Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-372f-jc47-7gr5

почти 4 года назад

Missing permission check in Jenkins Conjur Secrets Plugin allows enumerating credentials IDs

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-372f-fc65-m555

10 месяцев назад

The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in all versions up to, and including, 0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-372f-8jhc-h6mp

около 1 года назад

The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Processing a maliciously crafted file may lead to a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-372f-59f7-7hfw

больше 3 лет назад

The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS short-code messaging via a crafted application, aka internal bug 22314646.

EPSS: Низкий
github логотип

GHSA-372f-26mp-wjj9

больше 3 лет назад

An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caused by incomplete obfuscation of application configuration information.

EPSS: Низкий
github логотип

GHSA-3729-fh52-2ph2

больше 2 лет назад

The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to gain root privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3729-9j52-jqrv

больше 1 года назад

A vulnerability, which was classified as problematic, has been found in OcoMon 4.0. This issue affects some unknown processing of the file /includes/common/require_access_recovery.php of the component URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.0.1 and 5.0 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3728-9cr9-4xwr

больше 2 лет назад

Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication by sending illegitimate messages.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3728-546x-w527

больше 3 лет назад

Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exploited, could allow kernel pointers and debug messages to leak to userland. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.

EPSS: Низкий
github логотип

GHSA-3727-xggf-v75h

больше 2 лет назад

A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /SystemManage/Organize/GetTreeGridJson?_search=false&nd=1681813520783&rows=10000&page=1&sidx=&sord=asc. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-229976. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3727-x5w3-xwrr

около 2 лет назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3727-rqp8-9h64

3 месяца назад

Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3725-x3x8-r7jq

почти 4 года назад

The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan.

EPSS: Низкий
github логотип

GHSA-3724-xmqw-2wwv

больше 3 лет назад

Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.

EPSS: Низкий
github логотип

GHSA-3724-qc3c-8gr9

почти 4 года назад

In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3724-q3rh-j82p

почти 4 года назад

A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3724-jcfq-mvfc

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Miguel Peixe WP Feature Box allows Stored XSS.This issue affects WP Feature Box: from n/a through 0.1.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3724-4mmc-j59x

около 4 лет назад

NoMachine Enterprise Desktop is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

EPSS: Низкий
github логотип

GHSA-3723-f7xr-2xgj

около 1 года назад

WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36xx-7vf6-7mv3

больше 2 лет назад

Silverstripe Framework: Members with no password can be created and bypass custom login forms

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-372f-jc47-7gr5

Missing permission check in Jenkins Conjur Secrets Plugin allows enumerating credentials IDs

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-372f-fc65-m555

The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in all versions up to, and including, 0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-372f-8jhc-h6mp

The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. Processing a maliciously crafted file may lead to a denial of service.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-372f-59f7-7hfw

The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS short-code messaging via a crafted application, aka internal bug 22314646.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-372f-26mp-wjj9

An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caused by incomplete obfuscation of application configuration information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3729-fh52-2ph2

The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to gain root privileges.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3729-9j52-jqrv

A vulnerability, which was classified as problematic, has been found in OcoMon 4.0. This issue affects some unknown processing of the file /includes/common/require_access_recovery.php of the component URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.0.1 and 5.0 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3728-9cr9-4xwr

Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication by sending illegitimate messages.

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3728-546x-w527

Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exploited, could allow kernel pointers and debug messages to leak to userland. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3727-xggf-v75h

A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /SystemManage/Organize/GetTreeGridJson?_search=false&nd=1681813520783&rows=10000&page=1&sidx=&sord=asc. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-229976. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3727-x5w3-xwrr

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level.

CVSS3: 7.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-3727-rqp8-9h64

Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-3725-x3x8-r7jq

The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3724-xmqw-2wwv

Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3724-qc3c-8gr9

In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3724-q3rh-j82p

A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-3724-jcfq-mvfc

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Miguel Peixe WP Feature Box allows Stored XSS.This issue affects WP Feature Box: from n/a through 0.1.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3724-4mmc-j59x

NoMachine Enterprise Desktop is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3723-f7xr-2xgj

WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-36xx-7vf6-7mv3

Silverstripe Framework: Members with no password can be created and bypass custom login forms

больше 2 лет назад

Уязвимостей на страницу