Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-342g-f49h-2w5g

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mighty Plugins Mighty Builder allows Stored XSS.This issue affects Mighty Builder: from n/a through 1.0.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-342f-jqfq-j38f

больше 3 лет назад

The CBSharedReviewSecurityDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.

EPSS: Низкий
github логотип

GHSA-342f-4vqf-w6hq

больше 3 лет назад

Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-342c-w38f-j4wc

около 3 лет назад

A vulnerability was found in intgr uqm-wasm. It has been classified as critical. This affects the function log_displayBox in the library sc2/src/libs/log/msgbox_macosx.m. The manipulation leads to format string. The name of the patch is 1d5cbf3350a02c423ad6bef6dfd5300d38aa828f. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217563.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-342c-vcff-2ff2

больше 3 лет назад

Login timing attack in ezsystems/ezplatform-kernel

EPSS: Низкий
github логотип

GHSA-342c-f869-5m44

больше 3 лет назад

Apache Sling POST Servlets Denial of Service Vulnerability

EPSS: Средний
github логотип

GHSA-3429-h97r-hqqx

8 месяцев назад

Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data.  This impacts OmniStudio: before version 254.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3429-2hmm-5vvx

больше 3 лет назад

A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3428-vpwf-2w42

почти 2 года назад

CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3427-99jp-r4g2

почти 2 года назад

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3426-w9wr-jxx4

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery.

EPSS: Низкий
github логотип

GHSA-3426-h5fc-ghj2

больше 3 лет назад

LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious php files that can be called under certain circumstances. This vulnerability appears to have been fixed in after commit 91d143230eb357260a19c8424b3005deb49a47f7 / version 3.14.4.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3425-gj4f-6wvw

почти 4 года назад

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.

EPSS: Низкий
github логотип

GHSA-3425-8q76-vpj9

больше 3 лет назад

Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to access information which would otherwise be restricted.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3424-mxvj-pcgx

3 месяца назад

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3424-fhhw-7h8h

больше 3 лет назад

The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data.

EPSS: Низкий
github логотип

GHSA-3422-7r3j-w49g

больше 1 года назад

A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via " searchifsccode" parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3422-45qx-4m3x

больше 3 лет назад

Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity with many IPv6 CPE devices, aka Bug ID CSCug47366.

EPSS: Низкий
github логотип

GHSA-33xx-xhf9-4h3m

почти 4 года назад

FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources.

EPSS: Низкий
github логотип

GHSA-33xx-v6xh-7w9j

больше 3 лет назад

In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-342g-f49h-2w5g

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mighty Plugins Mighty Builder allows Stored XSS.This issue affects Mighty Builder: from n/a through 1.0.2.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-342f-jqfq-j38f

The CBSharedReviewSecurityDialog method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-342f-4vqf-w6hq

Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges. The vulnerabilities are due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit these vulnerabilities by authenticating to the web-based management interface and sending crafted requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges. Note: The web-based management interface is enabled by default.

CVSS3: 8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-342c-w38f-j4wc

A vulnerability was found in intgr uqm-wasm. It has been classified as critical. This affects the function log_displayBox in the library sc2/src/libs/log/msgbox_macosx.m. The manipulation leads to format string. The name of the patch is 1d5cbf3350a02c423ad6bef6dfd5300d38aa828f. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217563.

CVSS3: 9.8
около 3 лет назад
github логотип
GHSA-342c-vcff-2ff2

Login timing attack in ezsystems/ezplatform-kernel

больше 3 лет назад
github логотип
GHSA-342c-f869-5m44

Apache Sling POST Servlets Denial of Service Vulnerability

38%
Средний
больше 3 лет назад
github логотип
GHSA-3429-h97r-hqqx

Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data.  This impacts OmniStudio: before version 254.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3429-2hmm-5vvx

A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3428-vpwf-2w42

CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3427-99jp-r4g2

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3426-w9wr-jxx4

Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3426-h5fc-ghj2

LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious php files that can be called under certain circumstances. This vulnerability appears to have been fixed in after commit 91d143230eb357260a19c8424b3005deb49a47f7 / version 3.14.4.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3425-gj4f-6wvw

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3425-8q76-vpj9

Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to access information which would otherwise be restricted.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3424-mxvj-pcgx

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS.

CVSS3: 8.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3424-fhhw-7h8h

The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3422-7r3j-w49g

A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via " searchifsccode" parameter.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3422-45qx-4m3x

Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity with many IPv6 CPE devices, aka Bug ID CSCug47366.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-33xx-xhf9-4h3m

FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources.

1%
Низкий
почти 4 года назад
github логотип
GHSA-33xx-v6xh-7w9j

In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу