Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 405

Количество 300 405

github логотип

GHSA-23f5-q32q-xcxm

больше 3 лет назад

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23f5-gr55-w97f

больше 2 лет назад

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23f5-2x6m-443f

больше 3 лет назад

The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-23f4-r5mp-f393

больше 3 лет назад

In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user. This may allow a local attacker to break out of the restricted environment or inject malicious code into the application and fully compromise the operating system.

EPSS: Низкий
github логотип

GHSA-23f4-p98f-875g

больше 3 лет назад

Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.

EPSS: Низкий
github логотип

GHSA-23f4-32qx-cg2x

больше 3 лет назад

The master-station DNP3 driver before driver19.exe, and Beta2041.exe, in IOServer allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets to TCP port 20000.

EPSS: Низкий
github логотип

GHSA-23f3-vhq3-gx53

больше 3 лет назад

AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.

EPSS: Низкий
github логотип

GHSA-23f3-rj2m-g7gq

больше 3 лет назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose file contents in the context of SYSTEM. Was ZDI-CAN-10709.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-23f3-58hp-h48q

около 2 лет назад

The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-23f2-vgr6-fwv7

больше 3 лет назад

Command injection in librenms

EPSS: Низкий
github логотип

GHSA-23f2-m2wj-439r

больше 3 лет назад

In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23f2-7h54-3w8p

больше 3 лет назад

The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.

EPSS: Низкий
github логотип

GHSA-23f2-6pcg-vrwj

больше 3 лет назад

SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-23cx-vh2c-742x

больше 3 лет назад

The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows a local attack when a USB device is plugged in.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23cx-98wc-24qg

7 месяцев назад

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /xray_print.php. The manipulation of the argument itr_no leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23cx-5wrj-f57f

больше 3 лет назад

AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.

EPSS: Низкий
github логотип

GHSA-23cw-p4x6-mcqc

больше 3 лет назад

A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23cv-w96c-877f

7 месяцев назад

The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-23cv-jh4v-vffm

больше 3 лет назад

Denial of service in ASP.NET Core

EPSS: Низкий
github логотип

GHSA-23cv-hj48-7c4g

больше 3 лет назад

The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a user's personal position on the semantics of an attestation.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23f5-q32q-xcxm

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f5-gr55-w97f

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23f5-2x6m-443f

The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f4-r5mp-f393

In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user. This may allow a local attacker to break out of the restricted environment or inject malicious code into the application and fully compromise the operating system.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f4-p98f-875g

Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23f4-32qx-cg2x

The master-station DNP3 driver before driver19.exe, and Beta2041.exe, in IOServer allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets to TCP port 20000.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f3-vhq3-gx53

AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f3-rj2m-g7gq

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose file contents in the context of SYSTEM. Was ZDI-CAN-10709.

CVSS3: 7.5
22%
Средний
больше 3 лет назад
github логотип
GHSA-23f3-58hp-h48q

The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-23f2-vgr6-fwv7

Command injection in librenms

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f2-m2wj-439r

In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f2-7h54-3w8p

The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23f2-6pcg-vrwj

SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23cx-vh2c-742x

The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 Series vehicles produced in 2012 through 2018 allows a local attack when a USB device is plugged in.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23cx-98wc-24qg

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /xray_print.php. The manipulation of the argument itr_no leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-23cx-5wrj-f57f

AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23cw-p4x6-mcqc

A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23cv-w96c-877f

The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

CVSS3: 6.6
0%
Низкий
7 месяцев назад
github логотип
GHSA-23cv-jh4v-vffm

Denial of service in ASP.NET Core

4%
Низкий
больше 3 лет назад
github логотип
GHSA-23cv-hj48-7c4g

The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a user's personal position on the semantics of an attestation.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу