Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3hjq-hp4g-45vg

больше 3 лет назад

Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hjq-h4pf-jcj9

больше 3 лет назад

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM 5.5.48 devices. Attackers can use the ZigBee trust center rejoin procedure to perform a denial of service attack.

EPSS: Низкий
github логотип

GHSA-3hjp-xhcw-gh99

больше 3 лет назад

Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.

EPSS: Низкий
github логотип

GHSA-3hjp-j522-245f

больше 1 года назад

Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3hjp-8vmr-crg9

6 месяцев назад

The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo data into the site.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hjp-23xj-gxx4

больше 3 лет назад

Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plaint text private keys of system's builtin local certificates via unsetting the keys encryption password in FortiOS 6.2.0, 6.0.0 to 6.0.6, 5.6.10 and below or for user uploaded local certificates via setting an empty password in FortiOS 6.2.1, 6.2.0, 6.0.6 and below.

EPSS: Низкий
github логотип

GHSA-3hjm-w3jh-pc36

больше 1 года назад

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could potentially exploit this vulnerability leading to a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hjm-7xr7-8fgf

больше 3 лет назад

The sigalgs implementation in t1_lib.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by using an invalid signature_algorithms extension in the ClientHello message during a renegotiation.

EPSS: Средний
github логотип

GHSA-3hjj-hrqp-h46r

больше 3 лет назад

Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.

EPSS: Низкий
github логотип

GHSA-3hjj-hrcp-g8r3

больше 3 лет назад

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8756, and CVE-2017-11764.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-3hjj-h6rj-vfvf

больше 3 лет назад

The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hjh-r8jh-f6p4

почти 4 года назад

Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3hjh-p587-3c92

больше 2 лет назад

A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0. This affects an unknown part of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3hjh-jh2h-vrg6

больше 1 года назад

Denial of service in langchain-community

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3hjh-cjx8-8c83

6 месяцев назад

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hjh-9vcg-w788

больше 3 лет назад

libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hjh-72vp-2mx6

больше 3 лет назад

The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.

EPSS: Низкий
github логотип

GHSA-3hjh-5hgx-f5wh

почти 3 года назад

Path traversal vulnerability in glance

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hjh-36cf-mgj5

6 месяцев назад

Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3hjg-vc7r-rcrw

почти 4 года назад

Denial of Service vulnerability in @podium/layout and @podium/proxy

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hjq-hp4g-45vg

Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjq-h4pf-jcj9

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM 5.5.48 devices. Attackers can use the ZigBee trust center rejoin procedure to perform a denial of service attack.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjp-xhcw-gh99

Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjp-j522-245f

Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hjp-8vmr-crg9

The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo data into the site.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3hjp-23xj-gxx4

Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plaint text private keys of system's builtin local certificates via unsetting the keys encryption password in FortiOS 6.2.0, 6.0.0 to 6.0.6, 5.6.10 and below or for user uploaded local certificates via setting an empty password in FortiOS 6.2.1, 6.2.0, 6.0.6 and below.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjm-w3jh-pc36

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could potentially exploit this vulnerability leading to a denial of service.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3hjm-7xr7-8fgf

The sigalgs implementation in t1_lib.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by using an invalid signature_algorithms extension in the ClientHello message during a renegotiation.

18%
Средний
больше 3 лет назад
github логотип
GHSA-3hjj-hrqp-h46r

Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjj-hrcp-g8r3

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8756, and CVE-2017-11764.

CVSS3: 7.5
77%
Высокий
больше 3 лет назад
github логотип
GHSA-3hjj-h6rj-vfvf

The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjh-r8jh-f6p4

Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

7%
Низкий
почти 4 года назад
github логотип
GHSA-3hjh-p587-3c92

A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0. This affects an unknown part of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hjh-jh2h-vrg6

Denial of service in langchain-community

CVSS3: 4.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hjh-cjx8-8c83

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3hjh-9vcg-w788

libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjh-72vp-2mx6

The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjh-5hgx-f5wh

Path traversal vulnerability in glance

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3hjh-36cf-mgj5

Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

CVSS3: 4.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-3hjg-vc7r-rcrw

Denial of Service vulnerability in @podium/layout and @podium/proxy

CVSS3: 7.5
1%
Низкий
почти 4 года назад

Уязвимостей на страницу