Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3q27-5m93-xfm4

около 1 года назад

Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.  A malicious user with network access may be able to use specially crafted SQL queries to gain database access.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3q26-rw63-5772

больше 1 года назад

There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3q26-f695-pp76

7 месяцев назад

@cyanheads/git-mcp-server vulnerable to command injection in several tools

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q25-m4x5-9jh7

больше 3 лет назад

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

EPSS: Низкий
github логотип

GHSA-3q24-wf35-56h6

около 1 года назад

IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3q24-rrgq-j66h

почти 3 года назад

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3q23-2j2r-mmw3

около 1 года назад

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3q22-68gw-x3mq

4 месяца назад

IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3pxx-76hx-4rw2

почти 4 года назад

Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.

EPSS: Низкий
github логотип

GHSA-3pxv-j5r5-v5qh

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propagation mount tree headed by @dest_mnt. Unfortunately it contains a bug where it fails to terminate at peers of @source_mnt when looking up copies of the source mount that become masters for copies of the source mount tree mounted on top of slaves in the destination propagation tree causing a NULL dereference. Once the mechanics of the bug are understood it's easy to trigger. Because of unprivileged user namespaces it is available to unprivileged users. While fixing this bug we've gotten confused multiple times due to unclear terminology or missing concepts. So let's start this with some clarifications: * The terms "master" or "peer" denote a shared mount. A shared mount belongs to a peer group. * A pee...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3pxr-vgjw-q3f8

больше 3 лет назад

Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

EPSS: Низкий
github логотип

GHSA-3pxr-3j7f-c35j

больше 1 года назад

Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3pxq-xg4j-rgqx

10 месяцев назад

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pxq-5cc9-p3hw

почти 4 года назад

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.

EPSS: Низкий
github логотип

GHSA-3pxq-4mq2-m2mc

больше 3 лет назад

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.

EPSS: Низкий
github логотип

GHSA-3pxp-pwrp-2w6f

почти 4 года назад

Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.

EPSS: Низкий
github логотип

GHSA-3pxp-6963-46r9

больше 7 лет назад

Command Injection in pdfinfojs

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pxp-67jr-6qw6

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.

EPSS: Низкий
github логотип

GHSA-3pxp-4jgv-xr88

почти 4 года назад

Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method.

EPSS: Низкий
github логотип

GHSA-3pxm-vvrr-xp9x

почти 4 года назад

Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q27-5m93-xfm4

Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.  A malicious user with network access may be able to use specially crafted SQL queries to gain database access.

CVSS3: 8.6
0%
Низкий
около 1 года назад
github логотип
GHSA-3q26-rw63-5772

There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-3q26-f695-pp76

@cyanheads/git-mcp-server vulnerable to command injection in several tools

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-3q25-m4x5-9jh7

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3q24-wf35-56h6

IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service.

CVSS3: 6
0%
Низкий
около 1 года назад
github логотип
GHSA-3q24-rrgq-j66h

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

CVSS3: 5.4
6%
Низкий
почти 3 года назад
github логотип
GHSA-3q23-2j2r-mmw3

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

CVSS3: 8.8
18%
Средний
около 1 года назад
github логотип
GHSA-3q22-68gw-x3mq

IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

CVSS3: 5.9
0%
Низкий
4 месяца назад
github логотип
GHSA-3pxx-76hx-4rw2

Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3pxv-j5r5-v5qh

In the Linux kernel, the following vulnerability has been resolved: pnode: terminate at peers of source The propagate_mnt() function handles mount propagation when creating mounts and propagates the source mount tree @source_mnt to all applicable nodes of the destination propagation mount tree headed by @dest_mnt. Unfortunately it contains a bug where it fails to terminate at peers of @source_mnt when looking up copies of the source mount that become masters for copies of the source mount tree mounted on top of slaves in the destination propagation tree causing a NULL dereference. Once the mechanics of the bug are understood it's easy to trigger. Because of unprivileged user namespaces it is available to unprivileged users. While fixing this bug we've gotten confused multiple times due to unclear terminology or missing concepts. So let's start this with some clarifications: * The terms "master" or "peer" denote a shared mount. A shared mount belongs to a peer group. * A pee...

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3pxr-vgjw-q3f8

Out of bound memory access in camera driver due to improper validation on data coming from UMD which is used for offset manipulation of pointer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pxr-3j7f-c35j

Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pxq-xg4j-rgqx

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

CVSS3: 9.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-3pxq-5cc9-p3hw

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3pxq-4mq2-m2mc

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3pxp-pwrp-2w6f

Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3pxp-6963-46r9

Command Injection in pdfinfojs

CVSS3: 9.8
2%
Низкий
больше 7 лет назад
github логотип
GHSA-3pxp-67jr-6qw6

Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3pxp-4jgv-xr88

Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3pxm-vvrr-xp9x

Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу