Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-375m-8hf7-5q5g

около 1 года назад

Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-375m-5fvv-xq23

почти 5 лет назад

VVE-2021-0002: Incorrect `returndatasize` when using simple forwarder proxies deployed prior to EIP-1167 adoption

EPSS: Низкий
github логотип

GHSA-375j-vf5x-r3gh

больше 1 года назад

Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-375h-xc5m-fwff

почти 2 года назад

Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-375h-4wr8-m676

больше 3 лет назад

An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1010, CVE-2020-1068.

EPSS: Низкий
github логотип

GHSA-375h-2mv6-2f8m

почти 4 года назад

An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write outside the intended buffer area.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-375g-qj2r-88m9

около 2 лет назад

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-375g-mf6c-ppr8

больше 3 лет назад

Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-375g-cvgg-5crp

больше 1 года назад

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-375g-39jq-vq7m

почти 2 года назад

Potential buffer overflow in CBOR2 decoder

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-375f-qm2g-pw3c

почти 4 года назад

VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privileges by replacing application programs, as demonstrated by replacing vba32ldr.exe.

EPSS: Низкий
github логотип

GHSA-375f-cc53-h7vh

больше 3 лет назад

Benjamin BALET Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-375c-626v-c7m7

больше 3 лет назад

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overflow in a way path jumps are processed. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3759-qv8m-9cv6

2 месяца назад

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3759-4226-vq4q

6 месяцев назад

Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3758-4r5f-9x5h

больше 3 лет назад

The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3757-wwff-jr3w

почти 4 года назад

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3757-h5gm-6pj5

5 дней назад

A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3756-mp7r-crrp

почти 4 года назад

Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3756-hwhv-qw58

почти 4 года назад

Cross site scripting in francoisjacquet/rosariosis

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-375m-8hf7-5q5g

Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-375m-5fvv-xq23

VVE-2021-0002: Incorrect `returndatasize` when using simple forwarder proxies deployed prior to EIP-1167 adoption

почти 5 лет назад
github логотип
GHSA-375j-vf5x-r3gh

Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-375h-xc5m-fwff

Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-375h-4wr8-m676

An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1010, CVE-2020-1068.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-375h-2mv6-2f8m

An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write outside the intended buffer area.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-375g-qj2r-88m9

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

CVSS3: 4.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-375g-mf6c-ppr8

Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-375g-cvgg-5crp

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-375g-39jq-vq7m

Potential buffer overflow in CBOR2 decoder

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-375f-qm2g-pw3c

VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privileges by replacing application programs, as demonstrated by replacing vba32ldr.exe.

0%
Низкий
почти 4 года назад
github логотип
GHSA-375f-cc53-h7vh

Benjamin BALET Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-375c-626v-c7m7

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overflow in a way path jumps are processed. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3759-qv8m-9cv6

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.

CVSS3: 6.8
0%
Низкий
2 месяца назад
github логотип
GHSA-3759-4226-vq4q

Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-3758-4r5f-9x5h

The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3757-wwff-jr3w

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3757-h5gm-6pj5

A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely.

CVSS3: 7.3
0%
Низкий
5 дней назад
github логотип
GHSA-3756-mp7r-crrp

Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

CVSS3: 3.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-3756-hwhv-qw58

Cross site scripting in francoisjacquet/rosariosis

CVSS3: 5.4
0%
Низкий
почти 4 года назад

Уязвимостей на страницу