Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3jxh-7h2g-h6mg

почти 4 года назад

AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.

EPSS: Низкий
github логотип

GHSA-3jxh-789f-p7m6

больше 4 лет назад

Craft CMS Cross-site Scripting Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3jxh-6635-6jwp

больше 3 лет назад

Path traversal in Concrete CMS

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3jxg-9cjf-4f5f

больше 1 года назад

An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3jxg-43fv-33j7

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.

EPSS: Низкий
github логотип

GHSA-3jxf-9f38-734g

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Joshua Wieczorek Bible Embed allows Stored XSS.This issue affects Bible Embed: from n/a through 0.0.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3jxc-895x-c94m

больше 3 лет назад

Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

EPSS: Низкий
github логотип

GHSA-3jxc-48w3-hf8g

почти 3 года назад

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 235533.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3jx9-v77h-f29p

почти 3 года назад

In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257289560References: N/A

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3jx9-mgwx-4q83

больше 3 лет назад

Apache Shiro Path Traversal vulnerability

EPSS: Средний
github логотип

GHSA-3jx8-9w5m-fvm9

3 месяца назад

A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1, visionOS 26.1. An app may be able to enumerate a user's installed apps.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3jx7-x4qq-w952

больше 3 лет назад

A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc77783. Known Affected Releases: 11.5(0).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3jx7-82j9-5prx

больше 3 лет назад

Valve Steam through 2021-04-10, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.

CVSS3: 9
EPSS: Средний
github логотип

GHSA-3jx6-xj3f-cxpm

больше 3 лет назад

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (with Hrm sensor support) software. The sysfs of the MAX86902 sensor driver does not prevent concurrent access, leading to a race condition and resultant heap-based buffer overflow. The Samsung ID is SVE-2016-7341 (December 2016).

EPSS: Низкий
github логотип

GHSA-3jx5-x6hv-w267

4 месяца назад

Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites or domains.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3jx5-7q2x-vvjw

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple Image Popup allows Stored XSS.This issue affects Simple Image Popup: from n/a through 2.4.0.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3jx4-rw6p-82pp

около 4 лет назад

A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.

EPSS: Низкий
github логотип

GHSA-3jx4-mgj3-j557

больше 3 лет назад

The PluginGetDriverFile function in Novell iPrint Client before 5.44 interprets an uninitialized memory location as a pointer value, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3jx4-4w9w-g9w4

около 1 года назад

TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains a Relative Path Traversal vulnerability, allowing attackers to write arbitrary files to any path on the user's system.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3jx4-3grj-xm5w

около 2 лет назад

Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jxh-7h2g-h6mg

AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3jxh-789f-p7m6

Craft CMS Cross-site Scripting Vulnerability

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3jxh-6635-6jwp

Path traversal in Concrete CMS

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jxg-9cjf-4f5f

An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3jxg-43fv-33j7

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jxf-9f38-734g

Cross-Site Request Forgery (CSRF) vulnerability in Joshua Wieczorek Bible Embed allows Stored XSS.This issue affects Bible Embed: from n/a through 0.0.4.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3jxc-895x-c94m

Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jxc-48w3-hf8g

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 235533.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3jx9-v77h-f29p

In rtt_unpack_xtlv_cbfn of dhd_rtt.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257289560References: N/A

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-3jx9-mgwx-4q83

Apache Shiro Path Traversal vulnerability

11%
Средний
больше 3 лет назад
github логотип
GHSA-3jx8-9w5m-fvm9

A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1, visionOS 26.1. An app may be able to enumerate a user's installed apps.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3jx7-x4qq-w952

A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: Cisco Prime Collaboration Assurance software versions 11.0, 11.1, and 11.5 are vulnerable. Cisco Prime Collaboration Assurance software versions prior to 11.0 are not vulnerable. More Information: CSCvc77783. Known Affected Releases: 11.5(0).

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jx7-82j9-5prx

Valve Steam through 2021-04-10, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.

CVSS3: 9
11%
Средний
больше 3 лет назад
github логотип
GHSA-3jx6-xj3f-cxpm

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (with Hrm sensor support) software. The sysfs of the MAX86902 sensor driver does not prevent concurrent access, leading to a race condition and resultant heap-based buffer overflow. The Samsung ID is SVE-2016-7341 (December 2016).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jx5-x6hv-w267

Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites or domains.

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-3jx5-7q2x-vvjw

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple Image Popup allows Stored XSS.This issue affects Simple Image Popup: from n/a through 2.4.0.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3jx4-rw6p-82pp

A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3jx4-mgj3-j557

The PluginGetDriverFile function in Novell iPrint Client before 5.44 interprets an uninitialized memory location as a pointer value, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3jx4-4w9w-g9w4

TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains a Relative Path Traversal vulnerability, allowing attackers to write arbitrary files to any path on the user's system.

CVSS3: 8.1
1%
Низкий
около 1 года назад
github логотип
GHSA-3jx4-3grj-xm5w

Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу