Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 225

Количество 288 225

github логотип

GHSA-2282-f329-v64x

около 3 лет назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-2282-4ccr-wfvx

6 месяцев назад

The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in all versions up to, and including, 1.3.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-227x-w5qv-2294

больше 3 лет назад

admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

EPSS: Низкий
github логотип

GHSA-227x-6m74-5g32

больше 2 лет назад

Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-227x-48c5-2jpf

около 3 лет назад

HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.

EPSS: Низкий
github логотип

GHSA-227w-xh58-rx2j

около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.

EPSS: Низкий
github логотип

GHSA-227w-wv4j-67h4

больше 3 лет назад

Class Loading Vulnerability in Artemis

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-227w-82c7-87qx

около 3 лет назад

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS: Низкий
github логотип

GHSA-227v-w3r6-6vc4

около 3 лет назад

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-227v-m6p6-j6gx

почти 2 года назад

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-227r-w5j2-6243

5 месяцев назад

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-227r-cc3q-mh85

около 3 лет назад

Windows GDI+ Information Disclosure Vulnerability

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-227p-7qgj-96v9

около 1 года назад

Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-227m-878m-h3qm

около 1 года назад

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-227j-xj2v-7f5v

около 3 лет назад

The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

EPSS: Низкий
github логотип

GHSA-227h-wvc4-w9jx

около 3 лет назад

In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-227h-6jwp-327q

больше 1 года назад

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-227g-p58c-6fwx

5 месяцев назад

Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-227g-7cvv-6ff3

около 3 лет назад

Apache Tapestry 5.8.1 vulnerable to ReDoS via Content Types causing catastrophic backtracking

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-227g-5725-2cf3

около 3 лет назад

A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebsd-tools/vmware-tools-distrib/vmware-install.pl path. The fake ISO image will be mounted and the script wmware-install.pl will be executed with super-user privileges as soon as the hidden option to install VMware Tools is selected in the main menu of the restricted shell (option number 5). The contents of the script can be whatever the attacker wants, including a backdoor or similar.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2282-f329-v64x

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.36, prior to 6.0.16 and prior to 6.1.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

0%
Низкий
около 3 лет назад
github логотип
GHSA-2282-4ccr-wfvx

The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in all versions up to, and including, 1.3.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-227x-w5qv-2294

admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-227x-6m74-5g32

Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-227x-48c5-2jpf

HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.

0%
Низкий
около 3 лет назад
github логотип
GHSA-227w-xh58-rx2j

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.

0%
Низкий
около 3 лет назад
github логотип
GHSA-227w-wv4j-67h4

Class Loading Vulnerability in Artemis

CVSS3: 8.2
больше 3 лет назад
github логотип
GHSA-227w-82c7-87qx

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

1%
Низкий
около 3 лет назад
github логотип
GHSA-227v-w3r6-6vc4

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVSS3: 9.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-227v-m6p6-j6gx

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-227r-w5j2-6243

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
2%
Низкий
5 месяцев назад
github логотип
GHSA-227r-cc3q-mh85

Windows GDI+ Information Disclosure Vulnerability

CVSS3: 5.7
8%
Низкий
около 3 лет назад
github логотип
GHSA-227p-7qgj-96v9

Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-227m-878m-h3qm

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-227j-xj2v-7f5v

The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

1%
Низкий
около 3 лет назад
github логотип
GHSA-227h-wvc4-w9jx

In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-227h-6jwp-327q

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-227g-p58c-6fwx

Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-227g-7cvv-6ff3

Apache Tapestry 5.8.1 vulnerable to ReDoS via Content Types causing catastrophic backtracking

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-227g-5725-2cf3

A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebsd-tools/vmware-tools-distrib/vmware-install.pl path. The fake ISO image will be mounted and the script wmware-install.pl will be executed with super-user privileges as soon as the hidden option to install VMware Tools is selected in the main menu of the restricted shell (option number 5). The contents of the script can be whatever the attacker wants, including a backdoor or similar.

1%
Низкий
около 3 лет назад

Уязвимостей на страницу