Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3g2h-vfw2-43cp

больше 3 лет назад

Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Memcached.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3g2h-7hrx-ghf6

больше 1 года назад

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file customeradd.php. The manipulation of the argument fullname/address/phonenumber/sex/email/city/comment leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269805 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3g2g-x5j3-6xwc

больше 3 лет назад

apertium 3.0.7 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/#####.lex.cc, (b) /tmp/#####.deformat.l, (c) /tmp/#####.reformat.l, (d) /tmp/#####docxorig, (e) /tmp/#####docxsalida.zip, (f) /tmp/#####xlsxembed, (g) /tmp/#####xlsxorig, and (h) /tmp/#####xslxsalida.zip temporary files, related to the (1) apertium-gen-deformat, (2) apertium-gen-reformat, and (3) apertium scripts.

EPSS: Низкий
github логотип

GHSA-3g2g-rcm6-rrq2

около 3 лет назад

Cleartext Transmission of Sensitive Information in Jenkins JIRA Pipeline Steps Plugin

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g2g-jmh9-pfcp

10 месяцев назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to read or write to protected files.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g2f-v3cg-vqjp

больше 3 лет назад

A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.

EPSS: Низкий
github логотип

GHSA-3g2f-4rjg-9385

23 дня назад

Weblate leaks information via screenshots

EPSS: Низкий
github логотип

GHSA-3g2c-jgm5-pwjh

8 месяцев назад

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

EPSS: Низкий
github логотип

GHSA-3g29-4vmj-wp8h

больше 3 лет назад

Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

EPSS: Низкий
github логотип

GHSA-3g28-v7g2-x3c3

больше 3 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE API function, an array out-of-bounds index can occur.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g28-3cvr-qv6w

больше 3 лет назад

A vulnerability in the web-based management interface of Cisco DNA Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco DNA Center versions prior to 1.2.5 are affected.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g28-22mv-7m5h

почти 4 года назад

The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document.

EPSS: Низкий
github логотип

GHSA-3g27-fg6w-fm64

около 2 месяцев назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in sevenspark Contact Form 7 Dynamic Text Extension contact-form-7-dynamic-text-extension allows Code Injection.This issue affects Contact Form 7 Dynamic Text Extension: from n/a through <= 5.0.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3g26-4vjw-j4m6

больше 1 года назад

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3g26-4c95-5p36

около 2 лет назад

A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the component Admin Panel. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249778 is the identifier assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3g25-46v4-h26c

больше 3 лет назад

** DISPUTED ** Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 and CVE-2018-15907. NOTE: Technicolor denies that the described behavior is a vulnerability and states that Wi-Fi traffic is slowed or stopped only while the devices are exposed to a MAC flooding attack. This has been confirmed through testing against official up-to-date versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g24-rv7h-5xh5

больше 3 лет назад

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g24-mff9-8mv9

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->max_osd OSD indexes come from untrusted network packets. Boundary checks are added to validate these against map->max_osd. [ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic edits ]

EPSS: Низкий
github логотип

GHSA-3g24-jm9m-c47r

больше 3 лет назад

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.

EPSS: Низкий
github логотип

GHSA-3g24-4p5j-c5q8

больше 3 лет назад

An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g2h-vfw2-43cp

Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Memcached.

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g2h-7hrx-ghf6

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affects an unknown part of the file customeradd.php. The manipulation of the argument fullname/address/phonenumber/sex/email/city/comment leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269805 was assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3g2g-x5j3-6xwc

apertium 3.0.7 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/#####.lex.cc, (b) /tmp/#####.deformat.l, (c) /tmp/#####.reformat.l, (d) /tmp/#####docxorig, (e) /tmp/#####docxsalida.zip, (f) /tmp/#####xlsxembed, (g) /tmp/#####xlsxorig, and (h) /tmp/#####xslxsalida.zip temporary files, related to the (1) apertium-gen-deformat, (2) apertium-gen-reformat, and (3) apertium scripts.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g2g-rcm6-rrq2

Cleartext Transmission of Sensitive Information in Jenkins JIRA Pipeline Steps Plugin

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3g2g-jmh9-pfcp

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to read or write to protected files.

CVSS3: 9.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-3g2f-v3cg-vqjp

A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g2f-4rjg-9385

Weblate leaks information via screenshots

0%
Низкий
23 дня назад
github логотип
GHSA-3g2c-jgm5-pwjh

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

0%
Низкий
8 месяцев назад
github логотип
GHSA-3g29-4vmj-wp8h

Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g28-v7g2-x3c3

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE API function, an array out-of-bounds index can occur.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g28-3cvr-qv6w

A vulnerability in the web-based management interface of Cisco DNA Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco DNA Center versions prior to 1.2.5 are affected.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g28-22mv-7m5h

The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format (XSPF) document.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3g27-fg6w-fm64

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in sevenspark Contact Form 7 Dynamic Text Extension contact-form-7-dynamic-text-extension allows Code Injection.This issue affects Contact Form 7 Dynamic Text Extension: from n/a through <= 5.0.3.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3g26-4vjw-j4m6

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

CVSS3: 7.5
50%
Средний
больше 1 года назад
github логотип
GHSA-3g26-4c95-5p36

A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the component Admin Panel. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249778 is the identifier assigned to this vulnerability.

CVSS3: 7.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3g25-46v4-h26c

** DISPUTED ** Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 and CVE-2018-15907. NOTE: Technicolor denies that the described behavior is a vulnerability and states that Wi-Fi traffic is slowed or stopped only while the devices are exposed to a MAC flooding attack. This has been confirmed through testing against official up-to-date versions.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g24-rv7h-5xh5

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g24-mff9-8mv9

In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->max_osd OSD indexes come from untrusted network packets. Boundary checks are added to validate these against map->max_osd. [ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic edits ]

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3g24-jm9m-c47r

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g24-4p5j-c5q8

An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу