Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 694

Количество 301 694

github логотип

GHSA-28fw-88hq-6jmm

около 5 лет назад

Persistent XSS in shopping worlds

EPSS: Низкий
github логотип

GHSA-28fv-xp4g-pphf

больше 1 года назад

Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-28fv-gqcc-g6m7

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-28fq-q3c7-php2

12 месяцев назад

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24448.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28fq-p2c7-42px

больше 3 лет назад

Secom Co. Dr.ID, a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers.

EPSS: Низкий
github логотип

GHSA-28fq-6473-mg5p

около 2 месяцев назад

Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution.This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

EPSS: Низкий
github логотип

GHSA-28fp-mw8j-xfc5

около 2 лет назад

The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-28fm-qh2h-3mch

около 3 лет назад

html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulnerability allows attackers to access sensitive files or cause a Denial of Service (DoS) via a crafted html file.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-28fj-h7cm-23g6

больше 3 лет назад

The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.

EPSS: Низкий
github логотип

GHSA-28fh-4j57-cc4w

больше 3 лет назад

A vulnerability in Trend Micro Apex One and OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28fh-3r6h-cgpw

больше 3 лет назад

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.

EPSS: Средний
github логотип

GHSA-28fg-r93m-m726

больше 2 лет назад

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28ff-x3xj-mx7q

больше 3 лет назад

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-31091777.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28fc-gvjg-5f4h

больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28f9-43w8-v45c

больше 3 лет назад

Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.

EPSS: Средний
github логотип

GHSA-28f8-hqmc-7ph8

около 5 лет назад

Malicious Package in ember-power-timepicker

EPSS: Низкий
github логотип

GHSA-28f7-mc45-4x8m

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from n/a through 1.6.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28f7-g5r5-mpx5

больше 2 лет назад

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28f6-9xpw-pwcr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.

EPSS: Низкий
github логотип

GHSA-28f6-647f-xq87

больше 3 лет назад

Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28fw-88hq-6jmm

Persistent XSS in shopping worlds

около 5 лет назад
github логотип
GHSA-28fv-xp4g-pphf

Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-28fv-gqcc-g6m7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28fq-q3c7-php2

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24448.

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-28fq-p2c7-42px

Secom Co. Dr.ID, a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28fq-6473-mg5p

Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution.This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-28fp-mw8j-xfc5

The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.

CVSS3: 8.6
2%
Низкий
около 2 лет назад
github логотип
GHSA-28fm-qh2h-3mch

html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulnerability allows attackers to access sensitive files or cause a Denial of Service (DoS) via a crafted html file.

CVSS3: 8.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-28fj-h7cm-23g6

The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-28fh-4j57-cc4w

A vulnerability in Trend Micro Apex One and OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28fh-3r6h-cgpw

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.

21%
Средний
больше 3 лет назад
github логотип
GHSA-28fg-r93m-m726

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

CVSS3: 8.8
3%
Низкий
больше 2 лет назад
github логотип
GHSA-28ff-x3xj-mx7q

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-31091777.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28fc-gvjg-5f4h

** UNSUPPORTED WHEN ASSIGNED ** The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28f9-43w8-v45c

Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.

29%
Средний
больше 3 лет назад
github логотип
GHSA-28f8-hqmc-7ph8

Malicious Package in ember-power-timepicker

около 5 лет назад
github логотип
GHSA-28f7-mc45-4x8m

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from n/a through 1.6.2.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-28f7-g5r5-mpx5

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28f6-9xpw-pwcr

Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28f6-647f-xq87

Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу