Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3g5f-wchp-h22r

больше 3 лет назад

Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4160, CVE-2016-4161, CVE-2016-4162, and CVE-2016-4163.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g5f-h429-8r64

больше 3 лет назад

The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3g5c-7828-xwcq

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3g58-rjqp-pmgh

больше 1 года назад

A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3g58-gh82-frfm

больше 2 лет назад

Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 could allow a guest user to elevate to admin privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g57-r9p3-mh2v

около 4 лет назад

vim is vulnerable to Use After Free

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g57-8qrr-phw8

больше 3 лет назад

Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.

EPSS: Низкий
github логотип

GHSA-3g56-vx8v-f22v

около 1 года назад

Path Traversal: '.../...//' vulnerability in Softpulse Infotech SP Blog Designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through 1.0.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g56-2hh3-35ph

больше 3 лет назад

SoSReport Predictable Tmp File Names

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3g55-gxf8-m8xp

почти 3 года назад

HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g55-69j2-vxv7

больше 3 лет назад

Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.

EPSS: Низкий
github логотип

GHSA-3g53-xxcg-hv89

почти 4 года назад

The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.5), 8.3 before 8.3(2.22), 8.4 before 8.4(2.1), and 8.5 before 8.5(1.2) does not properly handle flows, which allows remote attackers to cause a denial of service (device reload) via a crafted series of (1) IPv4 or (2) IPv6 UDP packets, aka Bug ID CSCtq10441.

EPSS: Низкий
github логотип

GHSA-3g53-hh59-7f34

почти 4 года назад

Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.

EPSS: Низкий
github логотип

GHSA-3g53-3cmj-qjrh

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: pwm: lpc32xx: Remove handling of PWM channels Because LPC32xx PWM controllers have only a single output which is registered as the only PWM device/channel per controller, it is known in advance that pwm->hwpwm value is always 0. On basis of this fact simplify the code by removing operations with pwm->hwpwm, there is no controls which require channel number as input. Even though I wasn't aware at the time when I forward ported that patch, this fixes a null pointer dereference as lpc32xx->chip.pwms is NULL before devm_pwmchip_add() is called.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g52-xh39-r8h9

больше 3 лет назад

An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3g52-7jf9-68rg

4 месяца назад

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3g4x-5jfv-pg4g

5 месяцев назад

A vulnerability was detected in Campcodes Hospital Management System 1.0. This affects an unknown function of the file /admin/edit-doctor-specialization.php of the component Edit Doctor Specialization Page. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3g4x-5gh5-43g8

10 месяцев назад

ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, resulting in the product becoming vulnerable to interception.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3g4w-52x2-m37c

больше 3 лет назад

While loading dynamic fonts, a buffer overflow may occur if the number of segments in the font file is out of range in Snapdragon Mobile and Snapdragon Wear.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g4v-p46q-rp5h

больше 1 года назад

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g5f-wchp-h22r

Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1096, CVE-2016-1098, CVE-2016-1099, CVE-2016-1100, CVE-2016-1102, CVE-2016-1104, CVE-2016-4109, CVE-2016-4111, CVE-2016-4112, CVE-2016-4113, CVE-2016-4114, CVE-2016-4115, CVE-2016-4160, CVE-2016-4161, CVE-2016-4162, and CVE-2016-4163.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5f-h429-8r64

The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.

CVSS3: 9.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5c-7828-xwcq

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.

CVSS3: 9.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3g58-rjqp-pmgh

A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.

CVSS3: 9.8
18%
Средний
больше 1 года назад
github логотип
GHSA-3g58-gh82-frfm

Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 could allow a guest user to elevate to admin privileges.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3g57-r9p3-mh2v

vim is vulnerable to Use After Free

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3g57-8qrr-phw8

Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g56-vx8v-f22v

Path Traversal: '.../...//' vulnerability in Softpulse Infotech SP Blog Designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through 1.0.0.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3g56-2hh3-35ph

SoSReport Predictable Tmp File Names

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g55-gxf8-m8xp

HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails

CVSS3: 5.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-3g55-69j2-vxv7

Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g53-xxcg-hv89

The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.5), 8.3 before 8.3(2.22), 8.4 before 8.4(2.1), and 8.5 before 8.5(1.2) does not properly handle flows, which allows remote attackers to cause a denial of service (device reload) via a crafted series of (1) IPv4 or (2) IPv6 UDP packets, aka Bug ID CSCtq10441.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3g53-hh59-7f34

Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3g53-3cmj-qjrh

In the Linux kernel, the following vulnerability has been resolved: pwm: lpc32xx: Remove handling of PWM channels Because LPC32xx PWM controllers have only a single output which is registered as the only PWM device/channel per controller, it is known in advance that pwm->hwpwm value is always 0. On basis of this fact simplify the code by removing operations with pwm->hwpwm, there is no controls which require channel number as input. Even though I wasn't aware at the time when I forward ported that patch, this fixes a null pointer dereference as lpc32xx->chip.pwms is NULL before devm_pwmchip_add() is called.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3g52-xh39-r8h9

An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g52-7jf9-68rg

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-3g4x-5jfv-pg4g

A vulnerability was detected in Campcodes Hospital Management System 1.0. This affects an unknown function of the file /admin/edit-doctor-specialization.php of the component Edit Doctor Specialization Page. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

CVSS3: 4.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3g4x-5gh5-43g8

ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, resulting in the product becoming vulnerable to interception.

CVSS3: 8
0%
Низкий
10 месяцев назад
github логотип
GHSA-3g4w-52x2-m37c

While loading dynamic fonts, a buffer overflow may occur if the number of segments in the font file is out of range in Snapdragon Mobile and Snapdragon Wear.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g4v-p46q-rp5h

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 4.7
0%
Низкий
больше 1 года назад

Уязвимостей на страницу