Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-28p7-f6h6-3jh3

9 месяцев назад

LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.php

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28p6-384f-vhg4

больше 3 лет назад

Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.

EPSS: Средний
github логотип

GHSA-28p5-7rg4-8v99

около 3 лет назад

Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )

EPSS: Низкий
github логотип

GHSA-28p3-mchr-9frj

больше 3 лет назад

Deserialization of Untrusted Data in Jenkins

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28p3-2x22-g64c

почти 3 года назад

In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07129717; Issue ID: ALPS07129717.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-28p2-p7pc-m535

около 3 лет назад

The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token.

EPSS: Низкий
github логотип

GHSA-28mr-3phc-39gr

больше 3 лет назад

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8345.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-28mq-w7hj-99g5

около 3 лет назад

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor

EPSS: Низкий
github логотип

GHSA-28mp-g2wm-23p3

около 2 лет назад

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-28mp-cx45-6mwq

больше 3 лет назад

The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28mp-cr2q-8xfm

около 2 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.6 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-28mp-5jqq-gwr6

около 3 лет назад

An elevation of privilege vulnerability exists when the &quot;Public Account Pictures&quot; folder improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28mm-x5hc-96xm

3 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-28mm-m2px-wcjp

больше 3 лет назад

Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, CVE-2014-4299, CVE-2014-6452, CVE-2014-6454, and CVE-2014-6542.

EPSS: Низкий
github логотип

GHSA-28mm-f6x9-rjqf

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6) Version, or (7) Home page variables.

EPSS: Низкий
github логотип

GHSA-28mj-w386-78gm

больше 3 лет назад

Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, and 5.0 SP1a-b allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web.

EPSS: Низкий
github логотип

GHSA-28mj-q95m-9rc8

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakir Hasan Blocks Post Grid allows DOM-Based XSS.This issue affects Blocks Post Grid: from n/a through 1.0.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28mj-jg9q-pj9c

больше 3 лет назад

Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."

EPSS: Средний
github логотип

GHSA-28mj-h58q-vmmm

около 3 лет назад

The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28mj-2qc3-mqch

больше 3 лет назад

Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28p7-f6h6-3jh3

LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.php

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-28p6-384f-vhg4

Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.

53%
Средний
больше 3 лет назад
github логотип
GHSA-28p5-7rg4-8v99

Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )

около 3 лет назад
github логотип
GHSA-28p3-mchr-9frj

Deserialization of Untrusted Data in Jenkins

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28p3-2x22-g64c

In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07129717; Issue ID: ALPS07129717.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-28p2-p7pc-m535

The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token.

1%
Низкий
около 3 лет назад
github логотип
GHSA-28mr-3phc-39gr

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8345.

CVSS3: 8.8
30%
Средний
больше 3 лет назад
github логотип
GHSA-28mq-w7hj-99g5

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor

1%
Низкий
около 3 лет назад
github логотип
GHSA-28mp-g2wm-23p3

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

CVSS3: 6
0%
Низкий
около 2 лет назад
github логотип
GHSA-28mp-cx45-6mwq

The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28mp-cr2q-8xfm

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.6 versions.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-28mp-5jqq-gwr6

An elevation of privilege vulnerability exists when the &quot;Public Account Pictures&quot; folder improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'.

CVSS3: 7.5
3%
Низкий
около 3 лет назад
github логотип
GHSA-28mm-x5hc-96xm

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

3 месяца назад
github логотип
GHSA-28mm-m2px-wcjp

Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, CVE-2014-4299, CVE-2014-6452, CVE-2014-6454, and CVE-2014-6542.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28mm-f6x9-rjqf

Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6) Version, or (7) Home page variables.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28mj-w386-78gm

Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, and 5.0 SP1a-b allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28mj-q95m-9rc8

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakir Hasan Blocks Post Grid allows DOM-Based XSS.This issue affects Blocks Post Grid: from n/a through 1.0.3.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-28mj-jg9q-pj9c

Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."

15%
Средний
больше 3 лет назад
github логотип
GHSA-28mj-h58q-vmmm

The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-28mj-2qc3-mqch

Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу