Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-373r-m8cx-p9m3

больше 1 года назад

NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-373r-9mg8-3jc4

больше 3 лет назад

Apache Geode vulnerable to Cross-Site Scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-373r-4p5w-qjr7

больше 3 лет назад

Misskey before 10.102.4 allows hijacking a user's token.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-373q-7p85-gr9f

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saif Bin-Alam Kings Tab Slider allows DOM-Based XSS.This issue affects Kings Tab Slider: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-373q-78xr-xjxr

почти 4 года назад

SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catcode parameter.

EPSS: Низкий
github логотип

GHSA-373q-4784-p65c

5 месяцев назад

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-373p-qrfg-hfq4

почти 4 года назад

cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument.

EPSS: Низкий
github логотип

GHSA-373p-j926-5m9h

больше 2 лет назад

An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-373p-f3jj-fc96

почти 4 года назад

** DISPUTED ** PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code via a URL in the SMARTY_DIR parameter. NOTE: this issue is disputed by CVE and a third party because SMARTY_DIR is a constant.

EPSS: Низкий
github логотип

GHSA-373m-pcmj-4448

около 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900 before 1.0.4.38, R7900P before 1.4.2.84, R8000 before 1.0.4.68, R8000P before 1.4.2.84, RAX200 before 1.0.3.106, MR60 before 1.0.6.110, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, MS60 before 1.0.6.110, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.

EPSS: Низкий
github логотип

GHSA-373m-h49w-9x43

больше 3 лет назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1146, CVE-2019-1155, CVE-2019-1156, CVE-2019-1157.

EPSS: Низкий
github логотип

GHSA-373m-8w83-9jwp

больше 3 лет назад

Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is set to accept SSH connections from the WAN side, and is also connected to the Internet with the authentication information unchanged from the default settings.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-373m-459c-25jg

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Terry Lin WP Githuber MD allows Stored XSS.This issue affects WP Githuber MD: from n/a through 1.16.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-373j-x448-854g

около 1 года назад

A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-373j-v9g8-mwpm

около 1 месяца назад

The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.3.2. This is due to the plugin's framework component adding SVG to the allowed MIME types via the upload_mimes filter without implementing any sanitization of SVG file contents. This makes it possible for authenticated attackers, with Author-level access and above, to upload SVG files containing malicious JavaScript that executes when the file is viewed, leading to arbitrary JavaScript execution in victims' browsers.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-373j-mhpf-84wg

8 месяцев назад

Janssen Config API returns results without scope verification

EPSS: Низкий
github логотип

GHSA-373j-hc6c-w8vm

почти 4 года назад

An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to render the thumbnail for the file while in the File->Open dialog.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-373j-h87p-5m67

почти 4 года назад

wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.

EPSS: Низкий
github логотип

GHSA-373h-5fj9-5xc7

больше 3 лет назад

Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-373g-j2hc-873c

больше 3 лет назад

PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-373r-m8cx-p9m3

NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-373r-9mg8-3jc4

Apache Geode vulnerable to Cross-Site Scripting

CVSS3: 5.4
3%
Низкий
больше 3 лет назад
github логотип
GHSA-373r-4p5w-qjr7

Misskey before 10.102.4 allows hijacking a user's token.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-373q-7p85-gr9f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saif Bin-Alam Kings Tab Slider allows DOM-Based XSS.This issue affects Kings Tab Slider: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-373q-78xr-xjxr

SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catcode parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-373q-4784-p65c

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-373p-qrfg-hfq4

cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-373p-j926-5m9h

An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-373p-f3jj-fc96

** DISPUTED ** PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code via a URL in the SMARTY_DIR parameter. NOTE: this issue is disputed by CVE and a third party because SMARTY_DIR is a constant.

1%
Низкий
почти 4 года назад
github логотип
GHSA-373m-pcmj-4448

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900 before 1.0.4.38, R7900P before 1.4.2.84, R8000 before 1.0.4.68, R8000P before 1.4.2.84, RAX200 before 1.0.3.106, MR60 before 1.0.6.110, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, MS60 before 1.0.6.110, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RBR750 before 3.2.16.6, RBR850 before 3.2.16.6, RBS750 before 3.2.16.6, RBS850 before 3.2.16.6, RBK752 before 3.2.16.6, and RBK852 before 3.2.16.6.

2%
Низкий
около 4 лет назад
github логотип
GHSA-373m-h49w-9x43

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1146, CVE-2019-1155, CVE-2019-1156, CVE-2019-1157.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-373m-8w83-9jwp

Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is set to accept SSH connections from the WAN side, and is also connected to the Internet with the authentication information unchanged from the default settings.

CVSS3: 7.2
9%
Низкий
больше 3 лет назад
github логотип
GHSA-373m-459c-25jg

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Terry Lin WP Githuber MD allows Stored XSS.This issue affects WP Githuber MD: from n/a through 1.16.3.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-373j-x448-854g

A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-373j-v9g8-mwpm

The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.3.2. This is due to the plugin's framework component adding SVG to the allowed MIME types via the upload_mimes filter without implementing any sanitization of SVG file contents. This makes it possible for authenticated attackers, with Author-level access and above, to upload SVG files containing malicious JavaScript that executes when the file is viewed, leading to arbitrary JavaScript execution in victims' browsers.

CVSS3: 6.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-373j-mhpf-84wg

Janssen Config API returns results without scope verification

0%
Низкий
8 месяцев назад
github логотип
GHSA-373j-hc6c-w8vm

An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to render the thumbnail for the file while in the File->Open dialog.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-373j-h87p-5m67

wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.

0%
Низкий
почти 4 года назад
github логотип
GHSA-373h-5fj9-5xc7

Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-373g-j2hc-873c

PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу