Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 840

Количество 301 840

github логотип

GHSA-295h-9p3g-cmj9

больше 3 лет назад

ImageMagick allows remote attackers to cause a denial of service (file descriptor consumption) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-295f-8p4v-mmf4

больше 3 лет назад

SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[startswith] parameter to ajax/render/memberlist_items.

EPSS: Низкий
github логотип

GHSA-295c-qxg5-g88q

10 месяцев назад

Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `open_port` POST parameter.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-295c-7mqg-g3v8

больше 3 лет назад

Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starting/stopping programs, shutdown, reset safety and more. The DashBoard server is not protected by any kind of authentication or authorization.

EPSS: Низкий
github логотип

GHSA-2959-fj73-hm8p

больше 3 лет назад

Missing permission checks in Jenkins Config File Provider Plugin allow enumerating configuration file IDs

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2958-5r4r-wvv6

около 5 лет назад

Directory Traversal in caolilinode

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2956-gj54-r9fg

больше 1 года назад

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2956-2v8q-xc52

больше 3 лет назад

A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT PRO (All versions < 5.5.1), SCALANCE X202-2 IRT (All versions < 5.5.1), SCALANCE X202-2P IRT (incl. SIPLUS NET variant) (All versions < 5.5.1), SCALANCE X202-2P IRT PRO (All versions < 5.5.1), SCALANCE X204 IRT (All versions < 5.5.1), SCALANCE X204 IRT PRO (All versions < 5.5.1), SCALANCE X204-2 (incl. SIPLUS NET variant) (All versions), SCALANCE X204-2FM (All versions), SCALANCE X204-2LD (incl. SIPLUS NET variant) (All versions), SCALANCE X204-2LD TS (All versions), SCALANCE X204-2TS (All versions), SCALANCE X206-1 (All versions), SCALANCE X206-1LD (All versions), SCALANCE X208 (incl. SIPLUS NET variant) (All versions), SCALANCE X208PRO (All versions), SCALANCE X212-2 (incl. SIPLUS NET variant) (All versions), SCALANCE X212-2LD (All versions), SCALANCE X216 (All versions), SCALANCE X224 (All versions), SCALANCE XF201-3P IRT (All versi...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2955-j2mm-qvcq

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: regmap: spi: Reserve space for register address/padding Currently the max_raw_read and max_raw_write limits in regmap_spi struct do not take into account the additional size of the transmitted register address and padding. This may result in exceeding the maximum permitted SPI message size, which could cause undefined behaviour, e.g. data corruption. Fix regmap_get_spi_bus() to properly adjust the above mentioned limits by reserving space for the register address/padding as set in the regmap configuration.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2955-fpjj-xgjj

больше 3 лет назад

The SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (process restart) via crafted SNMP packets, aka Bug ID CSCue69472.

EPSS: Низкий
github логотип

GHSA-2955-cp7r-7qw6

больше 3 лет назад

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2954-jqmf-g2fj

больше 1 года назад

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2954-hh3h-2236

больше 3 лет назад

Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.

EPSS: Средний
github логотип

GHSA-2954-4rrv-2pfp

7 месяцев назад

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2952-j2hp-678j

больше 1 года назад

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2952-9pxc-jw5m

больше 3 лет назад

SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.

EPSS: Низкий
github логотип

GHSA-294x-x7jx-8864

7 месяцев назад

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-294x-vx6v-6x6f

больше 3 лет назад

vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-294x-pcj2-wqf8

больше 1 года назад

Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-294x-mfp7-qj66

больше 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer allows Path Traversal.This issue affects Ovic Importer: from n/a through 1.6.3.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-295h-9p3g-cmj9

ImageMagick allows remote attackers to cause a denial of service (file descriptor consumption) via a crafted file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-295f-8p4v-mmf4

SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[startswith] parameter to ajax/render/memberlist_items.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-295c-qxg5-g88q

Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `open_port` POST parameter.

CVSS3: 9.1
2%
Низкий
10 месяцев назад
github логотип
GHSA-295c-7mqg-g3v8

Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starting/stopping programs, shutdown, reset safety and more. The DashBoard server is not protected by any kind of authentication or authorization.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2959-fj73-hm8p

Missing permission checks in Jenkins Config File Provider Plugin allow enumerating configuration file IDs

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2958-5r4r-wvv6

Directory Traversal in caolilinode

CVSS3: 7.5
1%
Низкий
около 5 лет назад
github логотип
GHSA-2956-gj54-r9fg

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7.8
6%
Низкий
больше 1 года назад
github логотип
GHSA-2956-2v8q-xc52

A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT PRO (All versions < 5.5.1), SCALANCE X202-2 IRT (All versions < 5.5.1), SCALANCE X202-2P IRT (incl. SIPLUS NET variant) (All versions < 5.5.1), SCALANCE X202-2P IRT PRO (All versions < 5.5.1), SCALANCE X204 IRT (All versions < 5.5.1), SCALANCE X204 IRT PRO (All versions < 5.5.1), SCALANCE X204-2 (incl. SIPLUS NET variant) (All versions), SCALANCE X204-2FM (All versions), SCALANCE X204-2LD (incl. SIPLUS NET variant) (All versions), SCALANCE X204-2LD TS (All versions), SCALANCE X204-2TS (All versions), SCALANCE X206-1 (All versions), SCALANCE X206-1LD (All versions), SCALANCE X208 (incl. SIPLUS NET variant) (All versions), SCALANCE X208PRO (All versions), SCALANCE X212-2 (incl. SIPLUS NET variant) (All versions), SCALANCE X212-2LD (All versions), SCALANCE X216 (All versions), SCALANCE X224 (All versions), SCALANCE XF201-3P IRT (All versi...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2955-j2mm-qvcq

In the Linux kernel, the following vulnerability has been resolved: regmap: spi: Reserve space for register address/padding Currently the max_raw_read and max_raw_write limits in regmap_spi struct do not take into account the additional size of the transmitted register address and padding. This may result in exceeding the maximum permitted SPI message size, which could cause undefined behaviour, e.g. data corruption. Fix regmap_get_spi_bus() to properly adjust the above mentioned limits by reserving space for the register address/padding as set in the regmap configuration.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2955-fpjj-xgjj

The SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (process restart) via crafted SNMP packets, aka Bug ID CSCue69472.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2955-cp7r-7qw6

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2954-jqmf-g2fj

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2954-hh3h-2236

Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.

18%
Средний
больше 3 лет назад
github логотип
GHSA-2954-4rrv-2pfp

The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 3.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2952-j2hp-678j

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-2952-9pxc-jw5m

SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-294x-x7jx-8864

During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-294x-vx6v-6x6f

vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-294x-pcj2-wqf8

Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.

CVSS3: 9.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-294x-mfp7-qj66

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer allows Path Traversal.This issue affects Ovic Importer: from n/a through 1.6.3.

CVSS3: 7.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу