Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3q9p-8qv6-vmjm

больше 1 года назад

The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify favorite views.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3q9m-cg52-56rj

больше 3 лет назад

ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a Relay-Forward message without an address in the Relay-Forward link-address field.

EPSS: Низкий
github логотип

GHSA-3q9m-9378-c85r

больше 2 лет назад

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3q9m-89p9-39jw

около 2 лет назад

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3q9f-2cp9-wp8v

больше 3 лет назад

Improper access control in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3q99-mmr6-6chg

больше 3 лет назад

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3q99-27hh-rcx8

около 3 лет назад

Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3q98-gw9r-j8rr

почти 4 года назад

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3q97-vjpp-c8rp

около 1 года назад

Socialstream has a Potential Account Takeover Vulnerability in Social Account Linking Due to Missing User Consent After OAuth Callback

EPSS: Низкий
github логотип

GHSA-3q96-v6jw-84q4

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3q96-v5v2-gwhq

больше 3 лет назад

In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.

EPSS: Низкий
github логотип

GHSA-3q95-xjvq-cqjf

больше 3 лет назад

A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or G46), SINAMICS PERFECT HARMONY GH180 with NXG II control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or G46). An improperly configured Parameter Read/Write execution via Field bus network may cause the controller to restart. The vulnerability could be exploited by an attacker with network access to the device. Successful exploitation requires no privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known.

EPSS: Низкий
github логотип

GHSA-3q95-7wc4-39vr

больше 3 лет назад

EMC SourceOne Email Supervisor before 7.2 does not properly employ random values for session IDs, which makes it easier for remote attackers to obtain access by guessing an ID.

EPSS: Низкий
github логотип

GHSA-3q94-vm9h-5h6v

3 дня назад

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3q94-6qx8-j4xw

почти 4 года назад

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0202, and CVE-2010-0203.

EPSS: Средний
github логотип

GHSA-3q92-j8r6-g6h8

больше 3 лет назад

ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-3q92-5vpf-96pw

5 месяцев назад

A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged, remote attacker to trigger a crash of the PIM6 process, resulting in a denial of service (DoS) condition. This vulnerability is due to improper processing of PIM6 ephemeral data queries. An attacker could exploit this vulnerability by sending a crafted ephemeral query to an affected device through one of the following methods: NX-API REST, NETCONF, RESTConf, gRPC, or Model Driven Telemetry. A successful exploit could allow the attacker to cause the PIM6 process to crash and restart, causing potential adjacency flaps and resulting in a DoS of the PIM6 and ephemeral query processes.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3q8x-vx89-4p24

6 месяцев назад

Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3q8x-6r83-jhqw

около 1 месяца назад

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

EPSS: Низкий
github логотип

GHSA-3q8x-6m7c-5p98

больше 3 лет назад

Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q9p-8qv6-vmjm

The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and above, to modify favorite views.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3q9m-cg52-56rj

ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a Relay-Forward message without an address in the Relay-Forward link-address field.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-3q9m-9378-c85r

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3q9m-89p9-39jw

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3q9f-2cp9-wp8v

Improper access control in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q99-mmr6-6chg

In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q99-27hh-rcx8

Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.

CVSS3: 9.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-3q98-gw9r-j8rr

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

CVSS3: 3.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-3q97-vjpp-c8rp

Socialstream has a Potential Account Takeover Vulnerability in Social Account Linking Due to Missing User Consent After OAuth Callback

0%
Низкий
около 1 года назад
github логотип
GHSA-3q96-v6jw-84q4

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3q96-v5v2-gwhq

In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q95-xjvq-cqjf

A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or G46), SINAMICS PERFECT HARMONY GH180 with NXG II control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or G46). An improperly configured Parameter Read/Write execution via Field bus network may cause the controller to restart. The vulnerability could be exploited by an attacker with network access to the device. Successful exploitation requires no privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q95-7wc4-39vr

EMC SourceOne Email Supervisor before 7.2 does not properly employ random values for session IDs, which makes it easier for remote attackers to obtain access by guessing an ID.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q94-vm9h-5h6v

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.

CVSS3: 4.7
0%
Низкий
3 дня назад
github логотип
GHSA-3q94-6qx8-j4xw

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0202, and CVE-2010-0203.

27%
Средний
почти 4 года назад
github логотип
GHSA-3q92-j8r6-g6h8

ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.

CVSS3: 3.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q92-5vpf-96pw

A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged, remote attacker to trigger a crash of the PIM6 process, resulting in a denial of service (DoS) condition. This vulnerability is due to improper processing of PIM6 ephemeral data queries. An attacker could exploit this vulnerability by sending a crafted ephemeral query to an affected device through one of the following methods: NX-API REST, NETCONF, RESTConf, gRPC, or Model Driven Telemetry. A successful exploit could allow the attacker to cause the PIM6 process to crash and restart, causing potential adjacency flaps and resulting in a DoS of the PIM6 and ephemeral query processes.

CVSS3: 5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3q8x-vx89-4p24

Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.

CVSS3: 9.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-3q8x-6r83-jhqw

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

около 1 месяца назад
github логотип
GHSA-3q8x-6m7c-5p98

Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу