Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3v49-j6p7-86pc

больше 3 лет назад

An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3v49-f236-jv89

больше 3 лет назад

The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v49-5224-w9p6

почти 4 года назад

Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.

EPSS: Низкий
github логотип

GHSA-3v49-294p-4c7w

почти 2 года назад

The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the admin panel. Also vulnerable to account takeover and arbitrary password change.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v48-283x-f2w4

7 месяцев назад

File Browser's password protection of links is bypassable

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3v46-43qj-3vpg

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3v45-w9r6-863p

больше 3 лет назад

SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v44-m29v-5rc5

больше 3 лет назад

Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.

EPSS: Низкий
github логотип

GHSA-3v44-382q-55f4

около 7 лет назад

Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v44-23hf-q5wp

около 1 года назад

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3v43-hgv9-g7jj

почти 2 года назад

A vulnerability classified as critical was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function fromqossetting of the file /goform/fromqossetting. The manipulation of the argument qos leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260911. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v43-8vv8-27j2

больше 2 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeFlavors Vimeotheque: Vimeo WordPress Plugin <= 2.2.1 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3v43-877x-qgmq

больше 6 лет назад

Moderate severity vulnerability that affects league/commonmark

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3v42-qjhq-4fjh

больше 3 лет назад

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3135 and CVE-2015-4432.

EPSS: Средний
github логотип

GHSA-3v3x-mvj6-m5jc

11 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v3x-cm3g-974v

почти 4 года назад

** DISPUTED ** Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue.

EPSS: Низкий
github логотип

GHSA-3v3q-fq2w-23r5

4 месяца назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions to make critical changes to local Morpho devices. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831 (MR8), all versions of 8.90 and prior.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3v3p-g3ch-4rcq

около 2 лет назад

An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3v3p-5qg2-fr76

почти 4 года назад

The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

EPSS: Низкий
github логотип

GHSA-3v3m-cp4r-m942

больше 3 лет назад

Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v49-j6p7-86pc

An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v49-f236-jv89

The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v49-5224-w9p6

Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.

7%
Низкий
почти 4 года назад
github логотип
GHSA-3v49-294p-4c7w

The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the admin panel. Also vulnerable to account takeover and arbitrary password change.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3v48-283x-f2w4

File Browser's password protection of links is bypassable

CVSS3: 3.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-3v46-43qj-3vpg

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3v45-w9r6-863p

SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3v44-m29v-5rc5

Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v44-382q-55f4

Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main

CVSS3: 6.5
0%
Низкий
около 7 лет назад
github логотип
GHSA-3v44-23hf-q5wp

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3v43-hgv9-g7jj

A vulnerability classified as critical was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function fromqossetting of the file /goform/fromqossetting. The manipulation of the argument qos leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260911. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3v43-8vv8-27j2

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeFlavors Vimeotheque: Vimeo WordPress Plugin <= 2.2.1 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3v43-877x-qgmq

Moderate severity vulnerability that affects league/commonmark

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
github логотип
GHSA-3v42-qjhq-4fjh

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3135 and CVE-2015-4432.

63%
Средний
больше 3 лет назад
github логотип
GHSA-3v3x-mvj6-m5jc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported.

CVSS3: 9.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-3v3x-cm3g-974v

** DISPUTED ** Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3v3q-fq2w-23r5

Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions to make critical changes to local Morpho devices. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831 (MR8), all versions of 8.90 and prior.

CVSS3: 9.9
0%
Низкий
4 месяца назад
github логотип
GHSA-3v3p-g3ch-4rcq

An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3v3p-5qg2-fr76

The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3v3m-cp4r-m942

Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу