Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-33cc-8pcc-ph75

почти 4 года назад

webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers a crash in the ws_decodepassword function; or (2) a header line without a ':' character, which triggers a crash in the ws_getheaders function.

EPSS: Средний
github логотип

GHSA-33c9-rppf-m7fq

больше 3 лет назад

Backdrop CMS Unrestricted File Upload vulnerability

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-33c9-mwcv-qmqf

8 месяцев назад

The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-33c8-ggqv-8g5p

больше 3 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33c8-cpc2-747q

больше 3 лет назад

SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33c8-c6vf-6wgg

больше 3 лет назад

On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.

EPSS: Низкий
github логотип

GHSA-33c8-2qq8-ffcg

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DynamicWebLab Dynamic Post Grid Elementor Addon allows DOM-Based XSS.This issue affects Dynamic Post Grid Elementor Addon: from n/a through 1.0.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33c7-g5wf-767m

больше 3 лет назад

SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands via the singerid parameter in a singers action.

EPSS: Низкий
github логотип

GHSA-33c7-f9jv-pmxj

почти 4 года назад

Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first parameter value could be passed to the ShellExecuteW API. The passed parameter is an arbitrary code to be executed. Remote attackers can use this vulnerability to execute arbitrary remote code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33c7-37w4-x2xm

больше 3 лет назад

Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachments via vectors related to duplicate messages.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-33c7-2mpw-hg34

больше 5 лет назад

Log injection in uvicorn

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33c6-jw29-2569

больше 3 лет назад

libmobi before v0.10 contains a NULL pointer dereference via the component mobi_buffer_getpointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mobi file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33c6-85j7-6xcp

больше 3 лет назад

SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33c5-xpjg-3vv5

больше 3 лет назад

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

EPSS: Низкий
github логотип

GHSA-33c5-j9v5-cwqf

8 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33c5-fq57-8p37

больше 3 лет назад

An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33c5-cxgm-mjpc

больше 3 лет назад

A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-33c5-9fx5-fvjm

почти 2 года назад

Privilege Escalation in Kubernetes

CVSS3: 6.8
EPSS: Средний
github логотип

GHSA-33c4-r3r9-gr9g

больше 3 лет назад

Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc79922.

EPSS: Низкий
github логотип

GHSA-33c4-f7cm-95m7

больше 2 лет назад

Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33cc-8pcc-ph75

webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers a crash in the ws_decodepassword function; or (2) a header line without a ':' character, which triggers a crash in the ws_getheaders function.

15%
Средний
почти 4 года назад
github логотип
GHSA-33c9-rppf-m7fq

Backdrop CMS Unrestricted File Upload vulnerability

CVSS3: 7.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-33c9-mwcv-qmqf

The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-33c8-ggqv-8g5p

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-33c8-cpc2-747q

SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33c8-c6vf-6wgg

On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33c8-2qq8-ffcg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DynamicWebLab Dynamic Post Grid Elementor Addon allows DOM-Based XSS.This issue affects Dynamic Post Grid Elementor Addon: from n/a through 1.0.6.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-33c7-g5wf-767m

SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands via the singerid parameter in a singers action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33c7-f9jv-pmxj

Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the execBrowser function is ‘default’, the first parameter value could be passed to the ShellExecuteW API. The passed parameter is an arbitrary code to be executed. Remote attackers can use this vulnerability to execute arbitrary remote code.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-33c7-37w4-x2xm

Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachments via vectors related to duplicate messages.

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33c7-2mpw-hg34

Log injection in uvicorn

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-33c6-jw29-2569

libmobi before v0.10 contains a NULL pointer dereference via the component mobi_buffer_getpointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mobi file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33c6-85j7-6xcp

SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33c5-xpjg-3vv5

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33c5-j9v5-cwqf

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-33c5-fq57-8p37

An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33c5-cxgm-mjpc

A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.

CVSS3: 8.8
42%
Средний
больше 3 лет назад
github логотип
GHSA-33c5-9fx5-fvjm

Privilege Escalation in Kubernetes

CVSS3: 6.8
60%
Средний
почти 2 года назад
github логотип
GHSA-33c4-r3r9-gr9g

Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc79922.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-33c4-f7cm-95m7

Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу