Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 330

Количество 301 330

github логотип

GHSA-273j-3w9c-cwgw

почти 3 года назад

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-273h-mfpf-cvq6

больше 1 года назад

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF (Use-After-Free) vulnerability.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-273h-28gx-8f5j

почти 2 года назад

A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-273g-rphj-ghmm

больше 3 лет назад

Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-273g-8x52-9gmv

больше 1 года назад

Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-273f-xq73-5xpg

больше 3 лет назад

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-273f-pp2q-7h53

больше 1 года назад

A vulnerability classified as critical was found in itsourcecode Alton Management System 1.0. This vulnerability affects unknown code of the file search.php. The manipulation of the argument rcode leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273142 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-273f-4jvc-r526

больше 3 лет назад

** DISPUTED ** Integer signedness error in the pmcraid_ioctl_passthrough function in drivers/scsi/pmcraid.c in the Linux kernel before 3.1 might allow local users to cause a denial of service (memory consumption or memory corruption) via a negative size value in an ioctl call. NOTE: this may be a vulnerability only in unusual environments that provide a privileged program for obtaining the required file descriptor.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-273f-4hpp-885q

больше 3 лет назад

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0651.

EPSS: Средний
github логотип

GHSA-273c-fjw8-v2w8

больше 3 лет назад

Jenkins OpsGenie Plugin Plaintext Storage of a Password vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-273c-f2cx-c649

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: efi/fdt: fix panic when no valid fdt found setup_arch() would invoke efi_init()->efi_get_fdt_params(). If no valid fdt found then initial_boot_params will be null. So we should stop further fdt processing here. I encountered this issue on risc-v.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-273c-54fq-2595

6 месяцев назад

In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-273c-4g26-4jpm

13 дней назад

Apache Airflow `/api/v2/dagReports` executes DAG Python in API

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-273c-3m7m-qmj2

больше 3 лет назад

Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-2739-vvgg-6rwf

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config allows Reflected XSS. This issue affects TinyMCE Extended Config: from n/a through 0.1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2739-p2pg-h53m

около 3 лет назад

The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2739-422w-8mjf

больше 3 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2738-x33m-p89q

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allow remote attackers to inject arbitrary web script or HTML via vectors related to Search forms.

EPSS: Низкий
github логотип

GHSA-2738-rgv4-92wj

больше 1 года назад

Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2737-gp9h-gmmc

почти 2 года назад

IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+27ef heap-based out-of-bounds write.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-273j-3w9c-cwgw

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-273h-mfpf-cvq6

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF (Use-After-Free) vulnerability.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-273h-28gx-8f5j

A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-273g-rphj-ghmm

Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-273g-8x52-9gmv

Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-273f-xq73-5xpg

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-273f-pp2q-7h53

A vulnerability classified as critical was found in itsourcecode Alton Management System 1.0. This vulnerability affects unknown code of the file search.php. The manipulation of the argument rcode leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273142 is the identifier assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-273f-4jvc-r526

** DISPUTED ** Integer signedness error in the pmcraid_ioctl_passthrough function in drivers/scsi/pmcraid.c in the Linux kernel before 3.1 might allow local users to cause a denial of service (memory consumption or memory corruption) via a negative size value in an ioctl call. NOTE: this may be a vulnerability only in unusual environments that provide a privileged program for obtaining the required file descriptor.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-273f-4hpp-885q

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0651.

34%
Средний
больше 3 лет назад
github логотип
GHSA-273c-fjw8-v2w8

Jenkins OpsGenie Plugin Plaintext Storage of a Password vulnerability

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-273c-f2cx-c649

In the Linux kernel, the following vulnerability has been resolved: efi/fdt: fix panic when no valid fdt found setup_arch() would invoke efi_init()->efi_get_fdt_params(). If no valid fdt found then initial_boot_params will be null. So we should stop further fdt processing here. I encountered this issue on risc-v.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-273c-54fq-2595

In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.

CVSS3: 5
0%
Низкий
6 месяцев назад
github логотип
GHSA-273c-4g26-4jpm

Apache Airflow `/api/v2/dagReports` executes DAG Python in API

CVSS3: 5.4
0%
Низкий
13 дней назад
github логотип
GHSA-273c-3m7m-qmj2

Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2739-vvgg-6rwf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config allows Reflected XSS. This issue affects TinyMCE Extended Config: from n/a through 0.1.0.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-2739-p2pg-h53m

The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.

CVSS3: 4.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-2739-422w-8mjf

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2738-x33m-p89q

Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allow remote attackers to inject arbitrary web script or HTML via vectors related to Search forms.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2738-rgv4-92wj

Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2737-gp9h-gmmc

IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+27ef heap-based out-of-bounds write.

CVSS3: 9.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу