Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3m5j-38m5-7239

больше 3 лет назад

An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

EPSS: Низкий
github логотип

GHSA-3m5h-3839-5w2g

почти 4 года назад

Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID.

EPSS: Низкий
github логотип

GHSA-3m5c-7hqx-55x7

больше 3 лет назад

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

EPSS: Низкий
github логотип

GHSA-3m59-fh79-m7m6

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon WHMpress allows Reflected XSS.This issue affects WHMpress: from n/a through 6.2-revision-5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3m59-c9cm-pmrv

больше 3 лет назад

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3m58-pgrc-g8hf

почти 3 года назад

Azure Machine Learning Compute Instance Information Disclosure Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3m58-3m5q-53hq

больше 3 лет назад

Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3m56-p87c-39jp

больше 3 лет назад

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS responses are cached by the router, potentially resulting in cache poisoning

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3m56-mh77-c3gc

больше 3 лет назад

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3m54-gw4x-32mf

почти 3 года назад

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3m53-prxg-5mr2

почти 4 года назад

Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.

EPSS: Низкий
github логотип

GHSA-3m53-jv7g-9x6v

больше 3 лет назад

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3m53-3rwg-2453

больше 3 лет назад

In Android before 2018-01-05 on Qualcomm Snapdragon Mobile SD 625, SD 650/52, SD 835, accessing SPCOM functions with a compromised client structure can result in a Use After Free condition.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3m52-hx3w-rfj4

почти 4 года назад

PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via a URL in the contentSpecial parameter.

EPSS: Низкий
github логотип

GHSA-3m52-6qc2-vwqh

9 месяцев назад

The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3m4x-gq6q-g6qr

больше 3 лет назад

A NULL pointer dereference flaw in kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when using BT_SNDMTU/BT_RCVMTU for SCO sockets. This could allow a local attacker with a special user privilege to crash the system (DOS) or leak kernel internal information.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3m4w-82p4-mv9p

почти 4 года назад

Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption.

EPSS: Низкий
github логотип

GHSA-3m4v-8v7m-fjqh

9 месяцев назад

Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3m4q-qm3m-pcv6

больше 3 лет назад

In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

EPSS: Низкий
github логотип

GHSA-3m4q-2j85-4rqv

10 месяцев назад

A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown processing of the file /ztree/insertTree. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3m5j-38m5-7239

An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m5h-3839-5w2g

Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3m5c-7hqx-55x7

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3m59-fh79-m7m6

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon WHMpress allows Reflected XSS.This issue affects WHMpress: from n/a through 6.2-revision-5.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3m59-c9cm-pmrv

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.

CVSS3: 5.5
7%
Низкий
больше 3 лет назад
github логотип
GHSA-3m58-pgrc-g8hf

Azure Machine Learning Compute Instance Information Disclosure Vulnerability

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3m58-3m5q-53hq

Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3m56-p87c-39jp

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS responses are cached by the router, potentially resulting in cache poisoning

CVSS3: 7.5
17%
Средний
больше 3 лет назад
github логотип
GHSA-3m56-mh77-c3gc

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m54-gw4x-32mf

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3m53-prxg-5mr2

Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3m53-jv7g-9x6v

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.

CVSS3: 6.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3m53-3rwg-2453

In Android before 2018-01-05 on Qualcomm Snapdragon Mobile SD 625, SD 650/52, SD 835, accessing SPCOM functions with a compromised client structure can result in a Use After Free condition.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3m52-hx3w-rfj4

PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via a URL in the contentSpecial parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-3m52-6qc2-vwqh

The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-3m4x-gq6q-g6qr

A NULL pointer dereference flaw in kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when using BT_SNDMTU/BT_RCVMTU for SCO sockets. This could allow a local attacker with a special user privilege to crash the system (DOS) or leak kernel internal information.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m4w-82p4-mv9p

Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3m4v-8v7m-fjqh

Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-3m4q-qm3m-pcv6

In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m4q-2j85-4rqv

A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown processing of the file /ztree/insertTree. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
10 месяцев назад

Уязвимостей на страницу