Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-3c5f-pfff-9cjf

больше 3 лет назад

The affected product is vulnerable to an out-of-bounds read, which can cause information leakage leading to arbitrary code execution if chained to the out-of-bounds write vulnerability on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE): versions prior to v5.3, Welch Allyn Software Development Kit (SDK): versions prior to v3.2, Welch Allyn Connex Central Station (CS): versions prior to v1.8.6, Welch Allyn Service Monitor: versions prior to v1.7.0.0, Welch Allyn Connex Vital Signs Monitor (CVSM): versions prior to v2.43.02, Welch Allyn Connex Integrated Wall System (CIWS): versions prior to v2.43.02, Welch Allyn Connex Spot Monitor (CSM): versions prior to v1.52, Welch Allyn Spot Vital Signs 4400 Device (Spot 4400) / Welch Allyn Spot 4400 Vital Signs Extended Care Device: versions prior to v1.11.00).

EPSS: Низкий
github логотип

GHSA-3c5c-xrq4-qhr8

больше 3 лет назад

ClassLoader manipulation in Apache Struts

EPSS: Высокий
github логотип

GHSA-3c5c-v4xp-7w7v

больше 3 лет назад

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'system.opkg.remove'.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3c5c-7235-994j

больше 7 лет назад

Pillow buffer overflow in ImagingPcdDecode

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3c58-jj8f-4j4g

больше 3 лет назад

Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5544, CVE-2015-5545, CVE-2015-5546, CVE-2015-5547, CVE-2015-5548, CVE-2015-5552, and CVE-2015-5553.

EPSS: Средний
github логотип

GHSA-3c57-hg33-rhrp

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3c56-vx6v-q5vh

больше 3 лет назад

SaltStack Salt Allows creating certificates with weak file permissions

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3c55-h885-645p

больше 3 лет назад

Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3c55-fm7j-h66h

больше 3 лет назад

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3c55-6x27-8w5g

больше 2 лет назад

In WS_FTP Server version 8.8.0 prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' directory listing.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3c54-wfm9-c82p

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rocketelements Split Test For Elementor allows Stored XSS. This issue affects Split Test For Elementor: from n/a through 1.8.3.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3c54-vg5v-pqpf

больше 3 лет назад

A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute arbitrary code with root privileges via a crafted POST request to a nucleo.neatocloud.com:4443/vendors/neato/robots/[robot_serial]/messages Neato cloud URL.

EPSS: Средний
github логотип

GHSA-3c54-rhvg-cfhh

больше 3 лет назад

Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.

EPSS: Низкий
github логотип

GHSA-3c54-jw9j-cwjh

почти 4 года назад

hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.

EPSS: Низкий
github логотип

GHSA-3c54-7fm7-g696

больше 3 лет назад

The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3c53-5p2q-p9qm

почти 2 года назад

A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/delete_activity.php. The manipulation of the argument activity_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259108.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3c52-m5xj-c7ff

9 месяцев назад

The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email Name, Subject, and Body in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3c52-h4x3-2jhm

почти 3 года назад

Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3c52-7j8w-6f87

больше 3 лет назад

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service.

EPSS: Низкий
github логотип

GHSA-3c52-2wpc-wj62

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: tty: vt: initialize unicode screen buffer syzbot reports kernel infoleak at vcs_read() [1], for buffer can be read immediately after resize operation. Initialize buffer using kzalloc(). ---------- #include <fcntl.h> #include <unistd.h> #include <sys/ioctl.h> #include <linux/fb.h> int main(int argc, char *argv[]) { struct fb_var_screeninfo var = { }; const int fb_fd = open("/dev/fb0", 3); ioctl(fb_fd, FBIOGET_VSCREENINFO, &var); var.yres = 0x21; ioctl(fb_fd, FBIOPUT_VSCREENINFO, &var); return read(open("/dev/vcsu", O_RDONLY), &var, sizeof(var)) == -1; } ----------

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3c5f-pfff-9cjf

The affected product is vulnerable to an out-of-bounds read, which can cause information leakage leading to arbitrary code execution if chained to the out-of-bounds write vulnerability on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE): versions prior to v5.3, Welch Allyn Software Development Kit (SDK): versions prior to v3.2, Welch Allyn Connex Central Station (CS): versions prior to v1.8.6, Welch Allyn Service Monitor: versions prior to v1.7.0.0, Welch Allyn Connex Vital Signs Monitor (CVSM): versions prior to v2.43.02, Welch Allyn Connex Integrated Wall System (CIWS): versions prior to v2.43.02, Welch Allyn Connex Spot Monitor (CSM): versions prior to v1.52, Welch Allyn Spot Vital Signs 4400 Device (Spot 4400) / Welch Allyn Spot 4400 Vital Signs Extended Care Device: versions prior to v1.11.00).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c5c-xrq4-qhr8

ClassLoader manipulation in Apache Struts

88%
Высокий
больше 3 лет назад
github логотип
GHSA-3c5c-v4xp-7w7v

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'system.opkg.remove'.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c5c-7235-994j

Pillow buffer overflow in ImagingPcdDecode

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
github логотип
GHSA-3c58-jj8f-4j4g

Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5544, CVE-2015-5545, CVE-2015-5546, CVE-2015-5547, CVE-2015-5548, CVE-2015-5552, and CVE-2015-5553.

46%
Средний
больше 3 лет назад
github логотип
GHSA-3c57-hg33-rhrp

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.

CVSS3: 5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3c56-vx6v-q5vh

SaltStack Salt Allows creating certificates with weak file permissions

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c55-h885-645p

Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

CVSS3: 7.6
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3c55-fm7j-h66h

In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c55-6x27-8w5g

In WS_FTP Server version 8.8.0 prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' directory listing.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3c54-wfm9-c82p

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rocketelements Split Test For Elementor allows Stored XSS. This issue affects Split Test For Elementor: from n/a through 1.8.3.

CVSS3: 5.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-3c54-vg5v-pqpf

A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute arbitrary code with root privileges via a crafted POST request to a nucleo.neatocloud.com:4443/vendors/neato/robots/[robot_serial]/messages Neato cloud URL.

18%
Средний
больше 3 лет назад
github логотип
GHSA-3c54-rhvg-cfhh

Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c54-jw9j-cwjh

hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.

10%
Низкий
почти 4 года назад
github логотип
GHSA-3c54-7fm7-g696

The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c53-5p2q-p9qm

A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/delete_activity.php. The manipulation of the argument activity_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259108.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3c52-m5xj-c7ff

The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email Name, Subject, and Body in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
0%
Низкий
9 месяцев назад
github логотип
GHSA-3c52-h4x3-2jhm

Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3c52-7j8w-6f87

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c52-2wpc-wj62

In the Linux kernel, the following vulnerability has been resolved: tty: vt: initialize unicode screen buffer syzbot reports kernel infoleak at vcs_read() [1], for buffer can be read immediately after resize operation. Initialize buffer using kzalloc(). ---------- #include <fcntl.h> #include <unistd.h> #include <sys/ioctl.h> #include <linux/fb.h> int main(int argc, char *argv[]) { struct fb_var_screeninfo var = { }; const int fb_fd = open("/dev/fb0", 3); ioctl(fb_fd, FBIOGET_VSCREENINFO, &var); var.yres = 0x21; ioctl(fb_fd, FBIOPUT_VSCREENINFO, &var); return read(open("/dev/vcsu", O_RDONLY), &var, sizeof(var)) == -1; } ----------

CVSS3: 5.5
0%
Низкий
8 месяцев назад

Уязвимостей на страницу