Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2wqp-mvhf-mj78

почти 3 года назад

In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245915315

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wqp-jmcc-mc77

почти 5 лет назад

Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wqp-c8qr-gw2j

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to inject arbitrary web script or HTML via the step parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2wqp-2j8m-7925

больше 3 лет назад

emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wqm-wj66-jfhg

больше 3 лет назад

The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wqm-v6p6-8mqx

больше 3 лет назад

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2wqm-g7m4-4gj8

почти 4 года назад

iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.

EPSS: Низкий
github логотип

GHSA-2wqh-23wf-9qr9

больше 1 года назад

Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through 1.2.6.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wqf-w23q-7294

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wqf-4598-f4f3

почти 4 года назад

Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path parameter.

EPSS: Низкий
github логотип

GHSA-2wqc-47g4-pm22

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Catch Themes Essential Widgets essential-widgets allows Stored XSS.This issue affects Essential Widgets: from n/a through <= 2.2.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wq9-hq2m-2hfq

больше 2 лет назад

The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2wq8-q24x-h8rw

больше 3 лет назад

Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.

EPSS: Низкий
github логотип

GHSA-2wq8-mxfj-4758

больше 3 лет назад

A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk application V1.12.5 and later.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wq7-x39p-77fm

больше 3 лет назад

Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media buffers.

EPSS: Низкий
github логотип

GHSA-2wq7-p5vp-5q7g

больше 3 лет назад

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper length check Validation in WLAN function can lead to driver writes the default rsn capabilities to the memory not allocated to the frame.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wq7-hx2p-5748

9 месяцев назад

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-2wq7-hcmr-3vvx

больше 3 лет назад

In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-73172115.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wq6-27jx-rfq7

больше 3 лет назад

Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2wq5-g96f-mv3v

больше 1 года назад

Ouch! allows a segmentation fault due to use of uninitialized memory

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wqp-mvhf-mj78

In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245915315

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2wqp-jmcc-mc77

Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-2wqp-c8qr-gw2j

Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to inject arbitrary web script or HTML via the step parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wqp-2j8m-7925

emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wqm-wj66-jfhg

The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wqm-v6p6-8mqx

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wqm-g7m4-4gj8

iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wqh-23wf-9qr9

Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through 1.2.6.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2wqf-w23q-7294

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wqf-4598-f4f3

Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path parameter.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2wqc-47g4-pm22

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Catch Themes Essential Widgets essential-widgets allows Stored XSS.This issue affects Essential Widgets: from n/a through <= 2.2.2.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-2wq9-hq2m-2hfq

The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wq8-q24x-h8rw

Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wq8-mxfj-4758

A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk application V1.12.5 and later.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wq7-x39p-77fm

Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media buffers.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wq7-p5vp-5q7g

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper length check Validation in WLAN function can lead to driver writes the default rsn capabilities to the memory not allocated to the frame.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wq7-hx2p-5748

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 8.7
0%
Низкий
9 месяцев назад
github логотип
GHSA-2wq7-hcmr-3vvx

In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-73172115.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2wq6-27jx-rfq7

Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wq5-g96f-mv3v

Ouch! allows a segmentation fault due to use of uninitialized memory

больше 1 года назад

Уязвимостей на страницу