Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 758

Количество 324 758

github логотип

GHSA-xr97-4xrw-7v23

почти 3 года назад

In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xr97-25v7-hc2q

8 месяцев назад

UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xr96-h2wc-75jf

почти 4 года назад

Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xr96-frvr-5w4p

почти 4 года назад

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).

EPSS: Низкий
github логотип

GHSA-xr96-c25j-m65g

почти 4 года назад

A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys that may allow an attacker to decrypt traffic from any other source.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr96-7ccp-pg5c

почти 4 года назад

DotNetNuke Vulnerable to XSS in Pass-Through Values

EPSS: Низкий
github логотип

GHSA-xr96-49c7-2pfc

3 месяца назад

Missing Authorization vulnerability in Damian WP Export Categories & Taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Export Categories & Taxonomies: from n/a through 1.0.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xr95-5hhj-crp6

почти 4 года назад

A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. Running dnsmasq in this manner may inadvertently make it an open resolver accessible from any address on the internet. This flaw allows an attacker to conduct a Distributed Denial of Service (DDoS) against other systems.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xr94-m5ww-76cc

почти 4 года назад

FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.

EPSS: Средний
github логотип

GHSA-xr94-h88h-jc73

около 1 года назад

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-xr94-cv8c-7r6v

около 2 лет назад

Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr94-3hc5-534p

около 2 лет назад

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22800.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xr94-28q3-25f3

почти 4 года назад

The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xr92-rw38-fmg9

почти 4 года назад

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

EPSS: Низкий
github логотип

GHSA-xr92-q26v-hcvr

почти 4 года назад

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.

EPSS: Низкий
github логотип

GHSA-xr8x-pxm6-prjg

около 3 лет назад

MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xr8x-f92g-w7rv

почти 2 года назад

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264443.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xr8x-5cxm-p785

почти 4 года назад

smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.

EPSS: Низкий
github логотип

GHSA-xr8x-4mg2-g4gr

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team Showcase team-showcase allows Stored XSS.This issue affects Team Showcase: from n/a through <= 2.9.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr8x-4f65-m34g

около 2 лет назад

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr97-4xrw-7v23

In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-xr97-25v7-hc2q

UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality

CVSS3: 6.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xr96-h2wc-75jf

Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVSS3: 9.6
1%
Низкий
почти 4 года назад
github логотип
GHSA-xr96-frvr-5w4p

Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).

0%
Низкий
почти 4 года назад
github логотип
GHSA-xr96-c25j-m65g

A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys that may allow an attacker to decrypt traffic from any other source.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr96-7ccp-pg5c

DotNetNuke Vulnerable to XSS in Pass-Through Values

1%
Низкий
почти 4 года назад
github логотип
GHSA-xr96-49c7-2pfc

Missing Authorization vulnerability in Damian WP Export Categories & Taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Export Categories &amp; Taxonomies: from n/a through 1.0.3.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xr95-5hhj-crp6

A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. Running dnsmasq in this manner may inadvertently make it an open resolver accessible from any address on the internet. This flaw allows an attacker to conduct a Distributed Denial of Service (DDoS) against other systems.

CVSS3: 5.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr94-m5ww-76cc

FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.

18%
Средний
почти 4 года назад
github логотип
GHSA-xr94-h88h-jc73

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 5.6
0%
Низкий
около 1 года назад
github логотип
GHSA-xr94-cv8c-7r6v

Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xr94-3hc5-534p

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22800.

CVSS3: 7.8
2%
Низкий
около 2 лет назад
github логотип
GHSA-xr94-28q3-25f3

The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr92-rw38-fmg9

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xr92-q26v-hcvr

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xr8x-pxm6-prjg

MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`

CVSS3: 9.1
около 3 лет назад
github логотип
GHSA-xr8x-f92g-w7rv

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264443.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr8x-5cxm-p785

smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.

4%
Низкий
почти 4 года назад
github логотип
GHSA-xr8x-4mg2-g4gr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team Showcase team-showcase allows Stored XSS.This issue affects Team Showcase: from n/a through <= 2.9.

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-xr8x-4f65-m34g

The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу