Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3jw2-chpc-h229

6 месяцев назад

A vulnerability was identified in Portabilis i-Diario 1.6. Affected by this vulnerability is an unknown functionality of the file /dicionario-de-termos-bncc of the component Dicionário de Termos BNCC Page. The manipulation of the argument Planos de ensino leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-3jw2-5hjg-hc2c

3 месяца назад

Jenkins Extensible Choice Parameter Plugin vulnerable to cross-site request forgery

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3jvx-f94j-g6fh

больше 2 лет назад

e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jvx-6vr7-jwgj

почти 4 года назад

Destiney Links Script 2.1.2 does not protect library and other support files, which allows remote attackers to obtain the installation path via a direct URL to files in the (1) include and (2) themes/original directories.

EPSS: Низкий
github логотип

GHSA-3jvx-6m6x-8g45

больше 2 лет назад

IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3jvw-9ph4-qc53

почти 4 года назад

Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.

EPSS: Низкий
github логотип

GHSA-3jvw-73q9-5f3x

больше 3 лет назад

Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.

EPSS: Низкий
github логотип

GHSA-3jvv-r7g7-63qp

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3jvv-m32r-4hpf

больше 2 лет назад

All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to set request headers in the addHeader function. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3jvv-6xf5-32ff

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted web site.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3jvr-vh6h-62fq

почти 3 года назад

PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3jvr-7h6f-xpmw

почти 4 года назад

Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3jvr-3w2h-527p

больше 3 лет назад

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES Key that can be used for packet decryption (obtaining cleartext credentials) by an attacker who has access to a wired port.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3jvq-9rg9-g8rp

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: avoid deadlock between hci_dev->lock and socket lock Commit eab2404ba798 ("Bluetooth: Add BT_PHY socket option") added a dependency between socket lock and hci_dev->lock that could lead to deadlock. It turns out that hci_conn_get_phy() is not in any way relying on hdev being immutable during the runtime of this function, neither does it even look at any of the members of hdev, and as such there is no need to hold that lock. This fixes the lockdep splat below: ====================================================== WARNING: possible circular locking dependency detected 5.12.0-rc1-00026-g73d464503354 #10 Not tainted ------------------------------------------------------ bluetoothd/1118 is trying to acquire lock: ffff8f078383c078 (&hdev->lock){+.+.}-{3:3}, at: hci_conn_get_phy+0x1c/0x150 [bluetooth] but task is already holding lock: ffff8f07e831d920 (sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP){+.+.}-{0:...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3jvq-6cw5-wrc6

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3jvq-22jp-22pp

около 4 лет назад

An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific IPv6 packets on certain EX Series devices may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Over time, exploitation of this vulnerability may cause traffic to stop being forwarded, or a crash of the fxpc process. An indication of the issue occurring may be observed through the following log messages: Sep 13 17:14:59 hostname : %PFE-3: fpc0 (buf alloc) failed allocating packet buffer Sep 13 17:14:59 hostname : %PFE-7: fpc0 brcm_pkt_buf_alloc:393 (buf alloc) failed allocating packet buffer When Packet DMA heap utilization reaches 99%, the system will become unstable. Packet DMA heap utilization can be monitored using the command: user@junos# request pfe execute target fpc0 timeout 30 command "show heap" ID Base Total(b) Free(b) Used(b) % Name -- ---------- ----------- ----------- ----------- --- ----------- 0 213301a8 536870488 387228840 149641648 27 Kernel 1 91800...

EPSS: Низкий
github логотип

GHSA-3jvm-p6c5-56xr

больше 3 лет назад

Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local users to gain privileges via unspecified vectors.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jvj-rg8c-7p8m

больше 2 лет назад

Exposure of sensitive information to an unauthorized actor issue exists in ELECOM wireless LAN routers, which allows a network-adjacent attacker to obtain sensitive information. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3jvj-f4f8-9hp2

6 месяцев назад

By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauthorized users to access and manipulate monitoring and control functions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jvj-6m5c-4r84

3 дня назад

Tanium addressed an information disclosure vulnerability in Threat Response.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jw2-chpc-h229

A vulnerability was identified in Portabilis i-Diario 1.6. Affected by this vulnerability is an unknown functionality of the file /dicionario-de-termos-bncc of the component Dicionário de Termos BNCC Page. The manipulation of the argument Planos de ensino leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-3jw2-5hjg-hc2c

Jenkins Extensible Choice Parameter Plugin vulnerable to cross-site request forgery

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-3jvx-f94j-g6fh

e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3jvx-6vr7-jwgj

Destiney Links Script 2.1.2 does not protect library and other support files, which allows remote attackers to obtain the installation path via a direct URL to files in the (1) include and (2) themes/original directories.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jvx-6m6x-8g45

IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jvw-9ph4-qc53

Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jvw-73q9-5f3x

Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jvv-r7g7-63qp

Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php.

CVSS3: 6.1
10%
Низкий
больше 3 лет назад
github логотип
GHSA-3jvv-m32r-4hpf

All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to set request headers in the addHeader function. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jvv-6xf5-32ff

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted web site.

CVSS3: 8.1
10%
Низкий
больше 3 лет назад
github логотип
GHSA-3jvr-vh6h-62fq

PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.

CVSS3: 6.1
9%
Низкий
почти 3 года назад
github логотип
GHSA-3jvr-7h6f-xpmw

Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jvr-3w2h-527p

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES Key that can be used for packet decryption (obtaining cleartext credentials) by an attacker who has access to a wired port.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jvq-9rg9-g8rp

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: avoid deadlock between hci_dev->lock and socket lock Commit eab2404ba798 ("Bluetooth: Add BT_PHY socket option") added a dependency between socket lock and hci_dev->lock that could lead to deadlock. It turns out that hci_conn_get_phy() is not in any way relying on hdev being immutable during the runtime of this function, neither does it even look at any of the members of hdev, and as such there is no need to hold that lock. This fixes the lockdep splat below: ====================================================== WARNING: possible circular locking dependency detected 5.12.0-rc1-00026-g73d464503354 #10 Not tainted ------------------------------------------------------ bluetoothd/1118 is trying to acquire lock: ffff8f078383c078 (&hdev->lock){+.+.}-{3:3}, at: hci_conn_get_phy+0x1c/0x150 [bluetooth] but task is already holding lock: ffff8f07e831d920 (sk_lock-AF_BLUETOOTH-BTPROTO_L2CAP){+.+.}-{0:...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3jvq-6cw5-wrc6

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jvq-22jp-22pp

An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific IPv6 packets on certain EX Series devices may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Over time, exploitation of this vulnerability may cause traffic to stop being forwarded, or a crash of the fxpc process. An indication of the issue occurring may be observed through the following log messages: Sep 13 17:14:59 hostname : %PFE-3: fpc0 (buf alloc) failed allocating packet buffer Sep 13 17:14:59 hostname : %PFE-7: fpc0 brcm_pkt_buf_alloc:393 (buf alloc) failed allocating packet buffer When Packet DMA heap utilization reaches 99%, the system will become unstable. Packet DMA heap utilization can be monitored using the command: user@junos# request pfe execute target fpc0 timeout 30 command "show heap" ID Base Total(b) Free(b) Used(b) % Name -- ---------- ----------- ----------- ----------- --- ----------- 0 213301a8 536870488 387228840 149641648 27 Kernel 1 91800...

0%
Низкий
около 4 лет назад
github логотип
GHSA-3jvm-p6c5-56xr

Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local users to gain privileges via unspecified vectors.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jvj-rg8c-7p8m

Exposure of sensitive information to an unauthorized actor issue exists in ELECOM wireless LAN routers, which allows a network-adjacent attacker to obtain sensitive information. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jvj-f4f8-9hp2

By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauthorized users to access and manipulate monitoring and control functions.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-3jvj-6m5c-4r84

Tanium addressed an information disclosure vulnerability in Threat Response.

CVSS3: 4.3
0%
Низкий
3 дня назад

Уязвимостей на страницу