Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-288v-v6p7-h593

больше 2 лет назад

A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215109 was assigned to this vulnerability.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-288r-cx7r-wfhc

больше 3 лет назад

PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.

EPSS: Низкий
github логотип

GHSA-288r-8c88-j3w5

около 1 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-288r-5qm5-qp55

больше 2 лет назад

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-288r-5pxq-4qgx

больше 3 лет назад

While processing the USB StrSerialDescriptor array, an array index out of bounds can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-288r-47q4-jvxj

около 2 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wow-Company Hover Effects allows SQL Injection. This issue affects Hover Effects: from n/a through 2.1.2.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-288p-75q5-6gj7

11 месяцев назад

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour configuration page in the web interface of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-288m-xm7h-p3xh

больше 3 лет назад

Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.

EPSS: Низкий
github логотип

GHSA-288h-hv2q-fwrv

около 3 лет назад

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. This may be used to corrupt nearby heap contents (leading to a query-of-death scenario) or may be used to bypass Envoy's access control mechanisms such as path based routing. An attacker can also modify requests from other users that happen to be proximal temporally and spatially.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-288h-h8hx-vvqm

больше 1 года назад

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-288h-f6gm-4vf9

больше 3 лет назад

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

EPSS: Средний
github логотип

GHSA-288h-4m8f-x8cf

больше 3 лет назад

Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-288f-gh2h-9j8q

больше 3 лет назад

Mumble: murmur-server has DoS due to malformed client query

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-288c-fr85-5qmw

больше 3 лет назад

The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authentication of users via a rogue access point and a man-in-the-middle attack.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-288c-cq4h-88gq

больше 4 лет назад

XML External Entity (XXE) Injection in Jackson Databind

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-288c-8vm9-x4gr

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

EPSS: Низкий
github логотип

GHSA-2889-44x2-9xg5

около 3 лет назад

, aka 'Windows Overlay Filter Security Feature Bypass Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2888-q29x-2g3p

больше 2 лет назад

A man in the middle can redirect traffic to a malicious server in a compromised configuration.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2888-p547-jrjr

2 месяца назад

Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bs_SetDNSInfo function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2888-gm7h-x2rw

10 месяцев назад

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-288v-v6p7-h593

A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215109 was assigned to this vulnerability.

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-288r-cx7r-wfhc

PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-288r-8c88-j3w5

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
около 1 года назад
github логотип
GHSA-288r-5qm5-qp55

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

CVSS3: 7.5
93%
Критический
больше 2 лет назад
github логотип
GHSA-288r-5pxq-4qgx

While processing the USB StrSerialDescriptor array, an array index out of bounds can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-288r-47q4-jvxj

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wow-Company Hover Effects allows SQL Injection. This issue affects Hover Effects: from n/a through 2.1.2.

CVSS3: 7.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-288p-75q5-6gj7

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing for an attacker to block access to the guard tour configuration page in the web interface of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-288m-xm7h-p3xh

Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-288h-hv2q-fwrv

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. This may be used to corrupt nearby heap contents (leading to a query-of-death scenario) or may be used to bypass Envoy's access control mechanisms such as path based routing. An attacker can also modify requests from other users that happen to be proximal temporally and spatially.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-288h-h8hx-vvqm

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-288h-f6gm-4vf9

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

37%
Средний
больше 3 лет назад
github логотип
GHSA-288h-4m8f-x8cf

Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-288f-gh2h-9j8q

Mumble: murmur-server has DoS due to malformed client query

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-288c-fr85-5qmw

The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authentication of users via a rogue access point and a man-in-the-middle attack.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-288c-cq4h-88gq

XML External Entity (XXE) Injection in Jackson Databind

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-288c-8vm9-x4gr

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-2889-44x2-9xg5

, aka 'Windows Overlay Filter Security Feature Bypass Vulnerability'.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2888-q29x-2g3p

A man in the middle can redirect traffic to a malicious server in a compromised configuration.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2888-p547-jrjr

Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bs_SetDNSInfo function.

CVSS3: 9.8
1%
Низкий
2 месяца назад
github логотип
GHSA-2888-gm7h-x2rw

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
10 месяцев назад

Уязвимостей на страницу