Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-39h8-5656-9hw5

больше 3 лет назад

A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

EPSS: Низкий
github логотип

GHSA-39h7-cq3m-g3fv

больше 2 лет назад

A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-39h7-3hhg-xx7p

почти 4 года назад

Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

EPSS: Низкий
github логотип

GHSA-39h6-pqr3-34cv

около 1 года назад

Improper conditions check in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-39h5-qh47-7qp5

больше 2 лет назад

The Custom Base Terms WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-39h5-f398-f6f8

больше 3 лет назад

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3203, CVE-2013-3206, CVE-2013-3207, and CVE-2013-3209.

EPSS: Средний
github логотип

GHSA-39h4-m68j-x2g9

почти 4 года назад

Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-39h4-c5qq-2w56

6 месяцев назад

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability.  https://support.lenovo.com/us/en/product_security/home

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-39h3-g67r-7g3c

19 дней назад

ImageMagick releases an invalid pointer in BilateralBlur when memory allocation fails

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-39h2-98ch-wh7c

больше 2 лет назад

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. Processing web content may disclose sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-39h2-3mq3-959g

19 дней назад

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

EPSS: Низкий
github логотип

GHSA-39gw-mq6q-79fw

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: usb: misc: brcmstb-usb-pinmap: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() returns NULL, we need check the return value.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-39gw-3p56-qj4r

больше 1 года назад

LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-39gv-w9gj-x452

6 месяцев назад

Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-39gv-q5r7-jg94

больше 2 лет назад

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution and gain a reverse shell in Western Digital My Cloud OS 5 devices.This issue affects My Cloud OS 5: before 5.26.119.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-39gv-p97w-w5h3

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in index.php/user_data/insert_user in Savsoft Quiz allows remote attackers to hijack the authentication of administrators for requests that create an administrator account via a crafted request.

EPSS: Низкий
github логотип

GHSA-39gr-vpmm-rhfg

больше 3 лет назад

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-39gr-m4xp-77wp

около 2 лет назад

Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Functionality Bypass.This issue affects F|One SmartEdge Agent: before 1.7.0.230330-554.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-39gp-f464-jp5h

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

EPSS: Низкий
github логотип

GHSA-39gm-mmxq-4x9r

больше 3 лет назад

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-39h8-5656-9hw5

A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-39h7-cq3m-g3fv

A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.

CVSS3: 7.2
6%
Низкий
больше 2 лет назад
github логотип
GHSA-39h7-3hhg-xx7p

Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-39h6-pqr3-34cv

Improper conditions check in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-39h5-qh47-7qp5

The Custom Base Terms WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-39h5-f398-f6f8

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3203, CVE-2013-3206, CVE-2013-3207, and CVE-2013-3209.

27%
Средний
больше 3 лет назад
github логотип
GHSA-39h4-m68j-x2g9

Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-39h4-c5qq-2w56

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerability.  https://support.lenovo.com/us/en/product_security/home

CVSS3: 8.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-39h3-g67r-7g3c

ImageMagick releases an invalid pointer in BilateralBlur when memory allocation fails

CVSS3: 6.5
0%
Низкий
19 дней назад
github логотип
GHSA-39h2-98ch-wh7c

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. Processing web content may disclose sensitive information.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-39h2-3mq3-959g

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

0%
Низкий
19 дней назад
github логотип
GHSA-39gw-mq6q-79fw

In the Linux kernel, the following vulnerability has been resolved: usb: misc: brcmstb-usb-pinmap: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() returns NULL, we need check the return value.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-39gw-3p56-qj4r

LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 6.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-39gv-w9gj-x452

Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-39gv-q5r7-jg94

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution and gain a reverse shell in Western Digital My Cloud OS 5 devices.This issue affects My Cloud OS 5: before 5.26.119.

CVSS3: 8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-39gv-p97w-w5h3

Cross-site request forgery (CSRF) vulnerability in index.php/user_data/insert_user in Savsoft Quiz allows remote attackers to hijack the authentication of administrators for requests that create an administrator account via a crafted request.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-39gr-vpmm-rhfg

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-39gr-m4xp-77wp

Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Functionality Bypass.This issue affects F|One SmartEdge Agent: before 1.7.0.230330-554.

CVSS3: 8.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-39gp-f464-jp5h

Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-39gm-mmxq-4x9r

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу