Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2wx8-q5hg-8h5m

больше 3 лет назад

Ming (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c.

EPSS: Низкий
github логотип

GHSA-2wx8-6jj8-chhc

больше 3 лет назад

Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

EPSS: Низкий
github логотип

GHSA-2wx7-j39g-4p6g

11 месяцев назад

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.  This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2wx7-cf6v-q9v8

больше 3 лет назад

A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2wx7-3qvr-gm34

больше 3 лет назад

A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user with an active session on an affected device to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions, including modifying the configuration, with the privilege level of the user.

EPSS: Низкий
github логотип

GHSA-2wx6-wc87-rmjm

почти 6 лет назад

GitHub personal access token leaking into temporary EasyBuild (debug) logs

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2wx6-gjr5-cw6x

почти 4 года назад

PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter. NOTE: The relative_script_path vector is already covered by CVE-2006-2270.

EPSS: Низкий
github логотип

GHSA-2wx5-xx7r-5pp4

почти 3 года назад

A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2wx5-x3v9-h4fr

около 3 лет назад

72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wx5-pg32-77vx

больше 3 лет назад

Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.

EPSS: Низкий
github логотип

GHSA-2wx5-jfx2-287m

10 дней назад

A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. The manipulation of the argument dmzIp results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2wx4-jmwh-g7cc

больше 2 лет назад

Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbritrary shell commands.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2wx4-c69c-72wc

больше 3 лет назад

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2wx3-wgwm-8jh9

около 2 лет назад

Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2wx3-jm7x-4xg5

больше 1 года назад

The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the plugin settings, including adding stored cross-site scripting.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2wx2-v8rp-rqwr

около 2 лет назад

An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2wwx-6vph-p3wm

больше 2 лет назад

In jpeg, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07693193; Issue ID: ALPS07693193.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2wwx-4xj6-c38h

3 месяца назад

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including Google OAuth credentials (client_id and client_secret) and Google account email addresses.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2www-m95g-9xrh

больше 2 лет назад

The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wwv-3g3g-h8w3

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value devm_kasprintf() can return a NULL pointer on failure but this returned value is not checked. Fix this lack and check the returned value.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wx8-q5hg-8h5m

Ming (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wx8-6jj8-chhc

Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2wx7-j39g-4p6g

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.  This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

CVSS3: 7.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-2wx7-cf6v-q9v8

A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wx7-3qvr-gm34

A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user with an active session on an affected device to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions, including modifying the configuration, with the privilege level of the user.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wx6-wc87-rmjm

GitHub personal access token leaking into temporary EasyBuild (debug) logs

CVSS3: 7.7
0%
Низкий
почти 6 лет назад
github логотип
GHSA-2wx6-gjr5-cw6x

PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter. NOTE: The relative_script_path vector is already covered by CVE-2006-2270.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2wx5-xx7r-5pp4

A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-2wx5-x3v9-h4fr

72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2wx5-pg32-77vx

Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wx5-jfx2-287m

A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. The manipulation of the argument dmzIp results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
1%
Низкий
10 дней назад
github логотип
GHSA-2wx4-jmwh-g7cc

Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbritrary shell commands.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wx4-c69c-72wc

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wx3-wgwm-8jh9

Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2wx3-jm7x-4xg5

The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the plugin settings, including adding stored cross-site scripting.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2wx2-v8rp-rqwr

An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVSS3: 9.8
27%
Средний
около 2 лет назад
github логотип
GHSA-2wwx-6vph-p3wm

In jpeg, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07693193; Issue ID: ALPS07693193.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wwx-4xj6-c38h

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including Google OAuth credentials (client_id and client_secret) and Google account email addresses.

CVSS3: 7.5
28%
Средний
3 месяца назад
github логотип
GHSA-2www-m95g-9xrh

The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wwv-3g3g-h8w3

In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value devm_kasprintf() can return a NULL pointer on failure but this returned value is not checked. Fix this lack and check the returned value.

CVSS3: 5.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу