Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3p24-qq22-3v59

больше 3 лет назад

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Высокий
github логотип

GHSA-3p24-p4jg-q3pq

больше 3 лет назад

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and arbitrary code execution. The Samsung ID is SVE-2019-15984 (February 2020).

EPSS: Низкий
github логотип

GHSA-3p24-gwpr-5f2q

почти 4 года назад

The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.

EPSS: Низкий
github логотип

GHSA-3p24-fq2f-mhqw

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marchetti Design Next Event Calendar allows Stored XSS. This issue affects Next Event Calendar: from n/a through 1.2.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3p24-8mw5-x2hx

7 месяцев назад

Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3p23-x5x3-gwjm

больше 3 лет назад

Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.

EPSS: Низкий
github логотип

GHSA-3p23-jfm6-493m

почти 4 года назад

This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16191.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p22-ghq8-v749

почти 4 года назад

Renderers can obtain access to random bluetooth device without permission in Electron

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-3p22-6rfg-m95x

почти 4 года назад

Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostname that is determined using reverse DNS lookups, (2) a long AUTH string, or (3) certain data in the xtell request.

EPSS: Средний
github логотип

GHSA-3mxx-c2rp-35q6

10 месяцев назад

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportCertificate' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mxw-j4x8-9xp2

почти 3 года назад

The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mxv-x893-5542

больше 1 года назад

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::FeaturesReply::unpack. This issue affects libfluid: 0.1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mxv-7mfp-6f7r

больше 3 лет назад

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component mp4mux. The manipulation leads to memory leak. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212683.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mxv-473p-h624

почти 2 года назад

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3mxr-r8gm-qxvv

больше 3 лет назад

oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

EPSS: Низкий
github логотип

GHSA-3mxr-5pfh-9c75

больше 3 лет назад

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mxr-2h37-xpjx

больше 3 лет назад

The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.

EPSS: Низкий
github логотип

GHSA-3mxq-x62m-9mvp

больше 3 лет назад

** DISPUTED ** An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue."

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mxq-v9rw-m6x9

больше 3 лет назад

Magento 2 Community Edition XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mxq-jvx5-cj48

6 месяцев назад

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p24-qq22-3v59

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

83%
Высокий
больше 3 лет назад
github логотип
GHSA-3p24-p4jg-q3pq

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and arbitrary code execution. The Samsung ID is SVE-2019-15984 (February 2020).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p24-gwpr-5f2q

The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3p24-fq2f-mhqw

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marchetti Design Next Event Calendar allows Stored XSS. This issue affects Next Event Calendar: from n/a through 1.2.

CVSS3: 5.9
0%
Низкий
8 месяцев назад
github логотип
GHSA-3p24-8mw5-x2hx

Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.

CVSS3: 4.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3p23-x5x3-gwjm

Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p23-jfm6-493m

This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16191.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3p22-ghq8-v749

Renderers can obtain access to random bluetooth device without permission in Electron

CVSS3: 3.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-3p22-6rfg-m95x

Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostname that is determined using reverse DNS lookups, (2) a long AUTH string, or (3) certain data in the xtell request.

14%
Средний
почти 4 года назад
github логотип
GHSA-3mxx-c2rp-35q6

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportCertificate' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

CVSS3: 8.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-3mxw-j4x8-9xp2

The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3mxv-x893-5542

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::FeaturesReply::unpack. This issue affects libfluid: 0.1.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3mxv-7mfp-6f7r

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component mp4mux. The manipulation leads to memory leak. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212683.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mxv-473p-h624

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame

CVSS3: 6.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-3mxr-r8gm-qxvv

oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mxr-5pfh-9c75

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mxr-2h37-xpjx

The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mxq-x62m-9mvp

** DISPUTED ** An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue."

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mxq-v9rw-m6x9

Magento 2 Community Edition XSS Vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mxq-jvx5-cj48

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

CVSS3: 8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу