Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 518

Количество 300 518

github логотип

GHSA-24jp-gg22-pxj3

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24jp-cwv2-qjwh

больше 3 лет назад

Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and earlier for Perl allows remote attackers to cause a denial of service (CPU consumption) via a crafted string containing a list of e-mail addresses in conjunction with parenthesis characters that can be associated with nested comments. NOTE: the default configuration in 1.908 mitigates this vulnerability but misparses certain realistic comments.

EPSS: Низкий
github логотип

GHSA-24jm-j25m-87p2

больше 3 лет назад

In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24jj-j75x-h48w

больше 2 лет назад

The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24jj-74cf-p75p

больше 3 лет назад

The MGCP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S11 allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug ID CSCsl39126.

EPSS: Низкий
github логотип

GHSA-24jj-2qmr-wg2p

почти 2 года назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24jh-wh5j-3j8m

больше 2 лет назад

No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags within Rest API documentation.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-24jh-rrw8-fr8w

больше 3 лет назад

Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information, contrary to specifications.

EPSS: Низкий
github логотип

GHSA-24jg-p7g4-p8rm

больше 3 лет назад

An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1179, CVE-2019-1180, CVE-2019-1186.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24jg-h6v2-qfrg

больше 3 лет назад

Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.

EPSS: Низкий
github логотип

GHSA-24jf-3vhr-fw23

больше 3 лет назад

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24jf-233j-q8x3

больше 3 лет назад

An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-24jc-w55j-5p83

больше 3 лет назад

Jenkins TAP Plugin allows Path Traversal

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24j8-j3f5-wfw6

больше 3 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-24j6-cgww-3pm6

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Format events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6355.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24j6-88m8-2wx3

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: coresight: cti: Fix hang in cti_disable_hw() cti_enable_hw() and cti_disable_hw() are called from an atomic context so shouldn't use runtime PM because it can result in a sleep when communicating with firmware. Since commit 3c6656337852 ("Revert "firmware: arm_scmi: Add clock management to the SCMI power domain""), this causes a hang on Juno when running the Perf Coresight tests or running this command: perf record -e cs_etm//u -- ls This was also missed until the revert commit because pm_runtime_put() was called with the wrong device until commit 692c9a499b28 ("coresight: cti: Correct the parameter for pm_runtime_put") With lock and scheduler debugging enabled the following is output: coresight cti_sys0: cti_enable_hw -- dev:cti_sys0 parent: 20020000.cti BUG: sleeping function called from invalid context at drivers/base/power/runtime.c:1151 in_atomic(): 1, irqs_disabled(): 128, non_block: 0, pid:...

EPSS: Низкий
github логотип

GHSA-24j5-267c-mjxv

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in CodeAndMore WP Page Widget plugin <= 3.9 on WordPress leading to plugin settings change.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24j4-xmfv-849m

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Adrian Moreno WP Lyrics allows Stored XSS.This issue affects WP Lyrics: from n/a through 0.4.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24j3-w3xq-4r3w

7 месяцев назад

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-24j2-jggq-gp96

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thiudis Custom Menu allows Stored XSS. This issue affects Custom Menu: from n/a through 1.8.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24jp-gg22-pxj3

Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-24jp-cwv2-qjwh

Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and earlier for Perl allows remote attackers to cause a denial of service (CPU consumption) via a crafted string containing a list of e-mail addresses in conjunction with parenthesis characters that can be associated with nested comments. NOTE: the default configuration in 1.908 mitigates this vulnerability but misparses certain realistic comments.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-24jm-j25m-87p2

In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24jj-j75x-h48w

The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24jj-74cf-p75p

The MGCP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S11 allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug ID CSCsl39126.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-24jj-2qmr-wg2p

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-24jh-wh5j-3j8m

No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags within Rest API documentation.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24jh-rrw8-fr8w

Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information, contrary to specifications.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-24jg-p7g4-p8rm

An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1179, CVE-2019-1180, CVE-2019-1186.

CVSS3: 7.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-24jg-h6v2-qfrg

Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-24jf-3vhr-fw23

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24jf-233j-q8x3

An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).

CVSS3: 9.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24jc-w55j-5p83

Jenkins TAP Plugin allows Path Traversal

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24j8-j3f5-wfw6

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24j6-cgww-3pm6

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Format events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6355.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24j6-88m8-2wx3

In the Linux kernel, the following vulnerability has been resolved: coresight: cti: Fix hang in cti_disable_hw() cti_enable_hw() and cti_disable_hw() are called from an atomic context so shouldn't use runtime PM because it can result in a sleep when communicating with firmware. Since commit 3c6656337852 ("Revert "firmware: arm_scmi: Add clock management to the SCMI power domain""), this causes a hang on Juno when running the Perf Coresight tests or running this command: perf record -e cs_etm//u -- ls This was also missed until the revert commit because pm_runtime_put() was called with the wrong device until commit 692c9a499b28 ("coresight: cti: Correct the parameter for pm_runtime_put") With lock and scheduler debugging enabled the following is output: coresight cti_sys0: cti_enable_hw -- dev:cti_sys0 parent: 20020000.cti BUG: sleeping function called from invalid context at drivers/base/power/runtime.c:1151 in_atomic(): 1, irqs_disabled(): 128, non_block: 0, pid:...

0%
Низкий
около 1 месяца назад
github логотип
GHSA-24j5-267c-mjxv

Cross-Site Request Forgery (CSRF) vulnerability in CodeAndMore WP Page Widget plugin <= 3.9 on WordPress leading to plugin settings change.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-24j4-xmfv-849m

Cross-Site Request Forgery (CSRF) vulnerability in Adrian Moreno WP Lyrics allows Stored XSS.This issue affects WP Lyrics: from n/a through 0.4.1.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-24j3-w3xq-4r3w

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function.

CVSS3: 7.6
0%
Низкий
7 месяцев назад
github логотип
GHSA-24j2-jggq-gp96

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thiudis Custom Menu allows Stored XSS. This issue affects Custom Menu: from n/a through 1.8.

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу