Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3p9r-9j6c-6wxp

почти 4 года назад

Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.

EPSS: Низкий
github логотип

GHSA-3p9q-7w63-3f8q

11 месяцев назад

Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p9q-2c9q-vq29

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu allows Cross Site Request Forgery. This issue affects Bubble Menu – circle floating menu: from n/a through 4.0.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p9p-rmqp-8m38

больше 3 лет назад

An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p9p-h6x6-85gg

около 3 лет назад

The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p9p-84c4-78r8

больше 3 лет назад

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Certificate Request Message Format (CRMF) request.

EPSS: Низкий
github логотип

GHSA-3p9p-59qf-mqwh

больше 2 лет назад

Apache InLong has Files or Directories Accessible to External Parties

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p9m-6822-r65w

6 месяцев назад

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto of the file /goform/RP_setBasicAuto. The manipulation of the argument staticIp/staticNetmask leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3p9j-x42f-p86h

почти 2 года назад

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3p9j-442x-hjp7

почти 4 года назад

Business Logic Errors in microweber

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3p9h-r6fg-7r7h

4 месяца назад

A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with the engineering software. This could allow an on-path attacker between the engineering software and the controller to execute any previously recorded commands at a later time (e.g. set the controller to STOP), regardless whether or not the controller had a password configured.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3p9h-q4m6-wp5h

4 месяца назад

asdasdasdasdasdasdasd

EPSS: Низкий
github логотип

GHSA-3p9g-q4q3-x6mr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in edit.php in wellyblog allows remote attackers to inject arbitrary web script or HTML via the articleid parameter in an add action.

EPSS: Низкий
github логотип

GHSA-3p9g-h722-84r2

больше 3 лет назад

An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations, aka 'Windows iSCSI Target Service Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-3p9g-66p4-wgx6

26 дней назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3p9f-r3rx-4hx4

больше 3 лет назад

The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.

EPSS: Низкий
github логотип

GHSA-3p9c-7xp5-vwmq

почти 4 года назад

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.

EPSS: Низкий
github логотип

GHSA-3p9c-54gv-3m6x

почти 4 года назад

PHP-Ping 1.3 does not properly validate ping counts, which allows remote attackers to cause a denial of service (ping flood) via a negative count parameter.

EPSS: Низкий
github логотип

GHSA-3p9c-3m43-pw59

больше 3 лет назад

Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make the device not detect certain types of attacks. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D55; 15.1X49 prior to 15.1X49-D110;

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3p99-v7xg-6c4p

больше 3 лет назад

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175412.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p9r-9j6c-6wxp

Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3p9q-7w63-3f8q

Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint

CVSS3: 6.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-3p9q-2c9q-vq29

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu allows Cross Site Request Forgery. This issue affects Bubble Menu – circle floating menu: from n/a through 4.0.2.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3p9p-rmqp-8m38

An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9p-h6x6-85gg

The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p9p-84c4-78r8

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Certificate Request Message Format (CRMF) request.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9p-59qf-mqwh

Apache InLong has Files or Directories Accessible to External Parties

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3p9m-6822-r65w

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto of the file /goform/RP_setBasicAuto. The manipulation of the argument staticIp/staticNetmask leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3p9j-x42f-p86h

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through use after free.

CVSS3: 3.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3p9j-442x-hjp7

Business Logic Errors in microweber

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-3p9h-r6fg-7r7h

A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with the engineering software. This could allow an on-path attacker between the engineering software and the controller to execute any previously recorded commands at a later time (e.g. set the controller to STOP), regardless whether or not the controller had a password configured.

CVSS3: 7.4
0%
Низкий
4 месяца назад
github логотип
GHSA-3p9h-q4m6-wp5h

asdasdasdasdasdasdasd

4 месяца назад
github логотип
GHSA-3p9g-q4q3-x6mr

Cross-site scripting (XSS) vulnerability in edit.php in wellyblog allows remote attackers to inject arbitrary web script or HTML via the articleid parameter in an add action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9g-h722-84r2

An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations, aka 'Windows iSCSI Target Service Elevation of Privilege Vulnerability'.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9g-66p4-wgx6

Rejected reason: Not used

26 дней назад
github логотип
GHSA-3p9f-r3rx-4hx4

The Global TV application 2.3.2 for Android and 4.7.5 for iOS sends Unencrypted Analytics.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9c-7xp5-vwmq

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3p9c-54gv-3m6x

PHP-Ping 1.3 does not properly validate ping counts, which allows remote attackers to cause a denial of service (ping flood) via a negative count parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3p9c-3m43-pw59

Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make the device not detect certain types of attacks. Affected Junos OS releases are: 12.1X46 prior to 12.1X46-D71; 12.3X48 prior to 12.3X48-D55; 15.1X49 prior to 15.1X49-D110;

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p99-v7xg-6c4p

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175412.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу