Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3f6m-j22w-8r7f

почти 4 года назад

ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.

EPSS: Низкий
github логотип

GHSA-3f6m-7jq2-3x7m

почти 4 года назад

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3f6j-r62c-wxpv

больше 3 лет назад

SQL injection vulnerability in the Moviebase addon for deV!L'z Clanportal (DZCP) 1.5.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a showkat action to index.php.

EPSS: Низкий
github логотип

GHSA-3f6j-jq37-282h

почти 3 года назад

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3f6j-956j-p8cx

почти 4 года назад

Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80).

EPSS: Низкий
github логотип

GHSA-3f6j-2cc7-x3qx

почти 4 года назад

Livingston portmaster machines could be rebooted via a series of commands.

EPSS: Низкий
github логотип

GHSA-3f6h-wmwv-m6rx

больше 3 лет назад

The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may allow for remote code execution. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0; 7.12.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Deployment Kit: versions up to and including 7.8.0; 7.9.0;7.9.1;7.10.0;7.10.1;7.11.0; 7.12.0, TIBCO Spotfire Desktop: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0;7.12.0, TIBCO Spotfire Desktop Language Packs: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f6h-6ch9-p8jv

больше 3 лет назад

libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.

EPSS: Низкий
github логотип

GHSA-3f6g-r82m-2vg5

почти 4 года назад

Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.

EPSS: Средний
github логотип

GHSA-3f6g-q6j8-gjpg

почти 4 года назад

Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.

EPSS: Средний
github логотип

GHSA-3f6g-m4hr-59h8

больше 1 года назад

OpenFGA Authorization Bypass

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3f6g-6p3h-q27p

почти 4 года назад

PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.

EPSS: Низкий
github логотип

GHSA-3f6c-mv48-pf3v

больше 3 лет назад

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3f6c-7fw2-ppm4

4 месяца назад

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3f69-xhq6-c8m8

больше 3 лет назад

Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3f69-f27h-f53w

больше 1 года назад

The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.

EPSS: Низкий
github логотип

GHSA-3f68-9fxg-g2j6

почти 4 года назад

The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.

EPSS: Низкий
github логотип

GHSA-3f67-9787-pwrh

около 3 лет назад

Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption situation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3f66-qjp3-gfq9

больше 3 лет назад

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511132; Issue ID: ALPS06511132.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3f66-mr9x-qch8

больше 2 лет назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gold Plugins Locations plugin <= 4.0 versions.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f6m-j22w-8r7f

ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3f6m-7jq2-3x7m

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3f6j-r62c-wxpv

SQL injection vulnerability in the Moviebase addon for deV!L'z Clanportal (DZCP) 1.5.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a showkat action to index.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f6j-jq37-282h

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS3: 7.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-3f6j-956j-p8cx

Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80).

2%
Низкий
почти 4 года назад
github логотип
GHSA-3f6j-2cc7-x3qx

Livingston portmaster machines could be rebooted via a series of commands.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3f6h-wmwv-m6rx

The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may allow for remote code execution. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0; 7.12.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Deployment Kit: versions up to and including 7.8.0; 7.9.0;7.9.1;7.10.0;7.10.1;7.11.0; 7.12.0, TIBCO Spotfire Desktop: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0;7.12.0, TIBCO Spotfire Desktop Language Packs: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3f6h-6ch9-p8jv

libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f6g-r82m-2vg5

Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.

65%
Средний
почти 4 года назад
github логотип
GHSA-3f6g-q6j8-gjpg

Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.

13%
Средний
почти 4 года назад
github логотип
GHSA-3f6g-m4hr-59h8

OpenFGA Authorization Bypass

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3f6g-6p3h-q27p

PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3f6c-mv48-pf3v

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.

CVSS3: 9.8
41%
Средний
больше 3 лет назад
github логотип
GHSA-3f6c-7fw2-ppm4

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-3f69-xhq6-c8m8

Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3f69-f27h-f53w

The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.

0%
Низкий
больше 1 года назад
github логотип
GHSA-3f68-9fxg-g2j6

The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3f67-9787-pwrh

Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption situation.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3f66-qjp3-gfq9

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511132; Issue ID: ALPS06511132.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f66-mr9x-qch8

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gold Plugins Locations plugin <= 4.0 versions.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу