Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3fq5-m2m4-f2qw

больше 3 лет назад

In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack an end user could read files on the host system that the BOSH-created vcap user has permissions to read and then package them into their app droplet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3fq5-c2gj-gmqj

больше 3 лет назад

The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3fq5-562h-h369

больше 3 лет назад

ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled database and to force Log360 to restart. An attacker can leverage this vulnerability to achieve remote code execution by replacing files executed by Log360 on startup.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3fq5-2xw2-2v7v

больше 3 лет назад

University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated Reflected XSS vulnerability. This has been fixed in the version 19.2

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3fq4-ww3p-x6v2

больше 3 лет назад

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3fq4-qf4h-j7fg

больше 3 лет назад

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3fq4-h97c-g9vv

больше 3 лет назад

IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3fq4-7v27-7g49

около 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18630.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3fq3-m842-mpf8

больше 3 лет назад

The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.

EPSS: Низкий
github логотип

GHSA-3fq2-5669-f3x9

больше 3 лет назад

The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: Низкий
github логотип

GHSA-3fpx-q477-fj97

почти 4 года назад

Unspecified vulnerability in class/theme.class.php in SPAW Editor PHP Edition before 2.0.8.1 has unknown impact and attack vectors, probably related to directory traversal sequences in the theme name.

EPSS: Низкий
github логотип

GHSA-3fpx-g9h3-hh8x

больше 3 лет назад

Jenkins NeuVector Vulnerability Scanner Plugin stored credentials in plain text

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3fpx-64j2-m33g

6 месяцев назад

A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file /auth/delete_project/ of the component Delete Request Handler. The manipulation of the argument projectID leads to missing authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3fpx-4c54-q88f

12 месяцев назад

A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the function sprintf of the file epsdaemon of the component Autoscan USB. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3fpv-rr32-pwqw

почти 4 года назад

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fpv-54ff-wqfj

почти 4 года назад

Deserialization of Untrusted Data in topthink/framework

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3fpr-96rf-fw9f

больше 3 лет назад

Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element.

EPSS: Низкий
github логотип

GHSA-3fpr-88w3-v99m

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: team: prevent adding a device which is already a team device lower Prevent adding a device which is already a team device lower, e.g. adding veth0 if vlan1 was already added and veth0 is a lower of vlan1. This is not useful in practice and can lead to recursive locking: $ ip link add veth0 type veth peer name veth1 $ ip link set veth0 up $ ip link set veth1 up $ ip link add link veth0 name veth0.1 type vlan protocol 802.1Q id 1 $ ip link add team0 type team $ ip link set veth0.1 down $ ip link set veth0.1 master team0 team0: Port device veth0.1 added $ ip link set veth0 down $ ip link set veth0 master team0 ============================================ WARNING: possible recursive locking detected 6.13.0-rc2-virtme-00441-ga14a429069bb #46 Not tainted -------------------------------------------- ip/7684 is trying to acquire lock: ffff888016848e00 (team->team_lock_key){+.+.}-{4:4}, at: team_device_event (drivers/ne...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3fpr-5fgv-65vg

больше 1 года назад

InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3fpm-hp83-g34v

больше 3 лет назад

Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3fq5-m2m4-f2qw

In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack an end user could read files on the host system that the BOSH-created vcap user has permissions to read and then package them into their app droplet.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq5-c2gj-gmqj

The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq5-562h-h369

ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled database and to force Log360 to restart. An attacker can leverage this vulnerability to achieve remote code execution by replacing files executed by Log360 on startup.

CVSS3: 9.8
31%
Средний
больше 3 лет назад
github логотип
GHSA-3fq5-2xw2-2v7v

University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated Reflected XSS vulnerability. This has been fixed in the version 19.2

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq4-ww3p-x6v2

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq4-qf4h-j7fg

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq4-h97c-g9vv

IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq4-7v27-7g49

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18630.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3fq3-m842-mpf8

The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq2-5669-f3x9

The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fpx-q477-fj97

Unspecified vulnerability in class/theme.class.php in SPAW Editor PHP Edition before 2.0.8.1 has unknown impact and attack vectors, probably related to directory traversal sequences in the theme name.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3fpx-g9h3-hh8x

Jenkins NeuVector Vulnerability Scanner Plugin stored credentials in plain text

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fpx-64j2-m33g

A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file /auth/delete_project/ of the component Delete Request Handler. The manipulation of the argument projectID leads to missing authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-3fpx-4c54-q88f

A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the function sprintf of the file epsdaemon of the component Autoscan USB. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-3fpv-rr32-pwqw

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3fpv-54ff-wqfj

Deserialization of Untrusted Data in topthink/framework

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-3fpr-96rf-fw9f

Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fpr-88w3-v99m

In the Linux kernel, the following vulnerability has been resolved: team: prevent adding a device which is already a team device lower Prevent adding a device which is already a team device lower, e.g. adding veth0 if vlan1 was already added and veth0 is a lower of vlan1. This is not useful in practice and can lead to recursive locking: $ ip link add veth0 type veth peer name veth1 $ ip link set veth0 up $ ip link set veth1 up $ ip link add link veth0 name veth0.1 type vlan protocol 802.1Q id 1 $ ip link add team0 type team $ ip link set veth0.1 down $ ip link set veth0.1 master team0 team0: Port device veth0.1 added $ ip link set veth0 down $ ip link set veth0 master team0 ============================================ WARNING: possible recursive locking detected 6.13.0-rc2-virtme-00441-ga14a429069bb #46 Not tainted -------------------------------------------- ip/7684 is trying to acquire lock: ffff888016848e00 (team->team_lock_key){+.+.}-{4:4}, at: team_device_event (drivers/ne...

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3fpr-5fgv-65vg

InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3fpm-hp83-g34v

Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу