Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2wcr-87wf-cf9j

почти 3 года назад

Kiwi TCMS Stored Cross-site Scripting via SVG file

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2wcq-j266-p9cq

больше 3 лет назад

Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wcq-c54q-w79p

больше 3 лет назад

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the JPEG decoder routine. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wcq-89pp-jvvv

больше 3 лет назад

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.

EPSS: Низкий
github логотип

GHSA-2wcq-5m3f-4rfw

почти 4 года назад

SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2wcq-5jhh-r94q

10 дней назад

The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings, including reCAPTCHA keys, security settings, and frontend menu titles.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2wcp-wj82-j6vw

больше 3 лет назад

bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).

EPSS: Низкий
github логотип

GHSA-2wcp-prmg-9pr7

почти 4 года назад

iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak.

EPSS: Низкий
github логотип

GHSA-2wcp-6fq9-mcr6

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field If driver read val value sufficient for (val & 0x08) && (!(val & 0x80)) && ((val & 0x7) == ((val >> 4) & 0x7)) from device then Null pointer dereference occurs. (It is possible if tmp = 0b0xyz1xyz, where same literals mean same numbers) Also lm75[] does not serve a purpose anymore after switching to devm_i2c_new_dummy_device() in w83791d_detect_subclients(). The patch fixes possible NULL pointer dereference by removing lm75[]. Found by Linux Driver Verification project (linuxtesting.org). [groeck: Dropped unnecessary continuation lines, fixed multi-line alignment]

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wcm-vx67-3x4q

7 месяцев назад

Duplicate Advisory: GHSA-x698-5hjm-w2m5

EPSS: Низкий
github логотип

GHSA-2wcj-qr76-9768

около 2 лет назад

PaddlePaddle segfault in paddle.put_along_axis

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2wcj-p2hm-6ff7

больше 3 лет назад

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

EPSS: Средний
github логотип

GHSA-2wch-qhpr-mqp5

больше 3 лет назад

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

EPSS: Критический
github логотип

GHSA-2wch-pp5g-pc57

больше 3 лет назад

The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wch-9pmc-8h8m

больше 3 лет назад

In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2wcg-78mh-f9m8

почти 4 года назад

Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.

EPSS: Низкий
github логотип

GHSA-2wcf-8w35-jp7x

больше 3 лет назад

Microsoft SharePoint Spoofing Vulnerability This CVE ID is unique from CVE-2020-17015, CVE-2020-17060.

CVSS3: 8
EPSS: Средний
github логотип

GHSA-2wcf-7wvx-2jw3

почти 4 года назад

Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.

EPSS: Низкий
github логотип

GHSA-2wcf-273g-9c2w

почти 2 года назад

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263110 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2wc9-q6m7-wqrq

больше 3 лет назад

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wcr-87wf-cf9j

Kiwi TCMS Stored Cross-site Scripting via SVG file

CVSS3: 7.6
1%
Низкий
почти 3 года назад
github логотип
GHSA-2wcq-j266-p9cq

Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wcq-c54q-w79p

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the JPEG decoder routine. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2wcq-89pp-jvvv

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wcq-5m3f-4rfw

SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wcq-5jhh-r94q

The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings, including reCAPTCHA keys, security settings, and frontend menu titles.

CVSS3: 5.3
0%
Низкий
10 дней назад
github логотип
GHSA-2wcp-wj82-j6vw

bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wcp-prmg-9pr7

iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wcp-6fq9-mcr6

In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field If driver read val value sufficient for (val & 0x08) && (!(val & 0x80)) && ((val & 0x7) == ((val >> 4) & 0x7)) from device then Null pointer dereference occurs. (It is possible if tmp = 0b0xyz1xyz, where same literals mean same numbers) Also lm75[] does not serve a purpose anymore after switching to devm_i2c_new_dummy_device() in w83791d_detect_subclients(). The patch fixes possible NULL pointer dereference by removing lm75[]. Found by Linux Driver Verification project (linuxtesting.org). [groeck: Dropped unnecessary continuation lines, fixed multi-line alignment]

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2wcm-vx67-3x4q

Duplicate Advisory: GHSA-x698-5hjm-w2m5

7 месяцев назад
github логотип
GHSA-2wcj-qr76-9768

PaddlePaddle segfault in paddle.put_along_axis

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-2wcj-p2hm-6ff7

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

23%
Средний
больше 3 лет назад
github логотип
GHSA-2wch-qhpr-mqp5

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

91%
Критический
больше 3 лет назад
github логотип
GHSA-2wch-pp5g-pc57

The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wch-9pmc-8h8m

In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wcg-78mh-f9m8

Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.

10%
Низкий
почти 4 года назад
github логотип
GHSA-2wcf-8w35-jp7x

Microsoft SharePoint Spoofing Vulnerability This CVE ID is unique from CVE-2020-17015, CVE-2020-17060.

CVSS3: 8
17%
Средний
больше 3 лет назад
github логотип
GHSA-2wcf-7wvx-2jw3

Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wcf-273g-9c2w

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263110 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-2wc9-q6m7-wqrq

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу