Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3j9m-g8ph-73q2

почти 4 года назад

Opera 10.50 allows remote attackers to obtain sensitive information via crafted XSLT constructs, which cause Opera to return cached contents of other pages.

EPSS: Низкий
github логотип

GHSA-3j9m-4q8w-cqcp

5 месяцев назад

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 2.1.0. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j9j-xcvh-87c7

около 2 лет назад

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j9j-89rj-v28w

почти 4 года назад

CRLF injection vulnerability in (1) index.php and (2) admin.php in myWebland MyBloggie 2.1.3 allows remote attackers to hijack sessions and conduct cross-site scripting (XSS) attacks via a cookie.

EPSS: Низкий
github логотип

GHSA-3j9j-5462-cpx8

больше 2 лет назад

link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j9j-2r36-985r

больше 3 лет назад

Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3j9h-ppgw-76q9

больше 3 лет назад

Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter. in a GET request in view.cgi.

EPSS: Низкий
github логотип

GHSA-3j9h-5r8r-rrxc

больше 3 лет назад

In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

EPSS: Низкий
github логотип

GHSA-3j9g-r75v-xgjr

больше 3 лет назад

Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3j9f-c32h-wgj8

больше 3 лет назад

The Mindless Behavior Fan Base (aka com.mindless.behavior.fan.base) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3j9f-7w24-pcqg

3 месяца назад

Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3j9f-4r3c-964g

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: powerpc/qspinlock: Fix deadlock in MCS queue If an interrupt occurs in queued_spin_lock_slowpath() after we increment qnodesp->count and before node->lock is initialized, another CPU might see stale lock values in get_tail_qnode(). If the stale lock value happens to match the lock on that CPU, then we write to the "next" pointer of the wrong qnode. This causes a deadlock as the former CPU, once it becomes the head of the MCS queue, will spin indefinitely until it's "next" pointer is set by its successor in the queue. Running stress-ng on a 16 core (16EC/16VP) shared LPAR, results in occasional lockups similar to the following: $ stress-ng --all 128 --vm-bytes 80% --aggressive \ --maximize --oomable --verify --syslog \ --metrics --times --timeout 5m watchdog: CPU 15 Hard LOCKUP ...... NIP [c0000000000b78f4] queued_spin_lock_slowpath+0x1184/0x1490 LR [c000000001037c...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3j9c-cp7m-8w8g

больше 3 лет назад

Jenkins has XML External Entity (XXE) Vulnerability in Job Configuration via CLI

EPSS: Низкий
github логотип

GHSA-3j99-rpvr-7vpm

6 месяцев назад

A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3j98-rrxh-qmw6

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3j97-8r9f-j629

больше 1 года назад

Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3j96-q4p7-5h7v

больше 3 лет назад

Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j96-4r54-mhqg

больше 3 лет назад

The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3j96-2fmw-98f4

больше 3 лет назад

A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3j95-hrrj-gfw8

почти 4 года назад

statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3j9m-g8ph-73q2

Opera 10.50 allows remote attackers to obtain sensitive information via crafted XSLT constructs, which cause Opera to return cached contents of other pages.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3j9m-4q8w-cqcp

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 2.1.0. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.

CVSS3: 9.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3j9j-xcvh-87c7

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .

CVSS3: 9.8
2%
Низкий
около 2 лет назад
github логотип
GHSA-3j9j-89rj-v28w

CRLF injection vulnerability in (1) index.php and (2) admin.php in myWebland MyBloggie 2.1.3 allows remote attackers to hijack sessions and conduct cross-site scripting (XSS) attacks via a cookie.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3j9j-5462-cpx8

link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3j9j-2r36-985r

Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j9h-ppgw-76q9

Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter. in a GET request in view.cgi.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j9h-5r8r-rrxc

In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j9g-r75v-xgjr

Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j9f-c32h-wgj8

The Mindless Behavior Fan Base (aka com.mindless.behavior.fan.base) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j9f-7w24-pcqg

Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3j9f-4r3c-964g

In the Linux kernel, the following vulnerability has been resolved: powerpc/qspinlock: Fix deadlock in MCS queue If an interrupt occurs in queued_spin_lock_slowpath() after we increment qnodesp->count and before node->lock is initialized, another CPU might see stale lock values in get_tail_qnode(). If the stale lock value happens to match the lock on that CPU, then we write to the "next" pointer of the wrong qnode. This causes a deadlock as the former CPU, once it becomes the head of the MCS queue, will spin indefinitely until it's "next" pointer is set by its successor in the queue. Running stress-ng on a 16 core (16EC/16VP) shared LPAR, results in occasional lockups similar to the following: $ stress-ng --all 128 --vm-bytes 80% --aggressive \ --maximize --oomable --verify --syslog \ --metrics --times --timeout 5m watchdog: CPU 15 Hard LOCKUP ...... NIP [c0000000000b78f4] queued_spin_lock_slowpath+0x1184/0x1490 LR [c000000001037c...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3j9c-cp7m-8w8g

Jenkins has XML External Entity (XXE) Vulnerability in Job Configuration via CLI

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j99-rpvr-7vpm

A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3j98-rrxh-qmw6

Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j97-8r9f-j629

Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.5.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3j96-q4p7-5h7v

Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j96-4r54-mhqg

The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.

CVSS3: 8.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j96-2fmw-98f4

A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j95-hrrj-gfw8

statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.

93%
Критический
почти 4 года назад

Уязвимостей на страницу