Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3vf5-xm2p-6mh5

больше 2 лет назад

Cockpit Cross-site Scripting vulnerability

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3vf5-m872-p593

больше 3 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 810, SD 820, and SD 820A, a buffer overflow can occur in SafeSwitch.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vf5-967m-jfcw

12 месяцев назад

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3vf4-qf7v-8hwx

больше 1 года назад

Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-3vf4-p6xq-xxr9

больше 3 лет назад

The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error.

EPSS: Низкий
github логотип

GHSA-3vf4-6xfg-p852

больше 3 лет назад

cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3vf4-2h3f-crc2

больше 3 лет назад

IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3vf3-j8cr-x4g6

больше 1 года назад

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVSS3: 6.5
EPSS: Высокий
github логотип

GHSA-3vf3-8x3v-cfhr

почти 2 года назад

In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3vf2-rf9c-6455

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5.1.2 through 5.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3vf2-r6qr-hcf2

больше 3 лет назад

Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3vf2-6fxh-3q3m

больше 3 лет назад

WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability."

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3vcx-x6r7-phpm

почти 4 года назад

SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

EPSS: Низкий
github логотип

GHSA-3vcx-wp2w-x68x

2 месяца назад

Missing Authorization vulnerability in Yandex Metrika Yandex.Metrica wp-yandex-metrika allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yandex.Metrica: from n/a through <= 1.2.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vcx-w94h-68vg

больше 3 лет назад

XXE vulnerability in Jenkins Android Lint Plugin

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3vcx-qq88-36qg

больше 3 лет назад

The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3vcw-xhqc-97mh

больше 3 лет назад

Medtronic 2090 CareLink Programmer all versions The affected product uses a virtual private network connection to securely download updates. The product does not verify it is still connected to this virtual private network before downloading updates. An attacker with local network access to the programmer could influence these communications.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3vcw-92x2-jjg4

больше 3 лет назад

A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. An attacker could exploit this vulnerability by authenticating to the device with administrative privileges and issuing a CLI command with crafted user parameters. A successful exploit could allow the attacker to overwrite or append arbitrary data to system files using root-level privileges.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3vcv-r276-ff59

около 2 лет назад

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3vcv-qvpj-9v53

почти 2 года назад

SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add Users.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vf5-xm2p-6mh5

Cockpit Cross-site Scripting vulnerability

CVSS3: 8.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3vf5-m872-p593

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 810, SD 820, and SD 820A, a buffer overflow can occur in SafeSwitch.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vf5-967m-jfcw

A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.

CVSS3: 9.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-3vf4-qf7v-8hwx

Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3vf4-p6xq-xxr9

The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vf4-6xfg-p852

cPanel before 60.0.25 allows self XSS in the alias upload interface (SEC-184).

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vf4-2h3f-crc2

IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vf3-j8cr-x4g6

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVSS3: 6.5
79%
Высокий
больше 1 года назад
github логотип
GHSA-3vf3-8x3v-cfhr

In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3vf2-rf9c-6455

Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5.1.2 through 5.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vf2-r6qr-hcf2

Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vf2-6fxh-3q3m

WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability."

CVSS3: 7.5
24%
Средний
больше 3 лет назад
github логотип
GHSA-3vcx-x6r7-phpm

SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3vcx-wp2w-x68x

Missing Authorization vulnerability in Yandex Metrika Yandex.Metrica wp-yandex-metrika allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yandex.Metrica: from n/a through <= 1.2.2.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3vcx-w94h-68vg

XXE vulnerability in Jenkins Android Lint Plugin

CVSS3: 8.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vcx-qq88-36qg

The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vcw-xhqc-97mh

Medtronic 2090 CareLink Programmer all versions The affected product uses a virtual private network connection to securely download updates. The product does not verify it is still connected to this virtual private network before downloading updates. An attacker with local network access to the programmer could influence these communications.

CVSS3: 8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vcw-92x2-jjg4

A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete validation of user input for a specific CLI command. An attacker could exploit this vulnerability by authenticating to the device with administrative privileges and issuing a CLI command with crafted user parameters. A successful exploit could allow the attacker to overwrite or append arbitrary data to system files using root-level privileges.

CVSS3: 6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vcv-r276-ff59

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3vcv-qvpj-9v53

SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add Users.

CVSS3: 5.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу