Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3gwj-28p7-3v2r

почти 4 года назад

The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3gwg-rh47-h7p4

около 1 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Activity Shortcode allows Stored XSS.This issue affects BuddyPress Activity Shortcode: from n/a through 1.1.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gwg-p922-8p2m

больше 1 года назад

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3gwf-whf9-4x6h

почти 4 года назад

The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that rely on secrecy of those values.

EPSS: Низкий
github логотип

GHSA-3gwf-mm38-qg2j

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2015-4906 and CVE-2015-4908.

EPSS: Низкий
github логотип

GHSA-3gwf-437g-7hgf

почти 4 года назад

Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JBIG2 stream in a PDF file, leading to a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-3gwc-4hxr-w9w6

4 месяца назад

Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MDTF: from n/a through <= 1.3.3.9.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3gw9-qxrf-m4p6

8 месяцев назад

A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-3gw9-qvrp-jvcf

больше 3 лет назад

The LIFE TIME FITNESS (aka com.lifetimefitness.ltfmobile) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3gw8-xrcq-5xfv

больше 3 лет назад

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write to the logs of that app.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3gw8-cfcr-c4jc

больше 3 лет назад

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerabilities are due to the affected software improperly sanitizing command arguments to prevent access to internal data structures on a device. An attacker who has user EXEC mode (privilege level 1) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain crafted arguments. A successful exploit could allow the attacker to gain access to the underlying Linux shell of the affected device and execute arbitrary commands with root privileges on the device. Cisco Bug IDs: CSCtw85441, CSCus42252, CSCuv95370.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3gw8-89v6-jfv4

больше 3 лет назад

Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve arbitrary files from the device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3gw7-cqr8-xq7q

больше 3 лет назад

Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data without the viewing privilege.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gw6-fj56-vc35

почти 2 года назад

An remote attacker with low privileges can perform a command injection which can lead to root access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3gw6-8wwv-rhr2

больше 3 лет назад

Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3gw5-g9jg-7w5w

2 месяца назад

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to render the Administrator password in plaintext.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3gw4-wpf3-6rhr

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote attackers to inject arbitrary web script or HTML via tasklists.

EPSS: Низкий
github логотип

GHSA-3gw4-m5w7-v89c

больше 5 лет назад

Uncontrolled Resource Consumption in Indy Node

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3gw4-9fq5-6jf9

больше 3 лет назад

In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3gw4-7rm8-f8jr

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gwj-28p7-3v2r

The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3gwg-rh47-h7p4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Activity Shortcode allows Stored XSS.This issue affects BuddyPress Activity Shortcode: from n/a through 1.1.8.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3gwg-p922-8p2m

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3gwf-whf9-4x6h

The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that rely on secrecy of those values.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3gwf-mm38-qg2j

Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2015-4906 and CVE-2015-4908.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gwf-437g-7hgf

Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JBIG2 stream in a PDF file, leading to a heap-based buffer overflow.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3gwc-4hxr-w9w6

Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MDTF: from n/a through <= 1.3.3.9.

CVSS3: 8.2
0%
Низкий
4 месяца назад
github логотип
GHSA-3gw9-qxrf-m4p6

A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * OTRS 2025.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

CVSS3: 3.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-3gw9-qvrp-jvcf

The LIFE TIME FITNESS (aka com.lifetimefitness.ltfmobile) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gw8-xrcq-5xfv

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write to the logs of that app.

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gw8-cfcr-c4jc

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerabilities are due to the affected software improperly sanitizing command arguments to prevent access to internal data structures on a device. An attacker who has user EXEC mode (privilege level 1) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain crafted arguments. A successful exploit could allow the attacker to gain access to the underlying Linux shell of the affected device and execute arbitrary commands with root privileges on the device. Cisco Bug IDs: CSCtw85441, CSCus42252, CSCuv95370.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gw8-89v6-jfv4

Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve arbitrary files from the device.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3gw7-cqr8-xq7q

Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data without the viewing privilege.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gw6-fj56-vc35

An remote attacker with low privileges can perform a command injection which can lead to root access.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3gw6-8wwv-rhr2

Exim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete arbitrary files as root. This involves the -oP and -oPX options.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gw5-g9jg-7w5w

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to render the Administrator password in plaintext.

CVSS3: 5.7
0%
Низкий
2 месяца назад
github логотип
GHSA-3gw4-wpf3-6rhr

Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote attackers to inject arbitrary web script or HTML via tasklists.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3gw4-m5w7-v89c

Uncontrolled Resource Consumption in Indy Node

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-3gw4-9fq5-6jf9

In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gw4-7rm8-f8jr

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
5%
Низкий
больше 3 лет назад

Уязвимостей на страницу