лет назад

Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

EPSS: Низкий
github логотип

GHSA-28q6-f58p-4jf2

около 3 лет назад

Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.

EPSS: Низкий
github логотип

GHSA-28q6-2p45-6wjp

больше 3 лет назад

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

EPSS: Низкий
github логотип

GHSA-28q5-v2r3-qj3r

около 2 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows SQL Injection. This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through 2.4.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-28q5-692w-348q

больше 3 лет назад

The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicious Intent URI, in order to invoke private Activities within the Dolphin Browser.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28qj-36f6-4995

JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28qh-hp2x-hp83

Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23173.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-28qh-gf6m-p898

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks allows PHP Local File Inclusion. This issue affects Gutenberg Blocks: from n/a through 3.3.1.

CVSS3: 7.5
0%
Низкий
5 дней назад
github логотип
GHSA-28qh-fm59-ff8g

The HTTP server in Linksys SPA-921 VoIP Desktop Phone allows remote attackers to cause a denial of service (reboot) via (1) a long URL, or a long (2) username or (3) password during Basic Authentication.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-28qf-h8m9-4x6x

Luxion KeyShot USDC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of usdc files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23709.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-28qc-xv4f-hpq9

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.

24%
Средний
больше 3 лет назад
github логотип
GHSA-28qc-v7xx-3vpf

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-28qc-jxm4-f2f8

Directory traversal vulnerability in Cybozu Dezie 8.0.2 to 8.1.2 allows remote attackers to read arbitrary files via HTTP requests.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28q9-rp4x-j7g7

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.

CVSS3: 9.8
36%
Средний
больше 3 лет назад
github логотип
GHSA-28q9-9cw2-qq2c

The debugging feature in the kernel in Apple OS X before 10.11 mismanages state, which allows local users to cause a denial of service via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28q9-9c3g-v3f9

lakeFS vulnerable to authenticated users deleting files they are not authorized to delete

почти 3 года назад
github логотип
GHSA-28q8-f96p-q62j

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-28q8-3hq4-6hmv

Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 Gold through SP6 allows remote authenticated users to gain privileges via unknown vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28q7-ffc5-gfjp

Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

CVSS3: 5.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-28q6-w24q-3hph

Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.

CVSS3: 9.1
0%
Низкий
около 1 года назад
github логотип
GHSA-28q6-prfq-9g82

Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

0%
Низкий
около 3 лет назад
github логотип
GHSA-28q6-f58p-4jf2

Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.

0%
Низкий
около 3 лет назад
github логотип
GHSA-28q6-2p45-6wjp

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

3%
Низкий
больше 3 лет назад
github логотип
GHSA-28q5-v2r3-qj3r

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows SQL Injection. This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through 2.4.0.

CVSS3: 8.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-28q5-692w-348q

The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicious Intent URI, in order to invoke private Activities within the Dolphin Browser.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу