Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3vr6-r8gf-6wr6

около 3 лет назад

The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the unfiltered_html capability is disabled.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3vr6-cm7r-pmpq

почти 4 года назад

Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.

EPSS: Низкий
github логотип

GHSA-3vr5-m2vg-9vqj

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for Beaver Builder allows Stored XSS.This issue affects Livemesh Addons for Beaver Builder: from n/a through 3.6.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3vr5-764g-c3pw

8 месяцев назад

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3vr4-gx8q-4fgg

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: net: use dst_dev_rcu() in sk_setup_caps() Use RCU to protect accesses to dst->dev from sk_setup_caps() and sk_dst_gso_max_size(). Also use dst_dev_rcu() in ip6_dst_mtu_maybe_forward(), and ip_dst_mtu_maybe_forward(). ip4_dst_hoplimit() can use dst_dev_net_rcu().

EPSS: Низкий
github логотип

GHSA-3vr3-r7x9-49w7

больше 3 лет назад

Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-3vr3-fvrq-86x3

почти 4 года назад

XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.

EPSS: Низкий
github логотип

GHSA-3vr3-73ff-f37h

больше 3 лет назад

Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long data_select1 parameter.

EPSS: Средний
github логотип

GHSA-3vr2-w427-fcqp

9 месяцев назад

Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging the service to delete a directory

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vr2-225w-q57h

7 месяцев назад

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3vqx-m245-hc3c

больше 2 лет назад

SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vqx-f82r-h7jr

больше 3 лет назад

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.

EPSS: Средний
github логотип

GHSA-3vqv-q4j4-7vcj

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3vqv-29vx-vmgh

почти 4 года назад

SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.

EPSS: Низкий
github логотип

GHSA-3vqr-5r5v-rhm8

почти 2 года назад

Secure Boot Security Feature Bypass Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vqr-47f5-c2xr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in RSA Adaptive Authentication 2.x and 5.7.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3vqq-mcf6-8w3j

больше 3 лет назад

PHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vqq-m58h-g5f5

больше 3 лет назад

Windows Installer Spoofing Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3vqq-6vgg-h45h

больше 2 лет назад

It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vqq-45qg-2xf6

12 дней назад

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private ke...

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vr6-r8gf-6wr6

The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the unfiltered_html capability is disabled.

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3vr6-cm7r-pmpq

Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vr5-m2vg-9vqj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for Beaver Builder allows Stored XSS.This issue affects Livemesh Addons for Beaver Builder: from n/a through 3.6.1.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-3vr5-764g-c3pw

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.

CVSS3: 4.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-3vr4-gx8q-4fgg

In the Linux kernel, the following vulnerability has been resolved: net: use dst_dev_rcu() in sk_setup_caps() Use RCU to protect accesses to dst->dev from sk_setup_caps() and sk_dst_gso_max_size(). Also use dst_dev_rcu() in ip6_dst_mtu_maybe_forward(), and ip_dst_mtu_maybe_forward(). ip4_dst_hoplimit() can use dst_dev_net_rcu().

0%
Низкий
3 месяца назад
github логотип
GHSA-3vr3-r7x9-49w7

Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vr3-fvrq-86x3

XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3vr3-73ff-f37h

Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long data_select1 parameter.

49%
Средний
больше 3 лет назад
github логотип
GHSA-3vr2-w427-fcqp

Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging the service to delete a directory

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-3vr2-225w-q57h

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3vqx-m245-hc3c

SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3vqx-f82r-h7jr

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.

26%
Средний
больше 3 лет назад
github логотип
GHSA-3vqv-q4j4-7vcj

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3vqv-29vx-vmgh

SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vqr-5r5v-rhm8

Secure Boot Security Feature Bypass Vulnerability

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3vqr-47f5-c2xr

Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in RSA Adaptive Authentication 2.x and 5.7.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vqq-mcf6-8w3j

PHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vqq-m58h-g5f5

Windows Installer Spoofing Vulnerability

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vqq-6vgg-h45h

It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3vqq-45qg-2xf6

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private ke...

CVSS3: 5.5
0%
Низкий
12 дней назад

Уязвимостей на страницу