Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3hx8-jcjc-x9xm

12 месяцев назад

A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hx8-92xp-7g4r

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUserStateFromRequest function, and the (2) SEF and (3) com_messages modules.

EPSS: Низкий
github логотип

GHSA-3hx8-6m94-fm2x

почти 4 года назад

Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.

EPSS: Средний
github логотип

GHSA-3hx8-4hp2-whqv

больше 2 лет назад

A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hx8-25m4-f73q

почти 2 года назад

Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3hx6-fqpj-xfjr

больше 3 лет назад

RichFaces vulnerable to Expression Language Injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hx6-cm77-2752

больше 3 лет назад

libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.

EPSS: Низкий
github логотип

GHSA-3hx6-3qqx-qhvf

11 месяцев назад

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation Manager (BSM) before 1.1-65374, Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hx4-h4gp-2jhp

больше 3 лет назад

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27777501.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hx4-77f4-g7cp

больше 3 лет назад

BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hx4-75gf-pcm8

6 дней назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaViewer: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3hx4-285w-v6mm

больше 3 лет назад

Jenkins Project Inheritance Plugin vulnerable to cross site scripting

CVSS3: 8
EPSS: Средний
github логотип

GHSA-3hx3-v4g2-hgqp

больше 3 лет назад

Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hx3-6qpf-m689

около 3 лет назад

CVE was unused by HPE.

EPSS: Низкий
github логотип

GHSA-3hwx-vc7v-fw2m

около 4 лет назад

Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hwx-j4f5-4679

почти 2 года назад

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This makes it possible for authenticated attackers, with contributor access or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hwx-c6cp-q972

больше 3 лет назад

Publify vulnerable to cross site scripting

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3hww-w3cw-c9cm

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block allows DOM-Based XSS. This issue affects Hyperlink Group Block: from n/a through 2.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hww-45xr-whm4

больше 2 лет назад

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3hwv-x5p9-3h2h

больше 3 лет назад

In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222289114

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hx8-jcjc-x9xm

A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-3hx8-92xp-7g4r

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUserStateFromRequest function, and the (2) SEF and (3) com_messages modules.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3hx8-6m94-fm2x

Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.

32%
Средний
почти 4 года назад
github логотип
GHSA-3hx8-4hp2-whqv

A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3hx8-25m4-f73q

Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.

CVSS3: 7.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-3hx6-fqpj-xfjr

RichFaces vulnerable to Expression Language Injection

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3hx6-cm77-2752

libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hx6-3qqx-qhvf

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation Manager (BSM) before 1.1-65374, Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-3hx4-h4gp-2jhp

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27777501.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hx4-77f4-g7cp

BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.

CVSS3: 7.5
8%
Низкий
больше 3 лет назад
github логотип
GHSA-3hx4-75gf-pcm8

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaViewer: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.

CVSS3: 4.7
0%
Низкий
6 дней назад
github логотип
GHSA-3hx4-285w-v6mm

Jenkins Project Inheritance Plugin vulnerable to cross site scripting

CVSS3: 8
14%
Средний
больше 3 лет назад
github логотип
GHSA-3hx3-v4g2-hgqp

Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hx3-6qpf-m689

CVE was unused by HPE.

около 3 лет назад
github логотип
GHSA-3hwx-vc7v-fw2m

Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3hwx-j4f5-4679

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This makes it possible for authenticated attackers, with contributor access or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 8.8
10%
Низкий
почти 2 года назад
github логотип
GHSA-3hwx-c6cp-q972

Publify vulnerable to cross site scripting

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hww-w3cw-c9cm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block allows DOM-Based XSS. This issue affects Hyperlink Group Block: from n/a through 2.0.1.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3hww-45xr-whm4

In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hwv-x5p9-3h2h

In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222289114

CVSS3: 3.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу