Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-34rc-q3mr-hpv6

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15040.

EPSS: Низкий
github логотип

GHSA-34rc-844x-w698

больше 3 лет назад

An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-34r9-jr37-pmrf

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: fix mes ring buffer overflow wait memory room until enough before writing mes packets to avoid ring buffer overflow. v2: squash in sched_hw_submission fix (cherry picked from commit 34e087e8920e635c62e2ed6a758b0cd27f836d13)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34r8-jwpj-vw8q

почти 4 года назад

DbbS 2.0-alpha and earlier allows remote attackers to obtain sensitive information via an invalid (1) fcategoryid parameter to topics.php or (2) unavariabile, (3) GLOBALS, or (4) _SERVER[] parameters to script.php. NOTE: this information leak might be resultant from a global variable overwrite issue.

EPSS: Низкий
github логотип

GHSA-34r8-h3gq-qmjj

больше 3 лет назад

UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34r8-fv4m-hxcv

больше 1 года назад

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263924.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34r8-4w7f-49v8

почти 4 года назад

XnView 2.03 has a stack-based buffer overflow vulnerability

EPSS: Низкий
github логотип

GHSA-34r7-q49f-h37c

больше 8 лет назад

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34r6-xm35-5vcx

больше 3 лет назад

LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r6-q8c8-23mx

8 месяцев назад

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-34r6-9vgg-pmh3

около 2 лет назад

The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r5-hj3h-jf22

почти 4 года назад

JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-34r5-4vr6-q5h6

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO Precision markers need to be propagated whenever we have an ARG_CONST_* style argument, as the verifier cannot consider imprecise scalars to be equivalent for the purposes of states_equal check when such arguments refine the return value (in this case, set mem_size for PTR_TO_MEM). The resultant mem_size for the R0 is derived from the constant value, and if the verifier incorrectly prunes states considering them equivalent where such arguments exist (by seeing that both registers have reg->precise as false in regsafe), we can end up with invalid programs passing the verifier which can do access beyond what should have been the correct mem_size in that explored state. To show a concrete example of the problem: 0000000000000000 <prog>: 0: r2 = *(u32 *)(r1 + 80) 1: r1 = *(u32 *)(r1 + 76) 2: r3 = r1 3: r...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34r4-qfpx-74fg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-34r4-p9qh-fh37

больше 3 лет назад

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.

EPSS: Низкий
github логотип

GHSA-34r4-h4c9-vmrj

больше 3 лет назад

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-34r4-9973-43mq

почти 3 года назад

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34r3-v64f-c8m6

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943.

EPSS: Низкий
github логотип

GHSA-34r3-h75p-74mh

5 месяцев назад

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34r2-vc72-3cjg

больше 3 лет назад

SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34rc-q3mr-hpv6

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15040.

0%
Низкий
около 4 лет назад
github логотип
GHSA-34rc-844x-w698

An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.

CVSS3: 9.8
81%
Высокий
больше 3 лет назад
github логотип
GHSA-34r9-jr37-pmrf

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: fix mes ring buffer overflow wait memory room until enough before writing mes packets to avoid ring buffer overflow. v2: squash in sched_hw_submission fix (cherry picked from commit 34e087e8920e635c62e2ed6a758b0cd27f836d13)

CVSS3: 7.8
больше 1 года назад
github логотип
GHSA-34r8-jwpj-vw8q

DbbS 2.0-alpha and earlier allows remote attackers to obtain sensitive information via an invalid (1) fcategoryid parameter to topics.php or (2) unavariabile, (3) GLOBALS, or (4) _SERVER[] parameters to script.php. NOTE: this information leak might be resultant from a global variable overwrite issue.

0%
Низкий
почти 4 года назад
github логотип
GHSA-34r8-h3gq-qmjj

UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34r8-fv4m-hxcv

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263924.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-34r8-4w7f-49v8

XnView 2.03 has a stack-based buffer overflow vulnerability

0%
Низкий
почти 4 года назад
github логотип
GHSA-34r7-q49f-h37c

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
github логотип
GHSA-34r6-xm35-5vcx

LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34r6-q8c8-23mx

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-34r6-9vgg-pmh3

The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-34r5-hj3h-jf22

JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

CVSS3: 2.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-34r5-4vr6-q5h6

In the Linux kernel, the following vulnerability has been resolved: bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO Precision markers need to be propagated whenever we have an ARG_CONST_* style argument, as the verifier cannot consider imprecise scalars to be equivalent for the purposes of states_equal check when such arguments refine the return value (in this case, set mem_size for PTR_TO_MEM). The resultant mem_size for the R0 is derived from the constant value, and if the verifier incorrectly prunes states considering them equivalent where such arguments exist (by seeing that both registers have reg->precise as false in regsafe), we can end up with invalid programs passing the verifier which can do access beyond what should have been the correct mem_size in that explored state. To show a concrete example of the problem: 0000000000000000 <prog>: 0: r2 = *(u32 *)(r1 + 80) 1: r1 = *(u32 *)(r1 + 76) 2: r3 = r1 3: r...

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-34r4-qfpx-74fg

Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-34r4-p9qh-fh37

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-34r4-h4c9-vmrj

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34r4-9973-43mq

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.

CVSS3: 6.1
10%
Низкий
почти 3 года назад
github логотип
GHSA-34r3-v64f-c8m6

Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34r3-h75p-74mh

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-34r2-vc72-3cjg

SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу