Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2xrq-fg58-79g9

больше 3 лет назад

An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2xrp-v3fr-jqr7

больше 3 лет назад

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x000000000001f23e."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xrp-fqg8-p623

больше 3 лет назад

IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.

EPSS: Низкий
github логотип

GHSA-2xrp-4jrm-52gw

больше 3 лет назад

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-2xrm-mj2g-mf72

6 месяцев назад

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xrm-5j4x-838g

больше 3 лет назад

Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG references.

EPSS: Низкий
github логотип

GHSA-2xrj-wrq4-ff74

больше 3 лет назад

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The streaming service (default port 5410/tcp) of the SiNVR 3 Video Server applies weak cryptography when exposing device (camera) passwords. This could allow an unauthenticated remote attacker to read and decrypt the passwords and conduct further attacks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xrh-whv4-f7mq

7 месяцев назад

A vulnerability was found in code-projects Public Chat Room 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2xrh-r8pp-65w4

почти 4 года назад

The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a related issue to CVE-2015-8787.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xrh-pxx5-48rp

больше 3 лет назад

A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could gain access to path and filenames on the server by sending specifically crafted packets to 1099/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

EPSS: Низкий
github логотип

GHSA-2xrg-fw6r-w46h

больше 3 лет назад

An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure that a program was installed by root) and without integrity checks (e.g., a checksum comparison against known legitimate programs). Also, the vendor recommendation is to install this agent software with root privileges. Thus, privilege escalation is possible on systems where any of these pathnames is controlled by a non-root user. An example is /opt/firebird/bin/isql, where the /opt/firebird directory is often owned by the firebird user.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xrg-4jwx-p6xh

6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dimafreund Rentsyst allows Reflected XSS. This issue affects Rentsyst: from n/a through 2.0.100.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2xrf-r4mx-975v

больше 2 лет назад

The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2xrf-hq77-g825

больше 3 лет назад

The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2xrf-7rp5-6c2j

больше 3 лет назад

IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an incorrect password in conjunction with an account name from a different domain.

EPSS: Низкий
github логотип

GHSA-2xrc-mfj2-6vg5

почти 4 года назад

** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the langfile parameter is set to english.php in each file. NOTE: CVE also disputes a later report of this vulnerability in 1.2, because the langfile parameter is set to french.php in 1.2.

EPSS: Низкий
github логотип

GHSA-2xrc-jfhx-ghwr

больше 3 лет назад

treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xrc-27mc-638q

больше 3 лет назад

ChakraCore Remote code execution Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2xr9-8797-cf2f

почти 4 года назад

Azure Site Recovery Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24467, CVE-2022-24468, CVE-2022-24470, CVE-2022-24471, CVE-2022-24517.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2xr9-5cr4-4hfm

почти 4 года назад

Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xrq-fg58-79g9

An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrp-v3fr-jqr7

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x000000000001f23e."

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrp-fqg8-p623

IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrp-4jrm-52gw

An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrm-mj2g-mf72

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-2xrm-5j4x-838g

Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG references.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrj-wrq4-ff74

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The streaming service (default port 5410/tcp) of the SiNVR 3 Video Server applies weak cryptography when exposing device (camera) passwords. This could allow an unauthenticated remote attacker to read and decrypt the passwords and conduct further attacks.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrh-whv4-f7mq

A vulnerability was found in code-projects Public Chat Room 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2xrh-r8pp-65w4

The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a related issue to CVE-2015-8787.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2xrh-pxx5-48rp

A vulnerability has been identified in SPPA-T3000 Application Server (All versions). An attacker with network access to the Application Server could gain access to path and filenames on the server by sending specifically crafted packets to 1099/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrg-fw6r-w46h

An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure that a program was installed by root) and without integrity checks (e.g., a checksum comparison against known legitimate programs). Also, the vendor recommendation is to install this agent software with root privileges. Thus, privilege escalation is possible on systems where any of these pathnames is controlled by a non-root user. An example is /opt/firebird/bin/isql, where the /opt/firebird directory is often owned by the firebird user.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrg-4jwx-p6xh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dimafreund Rentsyst allows Reflected XSS. This issue affects Rentsyst: from n/a through 2.0.100.

CVSS3: 7.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-2xrf-r4mx-975v

The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2xrf-hq77-g825

The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrf-7rp5-6c2j

IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an incorrect password in conjunction with an account name from a different domain.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrc-mfj2-6vg5

** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the langfile parameter is set to english.php in each file. NOTE: CVE also disputes a later report of this vulnerability in 1.2, because the langfile parameter is set to french.php in 1.2.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2xrc-jfhx-ghwr

treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xrc-27mc-638q

ChakraCore Remote code execution Vulnerability

CVSS3: 7.5
13%
Средний
больше 3 лет назад
github логотип
GHSA-2xr9-8797-cf2f

Azure Site Recovery Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24467, CVE-2022-24468, CVE-2022-24470, CVE-2022-24471, CVE-2022-24517.

CVSS3: 7.2
7%
Низкий
почти 4 года назад
github логотип
GHSA-2xr9-5cr4-4hfm

Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу