Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3h2w-7wcr-vq95

больше 3 лет назад

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.

EPSS: Низкий
github логотип

GHSA-3h2w-68px-r4v5

3 месяца назад

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit:  https://github.com/apache/apisix/pull/12629 Users are recommended to upgrade to version 3.14, which fixes this issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h2w-5hmv-xgqc

больше 3 лет назад

CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2v-h2q9-f9r6

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix possible NULL pointer dereference in wfx_set_mfp_ap() Since 'ieee80211_beacon_get()' can return NULL, 'wfx_set_mfp_ap()' should check the return value before examining skb data. So convert the latter to return an appropriate error code and propagate it to return from 'wfx_start_ap()' as well. Compile tested only.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h2r-mh7w-gr5w

больше 3 лет назад

Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h2r-h2x2-mg4h

больше 2 лет назад

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3h2r-57j7-jcpg

почти 4 года назад

In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-202006191References: N/A

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3h2r-2233-77cq

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2q-m63q-9cf6

больше 3 лет назад

Missing permission check in Perfecto Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3h2q-4qw3-2f5h

больше 3 лет назад

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3h2m-jjrw-87hw

больше 3 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2j-h4g8-5pmr

почти 4 года назад

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h2j-95j8-599v

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.

EPSS: Низкий
github логотип

GHSA-3h2h-xqr2-2jp7

почти 4 года назад

Cross-site Scripting (XSS) in Apache ActiveMQ Artemis

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h2h-j4vg-8xm8

около 2 лет назад

An issue in Notion for macOS version 3.1.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h2h-fwxh-x5w9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."

EPSS: Низкий
github логотип

GHSA-3h2g-8x7p-qmjq

почти 4 года назад

crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.

EPSS: Низкий
github логотип

GHSA-3h2g-4ppf-wwf9

больше 3 лет назад

chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.

EPSS: Низкий
github логотип

GHSA-3h2f-w6h5-7wr8

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h2f-562g-hqwc

больше 2 лет назад

SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h2w-7wcr-vq95

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2w-68px-r4v5

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit:  https://github.com/apache/apisix/pull/12629 Users are recommended to upgrade to version 3.14, which fixes this issue.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3h2w-5hmv-xgqc

CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2v-h2q9-f9r6

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix possible NULL pointer dereference in wfx_set_mfp_ap() Since 'ieee80211_beacon_get()' can return NULL, 'wfx_set_mfp_ap()' should check the return value before examining skb data. So convert the latter to return an appropriate error code and propagate it to return from 'wfx_start_ap()' as well. Compile tested only.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3h2r-mh7w-gr5w

Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2r-h2x2-mg4h

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

CVSS3: 2.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3h2r-57j7-jcpg

In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-202006191References: N/A

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-3h2r-2233-77cq

Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3h2q-m63q-9cf6

Missing permission check in Perfecto Plugin

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2q-4qw3-2f5h

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2m-jjrw-87hw

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2j-h4g8-5pmr

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3h2j-95j8-599v

Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2h-xqr2-2jp7

Cross-site Scripting (XSS) in Apache ActiveMQ Artemis

CVSS3: 6.1
3%
Низкий
почти 4 года назад
github логотип
GHSA-3h2h-j4vg-8xm8

An issue in Notion for macOS version 3.1.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3h2h-fwxh-x5w9

Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."

7%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2g-8x7p-qmjq

crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3h2g-4ppf-wwf9

chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2f-w6h5-7wr8

Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2f-562g-hqwc

SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу