Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 538

Количество 301 538

github логотип

GHSA-27mx-p3cq-xm25

больше 3 лет назад

Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.

EPSS: Средний
github логотип

GHSA-27mx-gchc-6xjp

больше 3 лет назад

Unhandled crash in npm posix

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27mx-5g65-22g6

12 месяцев назад

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-27mw-8p8v-6j5h

22 дня назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.

EPSS: Низкий
github логотип

GHSA-27mw-6w9p-cpx7

больше 3 лет назад

The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-27mv-c3gh-hv8r

6 месяцев назад

When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27mv-5vpc-8g53

больше 2 лет назад

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-27mr-8vvw-x4gr

11 месяцев назад

The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-27mq-645j-xwfx

больше 3 лет назад

Non-secure SW can cause SDCC to generate secure bus accesses, which may expose RPM access in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27mm-rpgf-cvhw

больше 2 лет назад

An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27mm-mp84-cq8h

больше 3 лет назад

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.

EPSS: Низкий
github логотип

GHSA-27mm-gc33-cv78

2 дня назад

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27mm-4rvr-4q6h

больше 1 года назад

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to import courses.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-27mm-4p4v-5qpj

больше 3 лет назад

D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27mh-mg4q-xvj9

больше 3 лет назад

PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter.

EPSS: Низкий
github логотип

GHSA-27mh-3343-6hg5

больше 3 лет назад

dhowden tag panic due to out-of-bounds read

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27mf-h76r-wrj9

6 месяцев назад

A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to modify protected parts of the file system.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27mf-ghqm-j3j8

12 месяцев назад

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27mc-9399-r9mx

14 дней назад

Drupal Access code allows Brute Force Attempts

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-27m8-q4mw-5g3g

больше 3 лет назад

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27mx-p3cq-xm25

Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.

30%
Средний
больше 3 лет назад
github логотип
GHSA-27mx-gchc-6xjp

Unhandled crash in npm posix

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27mx-5g65-22g6

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.

CVSS3: 5.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-27mw-8p8v-6j5h

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.

0%
Низкий
22 дня назад
github логотип
GHSA-27mw-6w9p-cpx7

The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27mv-c3gh-hv8r

When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-27mv-5vpc-8g53

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.

CVSS3: 7.5
80%
Высокий
больше 2 лет назад
github логотип
GHSA-27mr-8vvw-x4gr

The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
3%
Низкий
11 месяцев назад
github логотип
GHSA-27mq-645j-xwfx

Non-secure SW can cause SDCC to generate secure bus accesses, which may expose RPM access in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27mm-rpgf-cvhw

An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-27mm-mp84-cq8h

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-27mm-gc33-cv78

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVSS3: 7.5
0%
Низкий
2 дня назад
github логотип
GHSA-27mm-4rvr-4q6h

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to import courses.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-27mm-4p4v-5qpj

D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27mh-mg4q-xvj9

PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-27mh-3343-6hg5

dhowden tag panic due to out-of-bounds read

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27mf-h76r-wrj9

A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to modify protected parts of the file system.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-27mf-ghqm-j3j8

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

CVSS3: 7.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-27mc-9399-r9mx

Drupal Access code allows Brute Force Attempts

CVSS3: 6.3
0%
Низкий
14 дней назад
github логотип
GHSA-27m8-q4mw-5g3g

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

53%
Средний
больше 3 лет назад

Уязвимостей на страницу