Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3ppx-8h63-84vp

4 месяца назад

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3ppw-4jp4-5852

11 месяцев назад

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be exploited by injecting malicious HTML content during the training process, which is then rendered unsanitized in the Text Explorer.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3ppv-wqrq-v3rc

больше 3 лет назад

Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3ppr-72x5-x67q

около 3 лет назад

XML external entity vulnerability on agents in Jenkins MSTest Plugin

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3ppr-6h5r-qm4p

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.

EPSS: Низкий
github логотип

GHSA-3ppq-w2m7-6qvc

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.

EPSS: Низкий
github логотип

GHSA-3ppq-p8g9-x6rg

больше 3 лет назад

Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.

EPSS: Средний
github логотип

GHSA-3ppq-5wmg-wx3m

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downloads allows Stored XSS.This issue affects Z-Downloads: from n/a through 1.11.7.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3ppp-h4gc-mww4

почти 4 года назад

Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.

EPSS: Средний
github логотип

GHSA-3ppm-vmgq-rr54

почти 4 года назад

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3ppm-fwhm-qqg6

около 3 лет назад

FeehiCMS is vulnerable to Cross-Site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3ppm-97rq-4xwq

больше 3 лет назад

The sbr_make_f_master function in aacsbr.c in Libav 11.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3ppm-3h78-rw33

почти 4 года назад

Directory traversal vulnerability in download.php in webGENEius GOOP Gallery 2.0.2 allows remote attackers to read or list data from certain files or directories via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3ppj-x7p7-vph2

больше 3 лет назад

classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in a delete action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3pph-x43c-2v7f

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: wait for previous gc cycles when removing port syzbot hit a use-after-free[1] which is caused because the bridge doesn't make sure that all previous garbage has been collected when removing a port. What happens is: CPU 1 CPU 2 start gc cycle remove port acquire gc lock first wait for lock call br_multicasg_gc() directly acquire lock now but free port the port can be freed while grp timers still running Make sure all previous gc cycles have finished by using flush_work before freeing the port. [1] BUG: KASAN: slab-use-after-free in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861 Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699 CPU: 1 PID: 9699 Comm: syz.5.1232 Not tainted 6.10.0-rc5-syzkaller-00021-g24ca36a562d6 #0 Hardware name: Google Google Compute E...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pph-g5w6-c57w

больше 3 лет назад

SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pph-2595-cgfh

больше 7 лет назад

There is a XML external entity expansion (XXE) vulnerability in Apache Solr

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3ppg-6j84-f79c

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: media: az6007: Fix null-ptr-deref in az6007_i2c_xfer() In az6007_i2c_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach az6007_i2c_xfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3ppf-x2gr-8g6c

больше 3 лет назад

Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. This is a different vulnerability from CVE-2020-18221.

EPSS: Низкий
github логотип

GHSA-3ppf-gh8m-x9x8

почти 4 года назад

Ethereal 0.9.4 and earlier allows remote attackers to cause a denial of service and possibly excecute arbitrary code via the (1) SOCKS, (2) RSVP, (3) AFS, or (4) LMP dissectors, which can be caused to core dump.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3ppx-8h63-84vp

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3ppw-4jp4-5852

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be exploited by injecting malicious HTML content during the training process, which is then rendered unsanitized in the Text Explorer.

CVSS3: 7.2
0%
Низкий
11 месяцев назад
github логотип
GHSA-3ppv-wqrq-v3rc

Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

CVSS3: 7.5
40%
Средний
больше 3 лет назад
github логотип
GHSA-3ppr-72x5-x67q

XML external entity vulnerability on agents in Jenkins MSTest Plugin

CVSS3: 9.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-3ppr-6h5r-qm4p

Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ppq-w2m7-6qvc

Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ppq-p8g9-x6rg

Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.

13%
Средний
больше 3 лет назад
github логотип
GHSA-3ppq-5wmg-wx3m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downloads allows Stored XSS.This issue affects Z-Downloads: from n/a through 1.11.7.

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-3ppp-h4gc-mww4

Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.

12%
Средний
почти 4 года назад
github логотип
GHSA-3ppm-vmgq-rr54

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.

CVSS3: 7.5
6%
Низкий
почти 4 года назад
github логотип
GHSA-3ppm-fwhm-qqg6

FeehiCMS is vulnerable to Cross-Site Scripting (XSS)

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3ppm-97rq-4xwq

The sbr_make_f_master function in aacsbr.c in Libav 11.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3ppm-3h78-rw33

Directory traversal vulnerability in download.php in webGENEius GOOP Gallery 2.0.2 allows remote attackers to read or list data from certain files or directories via unspecified vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3ppj-x7p7-vph2

classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in a delete action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pph-x43c-2v7f

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: wait for previous gc cycles when removing port syzbot hit a use-after-free[1] which is caused because the bridge doesn't make sure that all previous garbage has been collected when removing a port. What happens is: CPU 1 CPU 2 start gc cycle remove port acquire gc lock first wait for lock call br_multicasg_gc() directly acquire lock now but free port the port can be freed while grp timers still running Make sure all previous gc cycles have finished by using flush_work before freeing the port. [1] BUG: KASAN: slab-use-after-free in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861 Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699 CPU: 1 PID: 9699 Comm: syz.5.1232 Not tainted 6.10.0-rc5-syzkaller-00021-g24ca36a562d6 #0 Hardware name: Google Google Compute E...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pph-g5w6-c57w

SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3pph-2595-cgfh

There is a XML external entity expansion (XXE) vulnerability in Apache Solr

CVSS3: 7.5
6%
Низкий
больше 7 лет назад
github логотип
GHSA-3ppg-6j84-f79c

In the Linux kernel, the following vulnerability has been resolved: media: az6007: Fix null-ptr-deref in az6007_i2c_xfer() In az6007_i2c_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach az6007_i2c_xfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3ppf-x2gr-8g6c

Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. This is a different vulnerability from CVE-2020-18221.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ppf-gh8m-x9x8

Ethereal 0.9.4 and earlier allows remote attackers to cause a denial of service and possibly excecute arbitrary code via the (1) SOCKS, (2) RSVP, (3) AFS, or (4) LMP dissectors, which can be caused to core dump.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу