Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3h32-9hq6-4rcq

больше 3 лет назад

The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h32-4mhh-8v2f

больше 3 лет назад

The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact by leveraging improper interaction with the vp3_h_loop_filter_c function in libavcodec/vp3dsp.c in FFmpeg.

EPSS: Низкий
github логотип

GHSA-3h2x-f5p6-82hc

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h2x-cpjg-qq3m

больше 3 лет назад

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, the HLOS can gain access to unauthorized memory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h2w-7wcr-vq95

больше 3 лет назад

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.

EPSS: Низкий
github логотип

GHSA-3h2w-68px-r4v5

3 месяца назад

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit:  https://github.com/apache/apisix/pull/12629 Users are recommended to upgrade to version 3.14, which fixes this issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h2w-5hmv-xgqc

больше 3 лет назад

CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2v-h2q9-f9r6

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix possible NULL pointer dereference in wfx_set_mfp_ap() Since 'ieee80211_beacon_get()' can return NULL, 'wfx_set_mfp_ap()' should check the return value before examining skb data. So convert the latter to return an appropriate error code and propagate it to return from 'wfx_start_ap()' as well. Compile tested only.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h2r-mh7w-gr5w

больше 3 лет назад

Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h2r-h2x2-mg4h

больше 2 лет назад

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3h2r-57j7-jcpg

почти 4 года назад

In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-202006191References: N/A

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3h2r-2233-77cq

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2q-m63q-9cf6

больше 3 лет назад

Missing permission check in Perfecto Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3h2q-4qw3-2f5h

больше 3 лет назад

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3h2m-jjrw-87hw

больше 3 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2j-h4g8-5pmr

почти 4 года назад

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h2j-95j8-599v

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.

EPSS: Низкий
github логотип

GHSA-3h2h-xqr2-2jp7

почти 4 года назад

Cross-site Scripting (XSS) in Apache ActiveMQ Artemis

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h2h-j4vg-8xm8

около 2 лет назад

An issue in Notion for macOS version 3.1.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h2h-fwxh-x5w9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h32-9hq6-4rcq

The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h32-4mhh-8v2f

The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact by leveraging improper interaction with the vp3_h_loop_filter_c function in libavcodec/vp3dsp.c in FFmpeg.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2x-f5p6-82hc

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2x-cpjg-qq3m

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, the HLOS can gain access to unauthorized memory.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2w-7wcr-vq95

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2w-68px-r4v5

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit:  https://github.com/apache/apisix/pull/12629 Users are recommended to upgrade to version 3.14, which fixes this issue.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3h2w-5hmv-xgqc

CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2v-h2q9-f9r6

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix possible NULL pointer dereference in wfx_set_mfp_ap() Since 'ieee80211_beacon_get()' can return NULL, 'wfx_set_mfp_ap()' should check the return value before examining skb data. So convert the latter to return an appropriate error code and propagate it to return from 'wfx_start_ap()' as well. Compile tested only.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3h2r-mh7w-gr5w

Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2r-h2x2-mg4h

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.

CVSS3: 2.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3h2r-57j7-jcpg

In the TitanM chip, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-202006191References: N/A

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-3h2r-2233-77cq

Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3h2q-m63q-9cf6

Missing permission check in Perfecto Plugin

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2q-4qw3-2f5h

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2m-jjrw-87hw

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2j-h4g8-5pmr

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3h2j-95j8-599v

Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2h-xqr2-2jp7

Cross-site Scripting (XSS) in Apache ActiveMQ Artemis

CVSS3: 6.1
3%
Низкий
почти 4 года назад
github логотип
GHSA-3h2h-j4vg-8xm8

An issue in Notion for macOS version 3.1.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3h2h-fwxh-x5w9

Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."

7%
Низкий
больше 3 лет назад

Уязвимостей на страницу