Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3q2g-h6qw-ffgj

почти 4 года назад

SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action.

EPSS: Низкий
github логотип

GHSA-3q2g-h5vg-gwqf

почти 4 года назад

smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.

EPSS: Низкий
github логотип

GHSA-3q2g-cq44-pjqq

11 месяцев назад

The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3q2g-2xmv-33rc

больше 3 лет назад

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0840.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3q2f-wr5w-xp3w

почти 4 года назад

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3q2f-qcg5-6425

больше 3 лет назад

A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652.

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-3q2f-pq2q-f9qf

около 1 года назад

TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.

CVSS3: 8
EPSS: Средний
github логотип

GHSA-3q2f-m5vm-7r8q

больше 3 лет назад

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3q2f-h5rm-7qv7

больше 3 лет назад

An ACL bypass flaw was found in pacemaker before 1.1.24-rc1 and 2.0.5-rc2. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3q2c-pvp5-3cqp

почти 2 года назад

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3q2c-9v2r-vjgj

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.

EPSS: Низкий
github логотип

GHSA-3q29-89cr-qgvj

больше 3 лет назад

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3q29-6c6h-84hh

больше 3 лет назад

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3q28-xfw3-2q35

больше 3 лет назад

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3q28-wqh2-j2f3

больше 3 лет назад

An unlimited recursion in DxeCore in EDK II.

EPSS: Низкий
github логотип

GHSA-3q28-p7pm-8p98

больше 3 лет назад

The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.

EPSS: Низкий
github логотип

GHSA-3q28-p6jr-9gpc

больше 3 лет назад

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-3q28-mmq2-xhcr

больше 3 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.

EPSS: Низкий
github логотип

GHSA-3q28-9x2c-2fcm

почти 4 года назад

In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06209201.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3q28-7xrx-5524

больше 3 лет назад

An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q2g-h6qw-ffgj

SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3q2g-h5vg-gwqf

smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3q2g-cq44-pjqq

The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
1%
Низкий
11 месяцев назад
github логотип
GHSA-3q2g-2xmv-33rc

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0840.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q2f-wr5w-xp3w

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

CVSS3: 6.1
4%
Низкий
почти 4 года назад
github логотип
GHSA-3q2f-qcg5-6425

A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652.

CVSS3: 5.9
62%
Средний
больше 3 лет назад
github логотип
GHSA-3q2f-pq2q-f9qf

TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.

CVSS3: 8
12%
Средний
около 1 года назад
github логотип
GHSA-3q2f-m5vm-7r8q

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q2f-h5rm-7qv7

An ACL bypass flaw was found in pacemaker before 1.1.24-rc1 and 2.0.5-rc2. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q2c-pvp5-3cqp

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3q2c-9v2r-vjgj

Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3q29-89cr-qgvj

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q29-6c6h-84hh

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q28-xfw3-2q35

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q28-wqh2-j2f3

An unlimited recursion in DxeCore in EDK II.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q28-p7pm-8p98

The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q28-p6jr-9gpc

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q28-mmq2-xhcr

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q28-9x2c-2fcm

In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06209201.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3q28-7xrx-5524

An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу