Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-38h6-gmr2-j4wx

почти 3 года назад

Silverstripe Form Capture vulnerable to stored cross-site-scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38h5-q5q6-wmqj

больше 3 лет назад

Cloudera Hue 4.6.0 allows XSS via the type parameter.

EPSS: Низкий
github логотип

GHSA-38h5-7v7x-v6pw

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38h4-p674-c649

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-38h4-hmr8-8c7q

около 1 года назад

Memory corruption when IOCTL call is invoked from user-space to read board data.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38h4-fx85-qcx7

12 месяцев назад

Exiv2 allows Use After Free

EPSS: Низкий
github логотип

GHSA-38h4-92v3-hhh5

больше 3 лет назад

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17018.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38h4-4x7h-qprw

больше 3 лет назад

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38h4-3233-xrh9

больше 3 лет назад

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.

EPSS: Низкий
github логотип

GHSA-38h3-wj4x-mm5c

почти 4 года назад

unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.

EPSS: Низкий
github логотип

GHSA-38h3-jcwf-hx88

около 3 лет назад

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gx-pgpj-9cw5

почти 4 года назад

Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gw-wmv7-g95w

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-38gw-6g45-69p7

больше 3 лет назад

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

EPSS: Низкий
github логотип

GHSA-38gv-g72v-rp63

больше 3 лет назад

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38gv-cwr5-whgg

больше 3 лет назад

An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38gr-cjjp-3f5w

почти 2 года назад

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38gq-f4qx-7pmw

больше 3 лет назад

Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38gp-wr3c-cqw7

больше 3 лет назад

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-38gp-wf27-935r

больше 3 лет назад

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38h6-gmr2-j4wx

Silverstripe Form Capture vulnerable to stored cross-site-scripting

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-38h5-q5q6-wmqj

Cloudera Hue 4.6.0 allows XSS via the type parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38h5-7v7x-v6pw

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-38h4-p674-c649

Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38h4-hmr8-8c7q

Memory corruption when IOCTL call is invoked from user-space to read board data.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-38h4-fx85-qcx7

Exiv2 allows Use After Free

1%
Низкий
12 месяцев назад
github логотип
GHSA-38h4-92v3-hhh5

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17018.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h4-4x7h-qprw

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h4-3233-xrh9

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h3-wj4x-mm5c

unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38h3-jcwf-hx88

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-38gx-pgpj-9cw5

Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-38gw-wmv7-g95w

Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gw-6g45-69p7

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gv-g72v-rp63

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gv-cwr5-whgg

An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38gr-cjjp-3f5w

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-38gq-f4qx-7pmw

Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-wr3c-cqw7

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gp-wf27-935r

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу