Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3fjm-4hqx-7gf9

больше 3 лет назад

Use after free in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fjj-qfv3-f9fj

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition before 5.0.a allows remote attackers to hijack the authentication of users for requests that access unauthorized URLs and obtain user credentials via a URL in the url parameter.

EPSS: Низкий
github логотип

GHSA-3fjj-p79j-c9hh

около 3 лет назад

Fastify: Incorrect Content-Type parsing can lead to CSRF attack

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3fjh-6fwj-4f8v

5 дней назад

Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side script execution.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3fjh-5fm6-fqmw

больше 3 лет назад

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3fjh-3qmq-p25v

больше 3 лет назад

A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to the health monitor API on an affected device. The vulnerability is due to inadequate provisioning of kernel parameters for the maximum number of TCP connections and SYN backlog. An attacker could exploit this vulnerability by sending a flood of crafted TCP packets to an affected device. A successful exploit could allow the attacker to block TCP listening ports that are used by the health monitor API. This vulnerability only affects customers who use the health monitor API.

EPSS: Низкий
github логотип

GHSA-3fjh-2rcv-9cfc

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Cleanup after an allocation error When allocation failures are not cleaned up by the driver, further allocation errors will be false-positives, which will cause buffers to remain uninitialized and cause NULL pointer dereferences. Ensure proper cleanup of failed allocations to prevent these issues.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3fjf-xcfg-59v3

больше 1 года назад

The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke this functionality intended for admin users. This enables subscribers to manage field groups, change visibility of items among other things.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3fjf-pgq8-c45w

почти 4 года назад

SQL injection vulnerability in index.php in Maian Greeting 2.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action.

EPSS: Низкий
github логотип

GHSA-3fjf-jf49-wrvp

около 1 года назад

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the function cn_update of the file /_parse/_all_edits.php. The manipulation of the argument cname/url leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3fjc-xv2v-jr9v

почти 4 года назад

Vulnerability in administration server for HP VirtualVault 4.5 on HP-UX 11.04 allows remote web servers or privileged external processes to bypass access restrictions and establish connections to the server.

EPSS: Низкий
github логотип

GHSA-3fjc-qmr3-wfpw

больше 3 лет назад

Unspecified vulnerability in the Spatial component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3fjc-pjgm-cw7f

больше 1 года назад

Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a crafted script.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3fjc-9f6x-jrfx

больше 3 лет назад

Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted mb_strcut call.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3fjc-956c-32mf

около 2 лет назад

The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat actor to insert a PCI card designed for memory capture. A threat actor can then isolate sensitive information such as a BitLocker encryption key from a dump of the workstation RAM during startup.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-3fj9-rv52-g5r6

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: udf: Fix preallocation discarding at indirect extent boundary When preallocation extent is the first one in the extent block, the code would corrupt extent tree header instead. Fix the problem and use udf_delete_aext() for deleting extent to avoid some code duplication.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3fj9-c88m-7g9f

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IndiaNIC Widgets Controller allows Reflected XSS.This issue affects Widgets Controller: from n/a through 1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3fj8-rp2r-mcx9

9 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3fj7-qfcc-cr72

4 месяца назад

An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3fj7-9j8m-7r8g

больше 3 лет назад

Moodle Stored HTML in assignment submission comments allowed links to be opened directly

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3fjm-4hqx-7gf9

Use after free in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjj-qfv3-f9fj

Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition before 5.0.a allows remote attackers to hijack the authentication of users for requests that access unauthorized URLs and obtain user credentials via a URL in the url parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjj-p79j-c9hh

Fastify: Incorrect Content-Type parsing can lead to CSRF attack

CVSS3: 4.2
0%
Низкий
около 3 лет назад
github логотип
GHSA-3fjh-6fwj-4f8v

Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side script execution.

CVSS3: 6.4
0%
Низкий
5 дней назад
github логотип
GHSA-3fjh-5fm6-fqmw

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjh-3qmq-p25v

A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) to the health monitor API on an affected device. The vulnerability is due to inadequate provisioning of kernel parameters for the maximum number of TCP connections and SYN backlog. An attacker could exploit this vulnerability by sending a flood of crafted TCP packets to an affected device. A successful exploit could allow the attacker to block TCP listening ports that are used by the health monitor API. This vulnerability only affects customers who use the health monitor API.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjh-2rcv-9cfc

In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Cleanup after an allocation error When allocation failures are not cleaned up by the driver, further allocation errors will be false-positives, which will cause buffers to remain uninitialized and cause NULL pointer dereferences. Ensure proper cleanup of failed allocations to prevent these issues.

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-3fjf-xcfg-59v3

The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke this functionality intended for admin users. This enables subscribers to manage field groups, change visibility of items among other things.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3fjf-pgq8-c45w

SQL injection vulnerability in index.php in Maian Greeting 2.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3fjf-jf49-wrvp

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the function cn_update of the file /_parse/_all_edits.php. The manipulation of the argument cname/url leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3fjc-xv2v-jr9v

Vulnerability in administration server for HP VirtualVault 4.5 on HP-UX 11.04 allows remote web servers or privileged external processes to bypass access restrictions and establish connections to the server.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3fjc-qmr3-wfpw

Unspecified vulnerability in the Spatial component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fjc-pjgm-cw7f

Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a crafted script.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3fjc-9f6x-jrfx

Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted mb_strcut call.

CVSS3: 9.8
11%
Средний
больше 3 лет назад
github логотип
GHSA-3fjc-956c-32mf

The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat actor to insert a PCI card designed for memory capture. A threat actor can then isolate sensitive information such as a BitLocker encryption key from a dump of the workstation RAM during startup.

CVSS3: 2.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3fj9-rv52-g5r6

In the Linux kernel, the following vulnerability has been resolved: udf: Fix preallocation discarding at indirect extent boundary When preallocation extent is the first one in the extent block, the code would corrupt extent tree header instead. Fix the problem and use udf_delete_aext() for deleting extent to avoid some code duplication.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3fj9-c88m-7g9f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IndiaNIC Widgets Controller allows Reflected XSS.This issue affects Widgets Controller: from n/a through 1.1.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3fj8-rp2r-mcx9

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

9 месяцев назад
github логотип
GHSA-3fj7-qfcc-cr72

An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3fj7-9j8m-7r8g

Moodle Stored HTML in assignment submission comments allowed links to be opened directly

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу