Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3h5v-q93c-6h6q

больше 1 года назад

ws affected by a DoS when handling a request with many HTTP headers

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h5v-53qj-h7p2

около 1 года назад

Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h5r-qj9r-h77r

больше 1 года назад

The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the nm_vistior page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h5r-928v-mxhh

почти 5 лет назад

Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-3h5q-gg6w-2g7p

больше 3 лет назад

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

EPSS: Низкий
github логотип

GHSA-3h5q-3j8q-4rm9

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

EPSS: Средний
github логотип

GHSA-3h5p-pg4g-m6gv

больше 1 года назад

A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the CsrRequestView class. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of a10user. Was ZDI-CAN-22517.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h5p-hx2f-x27c

больше 1 года назад

Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h5p-423v-vjw8

почти 4 года назад

Directory traversal vulnerability in download.cgi in EZFactory KDDI Download CGI 1.x allows remote attackers to read and download arbitrary files via a .. (dot dot) in the name parameter.

EPSS: Низкий
github логотип

GHSA-3h5m-h2xr-8j2p

9 месяцев назад

The 4stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the stats/stats.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h5j-qwmx-f9m6

больше 3 лет назад

The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h5j-fwx4-2458

больше 3 лет назад

An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3h5j-cjch-v685

больше 3 лет назад

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h5j-7g67-p37p

больше 3 лет назад

A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is the function dnxhd_init_rc of the file libavcodec/dnxhdenc.c. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h5h-7279-36j5

больше 3 лет назад

Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h5g-rhxf-84j5

больше 3 лет назад

Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-35774, CVE-2022-35775, CVE-2022-35780, CVE-2022-35781, CVE-2022-35782, CVE-2022-35783, CVE-2022-35784, CVE-2022-35785, CVE-2022-35786, CVE-2022-35787, CVE-2022-35788, CVE-2022-35789, CVE-2022-35790, CVE-2022-35791, CVE-2022-35799, CVE-2022-35800, CVE-2022-35801, CVE-2022-35802, CVE-2022-35808, CVE-2022-35809, CVE-2022-35810, CVE-2022-35811, CVE-2022-35812, CVE-2022-35813, CVE-2022-35814, CVE-2022-35815, CVE-2022-35816, CVE-2022-35817, CVE-2022-35818, CVE-2022-35819.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h5g-cg8f-5hwj

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: sof_es8336: fix possible use-after-free in sof_es8336_remove() sof_es8336_remove() calls cancel_delayed_work(). However, that function does not wait until the work function finishes. This means that the callback function may still be running after the driver's remove function has finished, which would result in a use-after-free. Fix by calling cancel_delayed_work_sync(), which ensures that the work is properly cancelled, no longer running, and unable to re-schedule itself.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3h5f-xp24-j3p4

почти 2 года назад

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3h5f-872v-9pwg

больше 2 лет назад

Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vulnerability via the deviceId parameter in the Parental Control module.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3h5c-v4x2-h5xf

почти 4 года назад

Use After Free in NPM radare2.js prior to 5.6.2.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h5v-q93c-6h6q

ws affected by a DoS when handling a request with many HTTP headers

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3h5v-53qj-h7p2

Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3h5r-qj9r-h77r

The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the nm_vistior page.

CVSS3: 7.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-3h5r-928v-mxhh

Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11

CVSS3: 2.6
почти 5 лет назад
github логотип
GHSA-3h5q-gg6w-2g7p

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h5q-3j8q-4rm9

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

37%
Средний
почти 4 года назад
github логотип
GHSA-3h5p-pg4g-m6gv

A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the CsrRequestView class. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of a10user. Was ZDI-CAN-22517.

CVSS3: 7.2
5%
Низкий
больше 1 года назад
github логотип
GHSA-3h5p-hx2f-x27c

Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3h5p-423v-vjw8

Directory traversal vulnerability in download.cgi in EZFactory KDDI Download CGI 1.x allows remote attackers to read and download arbitrary files via a .. (dot dot) in the name parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3h5m-h2xr-8j2p

The 4stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the stats/stats.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-3h5j-qwmx-f9m6

The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call.

CVSS3: 5.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-3h5j-fwx4-2458

An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h5j-cjch-v685

A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h5j-7g67-p37p

A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is the function dnxhd_init_rc of the file libavcodec/dnxhdenc.c. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h5h-7279-36j5

Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h5g-rhxf-84j5

Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-35774, CVE-2022-35775, CVE-2022-35780, CVE-2022-35781, CVE-2022-35782, CVE-2022-35783, CVE-2022-35784, CVE-2022-35785, CVE-2022-35786, CVE-2022-35787, CVE-2022-35788, CVE-2022-35789, CVE-2022-35790, CVE-2022-35791, CVE-2022-35799, CVE-2022-35800, CVE-2022-35801, CVE-2022-35802, CVE-2022-35808, CVE-2022-35809, CVE-2022-35810, CVE-2022-35811, CVE-2022-35812, CVE-2022-35813, CVE-2022-35814, CVE-2022-35815, CVE-2022-35816, CVE-2022-35817, CVE-2022-35818, CVE-2022-35819.

CVSS3: 6.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3h5g-cg8f-5hwj

In the Linux kernel, the following vulnerability has been resolved: ASoC: sof_es8336: fix possible use-after-free in sof_es8336_remove() sof_es8336_remove() calls cancel_delayed_work(). However, that function does not wait until the work function finishes. This means that the callback function may still be running after the driver's remove function has finished, which would result in a use-after-free. Fix by calling cancel_delayed_work_sync(), which ensures that the work is properly cancelled, no longer running, and unable to re-schedule itself.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3h5f-xp24-j3p4

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3h5f-872v-9pwg

Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vulnerability via the deviceId parameter in the Parental Control module.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3h5c-v4x2-h5xf

Use After Free in NPM radare2.js prior to 5.6.2.

CVSS3: 7.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу