Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3vpq-g4qh-42g9

больше 3 лет назад

The time subsystem in the Linux kernel through 4.9.9, when CONFIG_TIMER_STATS is enabled, allows local users to discover real PID values (as distinguished from PID values inside a PID namespace) by reading the /proc/timer_list file, related to the print_timer function in kernel/time/timer_list.c and the __timer_stats_timer_set_start_info function in kernel/time/timer.c.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-3vpq-f54j-x6hq

больше 3 лет назад

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2811, CVE-2014-2822, and CVE-2014-4057.

EPSS: Средний
github логотип

GHSA-3vpp-f76r-qq84

почти 4 года назад

opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities

EPSS: Низкий
github логотип

GHSA-3vpm-m9q4-g8qr

8 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages allows Blind SQL Injection. This issue affects WP Lead Capturing Pages: from n/a through 2.3.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3vpm-jqjj-f248

почти 2 года назад

A vulnerability classified as critical has been found in Tenda AC15 15.03.20_multi. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand of the component Cookie Handler. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257670 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vpm-9mr8-4v6p

больше 3 лет назад

Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3vpj-864g-v5cv

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vpj-6vgf-55jc

почти 3 года назад

The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3vph-xq7p-prmq

больше 3 лет назад

A vulnerability classified as critical has been found in Itech Movie Portal Script 7.36. This affects an unknown part of the file /movie.php. The manipulation of the argument f leads to sql injection (Union). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vpg-qj28-69px

4 месяца назад

A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to unauthenticated Remote Code Execution

EPSS: Низкий
github логотип

GHSA-3vpg-mwgf-4jvj

почти 4 года назад

A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3vpg-38h3-gc36

почти 4 года назад

SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the bid parameter. NOTE: it was later reported that 1.0.13 is also affected.

EPSS: Низкий
github логотип

GHSA-3vpf-qr93-9634

7 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3vpf-mcj7-5h38

больше 2 лет назад

Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3vpf-jm66-7hfx

больше 3 лет назад

The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPadOS 13.4. A local user may be able to view deleted content in the app switcher.

EPSS: Низкий
github логотип

GHSA-3vpf-2pmh-fq33

больше 3 лет назад

The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vpc-63g5-hmgh

больше 3 лет назад

The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3vpc-4p9p-47hc

больше 1 года назад

curl_cffi bundles a version of libcurl affected by High Severity vulnerability

EPSS: Низкий
github логотип

GHSA-3vp9-jf7f-cv3c

почти 4 года назад

Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.

EPSS: Средний
github логотип

GHSA-3vp8-x92w-r8qp

больше 3 лет назад

A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts. The vulnerability is due to incorrect handling of incoming TCP SYN packets to specific listening ports. The improper handling of the TCP SYN packets could cause a system file description to be allocated and not freed. An attacker could exploit this vulnerability by sending a crafted stream of TCP SYN packets to the application. A successful exploit could allow the attacker to cause the application to eventually restart if a file description cannot be obtained.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vpq-g4qh-42g9

The time subsystem in the Linux kernel through 4.9.9, when CONFIG_TIMER_STATS is enabled, allows local users to discover real PID values (as distinguished from PID values inside a PID namespace) by reading the /proc/timer_list file, related to the print_timer function in kernel/time/timer_list.c and the __timer_stats_timer_set_start_info function in kernel/time/timer.c.

CVSS3: 4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vpq-f54j-x6hq

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2810, CVE-2014-2811, CVE-2014-2822, and CVE-2014-4057.

14%
Средний
больше 3 лет назад
github логотип
GHSA-3vpp-f76r-qq84

opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vpm-m9q4-g8qr

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages allows Blind SQL Injection. This issue affects WP Lead Capturing Pages: from n/a through 2.3.

CVSS3: 9.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3vpm-jqjj-f248

A vulnerability classified as critical has been found in Tenda AC15 15.03.20_multi. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand of the component Cookie Handler. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257670 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3vpm-9mr8-4v6p

Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vpj-864g-v5cv

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-3vpj-6vgf-55jc

The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3vph-xq7p-prmq

A vulnerability classified as critical has been found in Itech Movie Portal Script 7.36. This affects an unknown part of the file /movie.php. The manipulation of the argument f leads to sql injection (Union). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vpg-qj28-69px

A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to unauthenticated Remote Code Execution

1%
Низкий
4 месяца назад
github логотип
GHSA-3vpg-mwgf-4jvj

A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.

CVSS3: 3.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-3vpg-38h3-gc36

SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the bid parameter. NOTE: it was later reported that 1.0.13 is also affected.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3vpf-qr93-9634

Rejected reason: Not used

7 месяцев назад
github логотип
GHSA-3vpf-mcj7-5h38

Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3vpf-jm66-7hfx

The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPadOS 13.4. A local user may be able to view deleted content in the app switcher.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vpf-2pmh-fq33

The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vpc-63g5-hmgh

The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vpc-4p9p-47hc

curl_cffi bundles a version of libcurl affected by High Severity vulnerability

больше 1 года назад
github логотип
GHSA-3vp9-jf7f-cv3c

Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.

18%
Средний
почти 4 года назад
github логотип
GHSA-3vp8-x92w-r8qp

A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts. The vulnerability is due to incorrect handling of incoming TCP SYN packets to specific listening ports. The improper handling of the TCP SYN packets could cause a system file description to be allocated and not freed. An attacker could exploit this vulnerability by sending a crafted stream of TCP SYN packets to the application. A successful exploit could allow the attacker to cause the application to eventually restart if a file description cannot be obtained.

CVSS3: 8.6
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу