Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-399c-25pm-72mj

больше 3 лет назад

A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3999-5ffv-wp2r

почти 2 года назад

Yamux Memory Exhaustion Vulnerability via Active::pending_frames property

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3997-cwm3-9wpp

больше 3 лет назад

Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a font.

EPSS: Низкий
github логотип

GHSA-3997-6wvq-mg36

больше 3 лет назад

Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.

EPSS: Низкий
github логотип

GHSA-3996-4m5r-mmwf

10 месяцев назад

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3995-cwrc-82pq

10 месяцев назад

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-3993-w4q6-qwmf

почти 4 года назад

Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-3993-q22g-mw33

больше 3 лет назад

A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3993-mq32-jgqq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.

EPSS: Низкий
github логотип

GHSA-3993-5r92-h3rg

около 2 лет назад

An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows attacker to cause out-of-bounds read and write.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3992-5mfp-43q5

больше 2 лет назад

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-398x-qm59-5hfg

почти 4 года назад

Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398x-j3p9-ffhp

около 1 года назад

Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-398w-ffjm-vc8f

почти 4 года назад

websitebaker prior to and including 2.8.1 has an authentication error in backup module.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398w-8vvx-7rh5

больше 3 лет назад

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398v-cx4g-hhxc

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: Fix memory leak Fix leaking buffer allocated to send MSFT_OP_LE_MONITOR_ADVERTISEMENT.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-398v-9vhq-3gg5

больше 3 лет назад

Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via network access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398v-9qw7-49xj

почти 4 года назад

SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.

EPSS: Низкий
github логотип

GHSA-398v-5g69-w972

больше 3 лет назад

IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398r-g5cv-mwh7

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering.This issue affects Satos Mobile: before 20230607.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-399c-25pm-72mj

A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3999-5ffv-wp2r

Yamux Memory Exhaustion Vulnerability via Active::pending_frames property

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3997-cwm3-9wpp

Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a font.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-3997-6wvq-mg36

Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3996-4m5r-mmwf

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function.

CVSS3: 7.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-3995-cwrc-82pq

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVSS3: 3.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-3993-w4q6-qwmf

Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3993-q22g-mw33

A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3993-mq32-jgqq

Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3993-5r92-h3rg

An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows attacker to cause out-of-bounds read and write.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3992-5mfp-43q5

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-398x-qm59-5hfg

Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-398x-j3p9-ffhp

Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-398w-ffjm-vc8f

websitebaker prior to and including 2.8.1 has an authentication error in backup module.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-398w-8vvx-7rh5

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-398v-cx4g-hhxc

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: Fix memory leak Fix leaking buffer allocated to send MSFT_OP_LE_MONITOR_ADVERTISEMENT.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-398v-9vhq-3gg5

Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via network access.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-398v-9qw7-49xj

SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.

1%
Низкий
почти 4 года назад
github логотип
GHSA-398v-5g69-w972

IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-398r-g5cv-mwh7

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering.This issue affects Satos Mobile: before 20230607.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу