Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-283m-g47h-4xp3

около 3 лет назад

OpenEMR v5.0.1-6 allows code execution.

EPSS: Низкий
github логотип

GHSA-283j-g8hx-4wgv

больше 3 лет назад

Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to (1) admin_modules.php and (2) modules.php.

EPSS: Низкий
github логотип

GHSA-283j-fp4h-g37g

больше 3 лет назад

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-283j-88x2-fqpr

больше 3 лет назад

Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) login.php or (b) fpass.php; or (2) cid parameter to (c) visview.php.

EPSS: Низкий
github логотип

GHSA-283h-wqwv-526q

около 3 лет назад

Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.

EPSS: Средний
github логотип

GHSA-283h-3w9j-26xq

больше 1 года назад

IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-283g-w9m2-fg76

больше 3 лет назад

Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.

EPSS: Низкий
github логотип

GHSA-283g-59hf-7q7h

больше 3 лет назад

The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a locale_get_display_name call with a long first argument.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-283f-f867-hhph

больше 3 лет назад

Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-283c-79hh-mfp9

около 1 года назад

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-283c-4h8h-4xmp

больше 3 лет назад

The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of memory, related to the program reference count or (2) a 1 Tb system, related to the map reference count.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-283c-28ph-cjjp

около 3 лет назад

A vulnerability classified as critical has been found in Kama Click Counter Plugin up to 3.4.8. This affects an unknown part of the file wp-admin/admin.php. The manipulation of the argument order_by/order with the input ASC%2c(select*from(select(sleep(2)))a) leads to sql injection (Blind). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.4.9 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2839-3chr-4f33

больше 3 лет назад

Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2838-j456-r5r4

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP allows Reflected XSS. This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a through 2.0.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2838-84rj-32xc

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free during router port configuration The bridge maintains a global list of ports behind which a multicast router resides. The list is consulted during forwarding to ensure multicast packets are forwarded to these ports even if the ports are not member in the matching MDB entry. When per-VLAN multicast snooping is enabled, the per-port multicast context is disabled on each port and the port is removed from the global router port list: # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1 # ip link add name dummy1 up master br1 type dummy # ip link set dev dummy1 type bridge_slave mcast_router 2 $ bridge -d mdb show | grep router router ports on br1: dummy1 # ip link set dev br1 type bridge mcast_vlan_snooping 1 $ bridge -d mdb show | grep router However, the port can be re-added to the global list even when per-VLAN multicast snooping is enabled: # ip link...

EPSS: Низкий
github логотип

GHSA-2837-wh3m-xwh8

больше 3 лет назад

The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2837-v82c-6wx6

больше 3 лет назад

ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadOneJNGImage in coders\png.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2837-v5j7-qwmh

около 3 лет назад

Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business Security versions prior to 6.6.23.329.

EPSS: Низкий
github логотип

GHSA-2837-pj7h-9v2g

больше 3 лет назад

Huawei eSpace 7910 and 7950 IP phones with software before V200R002C00SPC800 allow remote attackers with established sessions to cause a denial of service (device restart) via unspecified packets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2837-43wm-47x9

около 2 лет назад

Windows Hello Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-283m-g47h-4xp3

OpenEMR v5.0.1-6 allows code execution.

1%
Низкий
около 3 лет назад
github логотип
GHSA-283j-g8hx-4wgv

Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to (1) admin_modules.php and (2) modules.php.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-283j-fp4h-g37g

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.

CVSS3: 5.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-283j-88x2-fqpr

Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) login.php or (b) fpass.php; or (2) cid parameter to (c) visview.php.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-283h-wqwv-526q

Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.

18%
Средний
около 3 лет назад
github логотип
GHSA-283h-3w9j-26xq

IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-283g-w9m2-fg76

Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-283g-59hf-7q7h

The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a locale_get_display_name call with a long first argument.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-283f-f867-hhph

Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-283c-79hh-mfp9

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-283c-4h8h-4xmp

The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of memory, related to the program reference count or (2) a 1 Tb system, related to the map reference count.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-283c-28ph-cjjp

A vulnerability classified as critical has been found in Kama Click Counter Plugin up to 3.4.8. This affects an unknown part of the file wp-admin/admin.php. The manipulation of the argument order_by/order with the input ASC%2c(select*from(select(sleep(2)))a) leads to sql injection (Blind). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.4.9 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2839-3chr-4f33

Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2838-j456-r5r4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP allows Reflected XSS. This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a through 2.0.6.

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-2838-84rj-32xc

In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free during router port configuration The bridge maintains a global list of ports behind which a multicast router resides. The list is consulted during forwarding to ensure multicast packets are forwarded to these ports even if the ports are not member in the matching MDB entry. When per-VLAN multicast snooping is enabled, the per-port multicast context is disabled on each port and the port is removed from the global router port list: # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1 # ip link add name dummy1 up master br1 type dummy # ip link set dev dummy1 type bridge_slave mcast_router 2 $ bridge -d mdb show | grep router router ports on br1: dummy1 # ip link set dev br1 type bridge mcast_vlan_snooping 1 $ bridge -d mdb show | grep router However, the port can be re-added to the global list even when per-VLAN multicast snooping is enabled: # ip link...

0%
Низкий
около 1 месяца назад
github логотип
GHSA-2837-wh3m-xwh8

The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2837-v82c-6wx6

ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadOneJNGImage in coders\png.c.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2837-v5j7-qwmh

Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business Security versions prior to 6.6.23.329.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2837-pj7h-9v2g

Huawei eSpace 7910 and 7950 IP phones with software before V200R002C00SPC800 allow remote attackers with established sessions to cause a denial of service (device restart) via unspecified packets.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2837-43wm-47x9

Windows Hello Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
около 2 лет назад

Уязвимостей на страницу