Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-38gv-cwr5-whgg

больше 3 лет назад

An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38gr-cjjp-3f5w

почти 2 года назад

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38gq-f4qx-7pmw

больше 3 лет назад

Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38gp-wr3c-cqw7

больше 3 лет назад

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-38gp-wf27-935r

больше 3 лет назад

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gp-jhv5-4hgh

больше 3 лет назад

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38gp-chjq-42jw

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38gp-2mrc-f9cj

больше 3 лет назад

Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38gp-237c-7q54

почти 4 года назад

Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

EPSS: Низкий
github логотип

GHSA-38gm-wvj3-rc26

около 3 лет назад

A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214625 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gm-m6ww-x846

около 2 лет назад

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker sends high rate of specific ICMP traffic to a device with VXLAN configured, this causes a deadlock of the PFE and results in the device becoming unresponsive. A manual restart will be required to recover the device. This issue only affects EX4100, EX4400, EX4600, QFX5000 Series devices. This issue affects: Juniper Networks Junos OS * 21.4R3 versions earlier than 21.4R3-S4; * 22.1R3 versions earlier than 22.1R3-S3; * 22.2R2 versions earlier than 22.2R3-S1; * 22.3 versions earlier than 22.3R2-S2, 22.3R3; * 22.4 versions earlier than 22.4R2; * 23.1 versions earlier than 23.1R2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38gj-h5v9-v9pm

11 месяцев назад

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38gh-v47f-3r7c

почти 4 года назад

Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-38gh-44mj-6cx9

больше 1 года назад

Missing Authorization vulnerability in AutoWriter AI Post Generator | AutoWriter.This issue affects AI Post Generator | AutoWriter: from n/a through 3.3.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38gf-rh2w-gmj7

больше 1 года назад

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-38gf-q933-q62g

больше 1 года назад

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing XML input. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system or conduct an SSRF attack through the affected device.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38gc-w4h9-7pmf

около 4 лет назад

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

EPSS: Низкий
github логотип

GHSA-38g9-r8v2-99xr

около 1 года назад

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38g9-g3gm-rjcm

больше 3 лет назад

Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38g8-fx3r-j23m

больше 3 лет назад

Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38gv-cwr5-whgg

An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38gr-cjjp-3f5w

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-38gq-f4qx-7pmw

Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-wr3c-cqw7

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-wf27-935r

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-jhv5-4hgh

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-chjq-42jw

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-2mrc-f9cj

Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-237c-7q54

Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38gm-wvj3-rc26

A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214625 was assigned to this vulnerability.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-38gm-m6ww-x846

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker sends high rate of specific ICMP traffic to a device with VXLAN configured, this causes a deadlock of the PFE and results in the device becoming unresponsive. A manual restart will be required to recover the device. This issue only affects EX4100, EX4400, EX4600, QFX5000 Series devices. This issue affects: Juniper Networks Junos OS * 21.4R3 versions earlier than 21.4R3-S4; * 22.1R3 versions earlier than 22.1R3-S3; * 22.2R2 versions earlier than 22.2R3-S1; * 22.3 versions earlier than 22.3R2-S2, 22.3R3; * 22.4 versions earlier than 22.4R2; * 23.1 versions earlier than 23.1R2.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-38gj-h5v9-v9pm

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-38gh-v47f-3r7c

Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.

21%
Средний
почти 4 года назад
github логотип
GHSA-38gh-44mj-6cx9

Missing Authorization vulnerability in AutoWriter AI Post Generator | AutoWriter.This issue affects AI Post Generator | AutoWriter: from n/a through 3.3.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-38gf-rh2w-gmj7

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-38gf-q933-q62g

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing XML input. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system or conduct an SSRF attack through the affected device.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-38gc-w4h9-7pmf

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

0%
Низкий
около 4 лет назад
github логотип
GHSA-38g9-r8v2-99xr

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-38g9-g3gm-rjcm

Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-38g8-fx3r-j23m

Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу