Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3rx5-2rm5-fvhx

больше 3 лет назад

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3rx2-x6mx-grj3

больше 6 лет назад

Cross-site scripting in Apache JSPWiki

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3rwx-rphm-m3g7

больше 3 лет назад

In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173473906

EPSS: Низкий
github логотип

GHSA-3rwx-3vwh-mwxc

больше 3 лет назад

Jenkins Vulnerable to Denial of Service (DoS)

EPSS: Низкий
github логотип

GHSA-3rww-fm75-jc23

8 месяцев назад

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3rww-7g94-g9qj

больше 3 лет назад

Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the string_repeat() function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rwv-jrrg-99x3

почти 2 года назад

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the server running out of resources.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rwv-g3jc-r7cc

больше 3 лет назад

An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https://github.com/google/asylo/commit/a47ef55db2337d29de19c50cd29b0deb2871d31c

EPSS: Низкий
github логотип

GHSA-3rwr-fq47-78qj

10 месяцев назад

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/v1/link/edit. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3rwq-vmr7-cggq

почти 2 года назад

Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rwq-pxmh-pw55

около 2 лет назад

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3rwq-2648-vg59

почти 3 года назад

Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rwp-9p3r-82c4

около 2 лет назад

Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3rwm-jg87-jp7c

больше 3 лет назад

An out-of-bound write can be triggered by a specially-crafted command supplied by a userspace application. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6574AU, QCA8081, QCA9377, QCA9379, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM660, SDX20, SDX24

EPSS: Низкий
github логотип

GHSA-3rwj-vm9j-wg4r

больше 3 лет назад

IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152735.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rwj-v7jp-w542

больше 3 лет назад

Pagekit Stored Cross-site Scripting

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3rwj-9q84-fmqw

10 месяцев назад

A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.

EPSS: Низкий
github логотип

GHSA-3rwj-253m-qrvm

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc_submit: fix race around suspend_pending Currently in some testcases we can trigger: xe 0000:03:00.0: [drm] Assertion `exec_queue_destroyed(q)` failed! .... WARNING: CPU: 18 PID: 2640 at drivers/gpu/drm/xe/xe_guc_submit.c:1826 xe_guc_sched_done_handler+0xa54/0xef0 [xe] xe 0000:03:00.0: [drm] *ERROR* GT1: DEREGISTER_DONE: Unexpected engine state 0x00a1, guc_id=57 Looking at a snippet of corresponding ftrace for this GuC id we can see: 162.673311: xe_sched_msg_add: dev=0000:03:00.0, gt=1 guc_id=57, opcode=3 162.673317: xe_sched_msg_recv: dev=0000:03:00.0, gt=1 guc_id=57, opcode=3 162.673319: xe_exec_queue_scheduling_disable: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc_state=0x29, flags=0x0 162.674089: xe_exec_queue_kill: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc_state=0x29, flags=0x0 162.674108: xe_exec_queue_close: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3rwh-j2p9-wp9q

почти 4 года назад

The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.

EPSS: Низкий
github логотип

GHSA-3rwg-qhqc-m6rc

больше 1 года назад

Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rx5-2rm5-fvhx

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.

CVSS3: 9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rx2-x6mx-grj3

Cross-site scripting in Apache JSPWiki

CVSS3: 6.1
4%
Низкий
больше 6 лет назад
github логотип
GHSA-3rwx-rphm-m3g7

In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173473906

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rwx-3vwh-mwxc

Jenkins Vulnerable to Denial of Service (DoS)

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rww-fm75-jc23

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-3rww-7g94-g9qj

Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the string_repeat() function.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rwv-jrrg-99x3

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.5. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in the server running out of resources.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3rwv-g3jc-r7cc

An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave. It is recommended to update past 0.6.3 or git commit https://github.com/google/asylo/commit/a47ef55db2337d29de19c50cd29b0deb2871d31c

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rwr-fq47-78qj

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/v1/link/edit. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3rwq-vmr7-cggq

Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3rwq-pxmh-pw55

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

CVSS3: 9.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3rwq-2648-vg59

Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3rwp-9p3r-82c4

Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 7.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3rwm-jg87-jp7c

An out-of-bound write can be triggered by a specially-crafted command supplied by a userspace application. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6574AU, QCA8081, QCA9377, QCA9379, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM660, SDX20, SDX24

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rwj-vm9j-wg4r

IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.2 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152735.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rwj-v7jp-w542

Pagekit Stored Cross-site Scripting

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rwj-9q84-fmqw

A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.

0%
Низкий
10 месяцев назад
github логотип
GHSA-3rwj-253m-qrvm

In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc_submit: fix race around suspend_pending Currently in some testcases we can trigger: xe 0000:03:00.0: [drm] Assertion `exec_queue_destroyed(q)` failed! .... WARNING: CPU: 18 PID: 2640 at drivers/gpu/drm/xe/xe_guc_submit.c:1826 xe_guc_sched_done_handler+0xa54/0xef0 [xe] xe 0000:03:00.0: [drm] *ERROR* GT1: DEREGISTER_DONE: Unexpected engine state 0x00a1, guc_id=57 Looking at a snippet of corresponding ftrace for this GuC id we can see: 162.673311: xe_sched_msg_add: dev=0000:03:00.0, gt=1 guc_id=57, opcode=3 162.673317: xe_sched_msg_recv: dev=0000:03:00.0, gt=1 guc_id=57, opcode=3 162.673319: xe_exec_queue_scheduling_disable: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc_state=0x29, flags=0x0 162.674089: xe_exec_queue_kill: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc_state=0x29, flags=0x0 162.674108: xe_exec_queue_close: dev=0000:03:00.0, 1:0x2, gt=1, width=1, guc_id=57, guc...

CVSS3: 4.7
0%
Низкий
около 1 года назад
github логотип
GHSA-3rwh-j2p9-wp9q

The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3rwg-qhqc-m6rc

Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу