Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-33x7-98g2-hprp

больше 1 года назад

VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33x6-8x8r-9jpw

8 месяцев назад

The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-33x6-2v6v-hj27

больше 3 лет назад

In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33x5-jqpp-33fv

почти 2 года назад

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33x4-8657-2c2g

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: raw: Fix a data-race around sysctl_raw_l3mdev_accept. While reading sysctl_raw_l3mdev_accept, it can be changed concurrently. Thus, we need to add READ_ONCE() to its reader.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-33x4-757p-h9h8

3 месяца назад

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33x3-9w3j-2vw6

больше 2 лет назад

ASUS RT-AC86U’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system, or terminate services.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33x3-2r59-2wch

почти 4 года назад

Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the origin domain name of a script via a long name.

EPSS: Низкий
github логотип

GHSA-33x2-whwf-gwv7

около 2 месяцев назад

An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can be exploited by a local unprivileged user on default installations of the product. Insecure access to a named pipe allows unprivileged users to edit any registry key, leading to a full compromise as SYSTEM.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-33wx-mh64-x7f5

больше 3 лет назад

SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33wx-gh7x-xv44

около 1 года назад

Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33wx-8m27-jwj5

около 3 лет назад

The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-33ww-4588-wf76

больше 3 лет назад

Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33wv-m292-g2pv

больше 2 лет назад

Microsoft Office Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33wr-rmg5-rhwf

почти 4 года назад

Integer underflow in Preview in PDFKit on Apple Mac OS X 10.4.10 allows remote attackers to execute arbitrary code via a crafted PDF file.

EPSS: Низкий
github логотип

GHSA-33wr-mxv7-p2hc

больше 3 лет назад

A heap-based buffer over-read in SampleImage() in MagickCore/resize.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33wr-cf89-cggc

больше 3 лет назад

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows directory traversal for access to system files. The Samsung ID is SVE-2020-17665 (July 2020).

EPSS: Низкий
github логотип

GHSA-33wq-x9f3-95mh

больше 3 лет назад

In Core Kernel in all Android releases from CAF using the Linux kernel, a Null Pointer Dereference vulnerability could potentially exist.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33wp-c8x6-pv3w

почти 4 года назад

In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.

EPSS: Низкий
github логотип

GHSA-33wp-4xj7-xwqx

больше 3 лет назад

In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33x7-98g2-hprp

VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-33x6-8x8r-9jpw

The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

CVSS3: 2.9
0%
Низкий
8 месяцев назад
github логотип
GHSA-33x6-2v6v-hj27

In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33x5-jqpp-33fv

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-33x4-8657-2c2g

In the Linux kernel, the following vulnerability has been resolved: raw: Fix a data-race around sysctl_raw_l3mdev_accept. While reading sysctl_raw_l3mdev_accept, it can be changed concurrently. Thus, we need to add READ_ONCE() to its reader.

CVSS3: 4.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-33x4-757p-h9h8

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-33x3-9w3j-2vw6

ASUS RT-AC86U’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system, or terminate services.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-33x3-2r59-2wch

Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the origin domain name of a script via a long name.

1%
Низкий
почти 4 года назад
github логотип
GHSA-33x2-whwf-gwv7

An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can be exploited by a local unprivileged user on default installations of the product. Insecure access to a named pipe allows unprivileged users to edit any registry key, leading to a full compromise as SYSTEM.

CVSS3: 7.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-33wx-mh64-x7f5

SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33wx-gh7x-xv44

Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.5.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-33wx-8m27-jwj5

The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.

CVSS3: 6.1
28%
Средний
около 3 лет назад
github логотип
GHSA-33ww-4588-wf76

Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33wv-m292-g2pv

Microsoft Office Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33wr-rmg5-rhwf

Integer underflow in Preview in PDFKit on Apple Mac OS X 10.4.10 allows remote attackers to execute arbitrary code via a crafted PDF file.

1%
Низкий
почти 4 года назад
github логотип
GHSA-33wr-mxv7-p2hc

A heap-based buffer over-read in SampleImage() in MagickCore/resize.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33wr-cf89-cggc

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. StickerProvider allows directory traversal for access to system files. The Samsung ID is SVE-2020-17665 (July 2020).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33wq-x9f3-95mh

In Core Kernel in all Android releases from CAF using the Linux kernel, a Null Pointer Dereference vulnerability could potentially exist.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33wp-c8x6-pv3w

In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.

7%
Низкий
почти 4 года назад
github логотип
GHSA-33wp-4xj7-xwqx

In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу