Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3r7g-wrpr-j5g4

почти 4 года назад

Improper Authentication in django-mfa3

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3r7c-wgmw-38g7

около 3 лет назад

Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r7c-cf5v-4v53

больше 3 лет назад

OX App Suite 7.10.1 and 7.10.2 allows SSRF.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3r7c-93gc-73gw

больше 3 лет назад

Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r79-62f7-6gcx

7 месяцев назад

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators. Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server.

EPSS: Высокий
github логотип

GHSA-3r77-w9f5-q8q6

больше 3 лет назад

Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to execute arbitrary code via unspecified vectors to the (1) PrintSiteImage, (2) PlaySiteAllChannel, (3) StopSiteAllChannel, or (4) SaveSiteImage function.

EPSS: Средний
github логотип

GHSA-3r77-vxv8-f245

больше 3 лет назад

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to cause a denial of service condition or to execute arbitrary code. The vulnerability is due to improper boundary restrictions on user-supplied input in the Guest user feature of the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device, triggering a buffer overflow condition. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a denial of service condition, or could allow the attacker to execute arbitrary code.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3r77-48qc-c242

больше 3 лет назад

Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.

EPSS: Низкий
github логотип

GHSA-3r76-7gpf-jq4w

больше 1 года назад

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond their intended permissions.

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-3r75-2r54-55vx

больше 3 лет назад

The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3r74-v83p-f4f4

больше 1 года назад

Trufflehog vulnerable to Blind SSRF in some Detectors

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-3r74-6x6g-cp8v

больше 3 лет назад

An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3r74-3v78-7856

больше 3 лет назад

SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.

EPSS: Низкий
github логотип

GHSA-3r73-wrgm-c3rm

почти 4 года назад

The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.

EPSS: Низкий
github логотип

GHSA-3r73-v5gv-2jmq

7 месяцев назад

A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the recipient field of an e-mail message.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3r73-959g-g38r

почти 4 года назад

SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. NOTE: the original report indicated that this was the "photo" SourceForge project (aka Maan Bsat Photo Collection), but that was incorrect.

EPSS: Низкий
github логотип

GHSA-3r72-p59x-qr4h

больше 3 лет назад

The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3r72-j9f5-r8j5

больше 3 лет назад

In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3r72-fp6h-25pg

больше 3 лет назад

Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r6x-wmfj-r38f

2 месяца назад

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3r7g-wrpr-j5g4

Improper Authentication in django-mfa3

CVSS3: 7.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-3r7c-wgmw-38g7

Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3r7c-cf5v-4v53

OX App Suite 7.10.1 and 7.10.2 allows SSRF.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r7c-93gc-73gw

Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3r79-62f7-6gcx

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators. Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server.

71%
Высокий
7 месяцев назад
github логотип
GHSA-3r77-w9f5-q8q6

Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to execute arbitrary code via unspecified vectors to the (1) PrintSiteImage, (2) PlaySiteAllChannel, (3) StopSiteAllChannel, or (4) SaveSiteImage function.

57%
Средний
больше 3 лет назад
github логотип
GHSA-3r77-vxv8-f245

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to cause a denial of service condition or to execute arbitrary code. The vulnerability is due to improper boundary restrictions on user-supplied input in the Guest user feature of the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device, triggering a buffer overflow condition. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a denial of service condition, or could allow the attacker to execute arbitrary code.

CVSS3: 8.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3r77-48qc-c242

Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3r76-7gpf-jq4w

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond their intended permissions.

CVSS3: 3.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-3r75-2r54-55vx

The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3r74-v83p-f4f4

Trufflehog vulnerable to Blind SSRF in some Detectors

CVSS3: 3.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3r74-6x6g-cp8v

An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r74-3v78-7856

SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3r73-wrgm-c3rm

The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3r73-v5gv-2jmq

A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the recipient field of an e-mail message.

CVSS3: 5.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-3r73-959g-g38r

SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. NOTE: the original report indicated that this was the "photo" SourceForge project (aka Maan Bsat Photo Collection), but that was incorrect.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3r72-p59x-qr4h

The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

CVSS3: 5.4
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3r72-j9f5-r8j5

In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r72-fp6h-25pg

Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r6x-wmfj-r38f

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

CVSS3: 6.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу