Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-344w-5936-x3fq

больше 3 лет назад

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

EPSS: Низкий
github логотип

GHSA-344v-v752-rwcm

больше 3 лет назад

The mint function of a smart contract implementation for kkTestCoin1 (KTC1), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-344v-jr69-x57c

больше 3 лет назад

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.

EPSS: Низкий
github логотип

GHSA-344r-g579-ppxg

около 3 лет назад

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21543, CVE-2023-21546, CVE-2023-21556, CVE-2023-21679.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-344r-8fg9-xhm9

больше 1 года назад

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-344q-xw48-jxqf

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-344p-v638-q9gc

больше 3 лет назад

A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function tst_timer of the file drivers/atm/idt77252.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. VDB-211934 is the identifier assigned to this vulnerability.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-344m-qcjq-xgrf

почти 3 года назад

Vulnerable OpenSSL included in sgx-dcap-quote-verify-python

EPSS: Низкий
github логотип

GHSA-344m-9hp3-hgr7

больше 3 лет назад

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-news.php by adding a question mark (?) followed by the payload.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-344m-62pc-2wvw

около 4 лет назад

Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-344h-xj76-vwrq

3 месяца назад

A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to root.This issue affects lightdm-kde-greeter. before 6.0.4.

EPSS: Низкий
github логотип

GHSA-344g-jvx4-773r

больше 1 года назад

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style.php file, along with missing capability checks. This makes it possible for unauthenticated attackers to execute code on the server. This issue was partially patched in 2.8.6 when the code injection issue was resolved, and fully patched in 2.8.7 when the missing authorization and cross-site request forgery protection was added.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-344f-vx7h-jfh2

больше 3 лет назад

Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-344f-f5vg-2jfj

больше 5 лет назад

Potential remote code execution in Apache Tomcat

CVSS3: 7
EPSS: Критический
github логотип

GHSA-344f-3xh7-82cg

почти 2 года назад

Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into a webpage. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3449-q73h-pp22

около 4 лет назад

Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via snquote at src/mjs_json.c.

EPSS: Низкий
github логотип

GHSA-3448-wp7r-84q4

больше 3 лет назад

In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140419401

EPSS: Низкий
github логотип

GHSA-3448-vrgh-85xr

больше 4 лет назад

NULL Pointer Dereference in OpenCV.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3448-vfvv-xp9g

около 7 лет назад

Apache Tika Denial of Service due to Infinite Loop in Tika's SQLite3Parser

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3448-h4p5-g6mc

больше 3 лет назад

All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-344w-5936-x3fq

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-344v-v752-rwcm

The mint function of a smart contract implementation for kkTestCoin1 (KTC1), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-344v-jr69-x57c

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-344r-g579-ppxg

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21543, CVE-2023-21546, CVE-2023-21556, CVE-2023-21679.

CVSS3: 8.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-344r-8fg9-xhm9

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-344q-xw48-jxqf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-344p-v638-q9gc

A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function tst_timer of the file drivers/atm/idt77252.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. VDB-211934 is the identifier assigned to this vulnerability.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-344m-qcjq-xgrf

Vulnerable OpenSSL included in sgx-dcap-quote-verify-python

почти 3 года назад
github логотип
GHSA-344m-9hp3-hgr7

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-news.php by adding a question mark (?) followed by the payload.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-344m-62pc-2wvw

Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-344h-xj76-vwrq

A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to root.This issue affects lightdm-kde-greeter. before 6.0.4.

0%
Низкий
3 месяца назад
github логотип
GHSA-344g-jvx4-773r

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style.php file, along with missing capability checks. This makes it possible for unauthenticated attackers to execute code on the server. This issue was partially patched in 2.8.6 when the code injection issue was resolved, and fully patched in 2.8.7 when the missing authorization and cross-site request forgery protection was added.

CVSS3: 9.8
72%
Высокий
больше 1 года назад
github логотип
GHSA-344f-vx7h-jfh2

Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-344f-f5vg-2jfj

Potential remote code execution in Apache Tomcat

CVSS3: 7
93%
Критический
больше 5 лет назад
github логотип
GHSA-344f-3xh7-82cg

Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into a webpage. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser.

CVSS3: 5.4
4%
Низкий
почти 2 года назад
github логотип
GHSA-3449-q73h-pp22

Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via snquote at src/mjs_json.c.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3448-wp7r-84q4

In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140419401

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3448-vrgh-85xr

NULL Pointer Dereference in OpenCV.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3448-vfvv-xp9g

Apache Tika Denial of Service due to Infinite Loop in Tika's SQLite3Parser

CVSS3: 6.5
3%
Низкий
около 7 лет назад
github логотип
GHSA-3448-h4p5-g6mc

All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу