Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-32pc-g2wc-v836

около 2 лет назад

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-32p9-x7g8-8m43

8 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-32p9-vr87-6gx3

больше 2 лет назад

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, including the submitter's first name.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32p9-v6w3-v6fj

11 месяцев назад

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered or arbitrary code may be executed by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-32p9-9c2j-m88v

почти 4 года назад

PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plug_path parameter.

EPSS: Низкий
github логотип

GHSA-32p9-664j-q6j6

больше 3 лет назад

libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32p8-xhh6-v239

почти 4 года назад

SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

EPSS: Низкий
github логотип

GHSA-32p8-qq6w-3v8c

больше 3 лет назад

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32p7-7q74-w9jv

почти 3 года назад

An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-32p5-w624-64gp

около 2 лет назад

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252128. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-32p5-cp5f-35r6

около 2 лет назад

Rejected reason: NON Security Issue.

EPSS: Низкий
github логотип

GHSA-32p4-jg2m-x4r7

почти 4 года назад

Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

EPSS: Низкий
github логотип

GHSA-32p4-jcjv-28cx

почти 4 года назад

add_bookmark.php in Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to add arbitrary bookmarks as other users using a modified auth_user_id parameter.

EPSS: Низкий
github логотип

GHSA-32p4-gm2c-wmch

больше 1 года назад

ansible-core Incorrect Authorization vulnerability

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-32p4-8723-vw5m

почти 4 года назад

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer saveHistory Use After Free Vulnerability."

EPSS: Средний
github логотип

GHSA-32p3-vxg7-c4m2

больше 3 лет назад

Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.

EPSS: Низкий
github логотип

GHSA-32p2-vr3j-c4gw

почти 2 года назад

The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 4.2.2. This makes it possible for authenticated attackers, with subscrber-level access and above, to retrieve post content that is password protected and/or private.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32p2-rghv-w56x

больше 3 лет назад

In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-32p2-76xv-rj3g

почти 4 года назад

Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory.

EPSS: Средний
github логотип

GHSA-32p2-3fx9-4m6x

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jennifer Hall Filmix allows Reflected XSS.This issue affects Filmix: from n/a through 1.1.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32pc-g2wc-v836

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.

CVSS3: 6.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-32p9-x7g8-8m43

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-32p9-vr87-6gx3

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_first_name' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about arbitrary form submissions, including the submitter's first name.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32p9-v6w3-v6fj

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered or arbitrary code may be executed by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-32p9-9c2j-m88v

PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plug_path parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-32p9-664j-q6j6

libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32p8-xhh6-v239

SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32p8-qq6w-3v8c

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32p7-7q74-w9jv

An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.

CVSS3: 9.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-32p5-w624-64gp

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252128. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-32p5-cp5f-35r6

Rejected reason: NON Security Issue.

около 2 лет назад
github логотип
GHSA-32p4-jg2m-x4r7

Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-32p4-jcjv-28cx

add_bookmark.php in Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to add arbitrary bookmarks as other users using a modified auth_user_id parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32p4-gm2c-wmch

ansible-core Incorrect Authorization vulnerability

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-32p4-8723-vw5m

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer saveHistory Use After Free Vulnerability."

40%
Средний
почти 4 года назад
github логотип
GHSA-32p3-vxg7-c4m2

Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-32p2-vr3j-c4gw

The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 4.2.2. This makes it possible for authenticated attackers, with subscrber-level access and above, to retrieve post content that is password protected and/or private.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-32p2-rghv-w56x

In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart.

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32p2-76xv-rj3g

Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory.

23%
Средний
почти 4 года назад
github логотип
GHSA-32p2-3fx9-4m6x

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jennifer Hall Filmix allows Reflected XSS.This issue affects Filmix: from n/a through 1.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу