Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3ggr-5p57-2xgh

больше 1 года назад

The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the firmware and is freely available for download. This allows crafting malicious "signed" .patch files in order to compromise the device and execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3ggq-p922-54qp

больше 3 лет назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., throug...

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3ggp-43f5-88mv

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UIUX Lab Uix Shortcodes allows Stored XSS. This issue affects Uix Shortcodes: from n/a through 2.0.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3ggj-v8pg-xq6f

больше 3 лет назад

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3ggj-ffgc-7jg6

больше 3 лет назад

In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ggh-w4r5-27j4

больше 3 лет назад

An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3ggh-v6pr-hc9h

почти 4 года назад

GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

EPSS: Низкий
github логотип

GHSA-3ggh-h43h-cwc6

больше 3 лет назад

The advanced-custom-fields plugin before 5.7.8 for WordPress has XSS by authors.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3ggg-wrvv-9653

почти 4 года назад

na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 allows local users to gain Unix shell access via "`" (backtick) characters in the appliance's command line interface (CLI).

EPSS: Низкий
github логотип

GHSA-3ggg-9h5p-h885

больше 3 лет назад

The Shop Love (aka com.waterwish.shoplove) application 1.05 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3ggf-rp75-jh9p

7 месяцев назад

A vulnerability classified as critical was found in code-projects Jonnys Liquor 1.0. This vulnerability affects unknown code of the file /admin/admin-area.php. The manipulation of the argument drink leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3ggc-vmxq-jvr2

больше 3 лет назад

Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to bypass intended FontValidator sandbox-policy restrictions and execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3ggc-v7xp-4343

6 дней назад

IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3gg9-xvf5-p5wm

больше 3 лет назад

GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3gg9-g25v-rjf5

около 1 года назад

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gg9-f3vh-866f

почти 4 года назад

Improper Certificate Validation in Graylog

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3gg9-8j69-7cv4

больше 3 лет назад

In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3gg8-mc87-cq3h

почти 2 года назад

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3gg7-v77p-8v9j

почти 4 года назад

Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.

EPSS: Низкий
github логотип

GHSA-3gg7-9q2x-79fc

почти 6 лет назад

Improper Restriction of Rendered UI Layers or Frames in Keycloak

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3ggr-5p57-2xgh

The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the firmware and is freely available for download. This allows crafting malicious "signed" .patch files in order to compromise the device and execute arbitrary code.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3ggq-p922-54qp

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., throug...

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ggp-43f5-88mv

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UIUX Lab Uix Shortcodes allows Stored XSS. This issue affects Uix Shortcodes: from n/a through 2.0.4.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3ggj-v8pg-xq6f

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ggj-ffgc-7jg6

In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ggh-w4r5-27j4

An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ggh-v6pr-hc9h

GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3ggh-h43h-cwc6

The advanced-custom-fields plugin before 5.7.8 for WordPress has XSS by authors.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ggg-wrvv-9653

na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 allows local users to gain Unix shell access via "`" (backtick) characters in the appliance's command line interface (CLI).

0%
Низкий
почти 4 года назад
github логотип
GHSA-3ggg-9h5p-h885

The Shop Love (aka com.waterwish.shoplove) application 1.05 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ggf-rp75-jh9p

A vulnerability classified as critical was found in code-projects Jonnys Liquor 1.0. This vulnerability affects unknown code of the file /admin/admin-area.php. The manipulation of the argument drink leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3ggc-vmxq-jvr2

Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to bypass intended FontValidator sandbox-policy restrictions and execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ggc-v7xp-4343

IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.

CVSS3: 7.6
0%
Низкий
6 дней назад
github логотип
GHSA-3gg9-xvf5-p5wm

GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gg9-g25v-rjf5

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS3: 6.5
1%
Низкий
около 1 года назад
github логотип
GHSA-3gg9-f3vh-866f

Improper Certificate Validation in Graylog

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-3gg9-8j69-7cv4

In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gg8-mc87-cq3h

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider

CVSS3: 2.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-3gg7-v77p-8v9j

Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3gg7-9q2x-79fc

Improper Restriction of Rendered UI Layers or Frames in Keycloak

0%
Низкий
почти 6 лет назад

Уязвимостей на страницу