Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-339h-hwgh-x2jc

больше 2 лет назад

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form. Affected Products: Conext™ ComBox (All Versions)

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-339g-wwmf-2hqf

больше 3 лет назад

PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-339g-p78w-jq7j

больше 2 лет назад

Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd and starttijd parameters of do/search.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-339f-fg4x-gwcm

около 2 лет назад

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-339c-xph3-fj7g

почти 4 года назад

The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference) and a deadlock.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3399-vjx8-7x5c

больше 3 лет назад

MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3398-v46q-wcp6

около 4 лет назад

Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set the "message of the day" banner to any file on the system, allowing them to read all or some of the contents of those files. Such sensitive information as hashed credentials, hardcoded plaintext passwords for other services, configuration files, and private keys can be disclosed in this fashion. Improper handling of filenames that identify virtual resources, such as "/dev/urandom" allows an attacker to effect a denial of service attack against the command line interfaces of the Quagga services (zebra and ripd).

EPSS: Низкий
github логотип

GHSA-3398-j6j6-c7xj

4 месяца назад

Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attackers to potentially execute arbitrary code with SystemUI privilege.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3396-fm48-pqc5

почти 4 года назад

PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.

EPSS: Низкий
github логотип

GHSA-3394-h5f6-fpwc

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for 2.6.

EPSS: Низкий
github логотип

GHSA-3394-cqqj-2g45

больше 1 года назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3394-6qr2-55gf

больше 3 лет назад

Unspecified vulnerability in the MICROS Retail component in Oracle Retail Applications Xstore: 3.2.1, 3.4.2, 3.5.0, 4.0.1, 4.5.1, 4.8.0, 5.0.3, 5.5.3, 6.0.6, and 6.5.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Xstore Point of Sale.

EPSS: Низкий
github логотип

GHSA-3394-4x69-rcm8

больше 3 лет назад

The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.

EPSS: Низкий
github логотип

GHSA-3393-xjfj-fh77

7 месяцев назад

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3393-r4p5-vhqh

больше 3 лет назад

Gitea Allows 1FA Even for 2FA-Enrolled Accounts

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3393-hvrj-w7v3

больше 4 лет назад

Denial of Service in Elasticsearch

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3393-gh57-mr75

почти 4 года назад

The rsh/rlogin service is running.

EPSS: Средний
github логотип

GHSA-3393-4w74-98fc

больше 3 лет назад

Untrusted search path vulnerability in Music Center for PC version 1.0.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-338x-rqm6-3p3h

почти 4 года назад

Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0511, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.

EPSS: Средний
github логотип

GHSA-338x-q4qx-prw7

около 2 лет назад

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-339h-hwgh-x2jc

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form. Affected Products: Conext™ ComBox (All Versions)

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-339g-wwmf-2hqf

PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-339g-p78w-jq7j

Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd and starttijd parameters of do/search.php.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-339f-fg4x-gwcm

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

CVSS3: 9
0%
Низкий
около 2 лет назад
github логотип
GHSA-339c-xph3-fj7g

The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference) and a deadlock.

CVSS3: 7.5
4%
Низкий
почти 4 года назад
github логотип
GHSA-3399-vjx8-7x5c

MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3398-v46q-wcp6

Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set the "message of the day" banner to any file on the system, allowing them to read all or some of the contents of those files. Such sensitive information as hashed credentials, hardcoded plaintext passwords for other services, configuration files, and private keys can be disclosed in this fashion. Improper handling of filenames that identify virtual resources, such as "/dev/urandom" allows an attacker to effect a denial of service attack against the command line interfaces of the Quagga services (zebra and ripd).

0%
Низкий
около 4 лет назад
github логотип
GHSA-3398-j6j6-c7xj

Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attackers to potentially execute arbitrary code with SystemUI privilege.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3396-fm48-pqc5

PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-3394-h5f6-fpwc

Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for 2.6.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3394-cqqj-2g45

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

CVSS3: 8.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-3394-6qr2-55gf

Unspecified vulnerability in the MICROS Retail component in Oracle Retail Applications Xstore: 3.2.1, 3.4.2, 3.5.0, 4.0.1, 4.5.1, 4.8.0, 5.0.3, 5.5.3, 6.0.6, and 6.5.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Xstore Point of Sale.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3394-4x69-rcm8

The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3393-xjfj-fh77

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3393-r4p5-vhqh

Gitea Allows 1FA Even for 2FA-Enrolled Accounts

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3393-hvrj-w7v3

Denial of Service in Elasticsearch

CVSS3: 5.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3393-gh57-mr75

The rsh/rlogin service is running.

50%
Средний
почти 4 года назад
github логотип
GHSA-3393-4w74-98fc

Untrusted search path vulnerability in Music Center for PC version 1.0.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-338x-rqm6-3p3h

Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0511, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.

13%
Средний
почти 4 года назад
github логотип
GHSA-338x-q4qx-prw7

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list

CVSS3: 9.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу