Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-36vw-x38h-vrqr

больше 3 лет назад

In mca_ccb_hdl_req of mca_cact.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-110791536

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36vw-m4cf-f8jm

2 месяца назад

UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with elevated privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36vw-58gr-fvfc

больше 3 лет назад

The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36vv-q5jv-94cj

11 месяцев назад

Drupal Google Tag Cross-Site Scripting (XSS) vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-36vv-8mxf-q4m6

больше 3 лет назад

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-36vr-cpp3-vrwf

больше 3 лет назад

A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36vr-6mp8-v579

больше 3 лет назад

An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36vq-p8j8-w4qf

больше 3 лет назад

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429, CVE-2015-8430, CVE-2015-8431, CVE-2015-8432, ...

EPSS: Низкий
github логотип

GHSA-36vq-45p6-qv5c

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36vp-pvh3-w5x3

больше 3 лет назад

An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any local user on a Linux/UNIX system to run SysInfo and obtain a root shell, which can be used to compromise the local system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36vp-p2m5-97vp

около 2 лет назад

Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36vm-xw34-x4pj

больше 4 лет назад

CHECK-fail in `tf.raw_ops.IRFFT`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-36vm-5pc5-gh56

9 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-36vj-6865-3335

больше 3 лет назад

Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter.

EPSS: Низкий
github логотип

GHSA-36vh-mp6p-rrp2

больше 3 лет назад

perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36vh-jjg9-vxcf

больше 3 лет назад

PHP-Fusion 9.03 allows XSS via the error_log file.

EPSS: Низкий
github логотип

GHSA-36vh-hj6f-jcqm

больше 3 лет назад

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

EPSS: Низкий
github логотип

GHSA-36vf-gm3g-hgwj

больше 3 лет назад

** DISPUTED ** Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, have hardcoded SSH credentials, which makes it easier for remote attackers to obtain access by leveraging knowledge of the required username and password. NOTE: the vendor states "This was a flaw for the developer/debugging devices (again not possible in production versions)."

EPSS: Низкий
github логотип

GHSA-36vf-c8x2-4hhm

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in ajax_functions.php in the GEO Redirector plugin 1.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the hid_id parameter.

EPSS: Низкий
github логотип

GHSA-36vc-qhvq-j266

почти 4 года назад

Multiple SQL injection vulnerabilities in admin.asp in WPC.easy allow remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36vw-x38h-vrqr

In mca_ccb_hdl_req of mca_cact.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-110791536

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36vw-m4cf-f8jm

UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with elevated privileges.

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-36vw-58gr-fvfc

The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36vv-q5jv-94cj

Drupal Google Tag Cross-Site Scripting (XSS) vulnerability

CVSS3: 4.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-36vv-8mxf-q4m6

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.

CVSS3: 7.5
81%
Высокий
больше 3 лет назад
github логотип
GHSA-36vr-cpp3-vrwf

A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36vr-6mp8-v579

An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-36vq-p8j8-w4qf

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429, CVE-2015-8430, CVE-2015-8431, CVE-2015-8432, ...

6%
Низкий
больше 3 лет назад
github логотип
GHSA-36vq-45p6-qv5c

Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36vp-pvh3-w5x3

An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any local user on a Linux/UNIX system to run SysInfo and obtain a root shell, which can be used to compromise the local system.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36vp-p2m5-97vp

Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-36vm-xw34-x4pj

CHECK-fail in `tf.raw_ops.IRFFT`

CVSS3: 2.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-36vm-5pc5-gh56

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

9 месяцев назад
github логотип
GHSA-36vj-6865-3335

Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-36vh-mp6p-rrp2

perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36vh-jjg9-vxcf

PHP-Fusion 9.03 allows XSS via the error_log file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-36vh-hj6f-jcqm

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-36vf-gm3g-hgwj

** DISPUTED ** Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, have hardcoded SSH credentials, which makes it easier for remote attackers to obtain access by leveraging knowledge of the required username and password. NOTE: the vendor states "This was a flaw for the developer/debugging devices (again not possible in production versions)."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-36vf-c8x2-4hhm

Cross-site scripting (XSS) vulnerability in ajax_functions.php in the GEO Redirector plugin 1.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the hid_id parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-36vc-qhvq-j266

Multiple SQL injection vulnerabilities in admin.asp in WPC.easy allow remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameter.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу