Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2wcm-vx67-3x4q

7 месяцев назад

Duplicate Advisory: GHSA-x698-5hjm-w2m5

EPSS: Низкий
github логотип

GHSA-2wcj-qr76-9768

около 2 лет назад

PaddlePaddle segfault in paddle.put_along_axis

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2wcj-p2hm-6ff7

больше 3 лет назад

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

EPSS: Средний
github логотип

GHSA-2wch-qhpr-mqp5

больше 3 лет назад

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

EPSS: Критический
github логотип

GHSA-2wch-pp5g-pc57

больше 3 лет назад

The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wch-9pmc-8h8m

больше 3 лет назад

In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2wcg-78mh-f9m8

почти 4 года назад

Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.

EPSS: Низкий
github логотип

GHSA-2wcf-8w35-jp7x

больше 3 лет назад

Microsoft SharePoint Spoofing Vulnerability This CVE ID is unique from CVE-2020-17015, CVE-2020-17060.

CVSS3: 8
EPSS: Средний
github логотип

GHSA-2wcf-7wvx-2jw3

почти 4 года назад

Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.

EPSS: Низкий
github логотип

GHSA-2wcf-273g-9c2w

почти 2 года назад

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263110 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2wc9-q6m7-wqrq

больше 3 лет назад

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-2wc9-6hm3-wjmr

больше 3 лет назад

Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-2wc8-fx5r-628m

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2wc8-2pc2-v659

8 месяцев назад

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wc8-2hmm-w3qm

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.

EPSS: Низкий
github логотип

GHSA-2wc7-rq3v-m6mj

около 2 лет назад

The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with admin-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2wc7-p52f-xgxm

почти 4 года назад

Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.

EPSS: Средний
github логотип

GHSA-2wc7-jrqh-277g

больше 1 года назад

Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wc6-h889-742q

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2wc6-2rcj-8v76

больше 4 лет назад

scalarmult() vulnerable to degenerate public keys

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wcm-vx67-3x4q

Duplicate Advisory: GHSA-x698-5hjm-w2m5

7 месяцев назад
github логотип
GHSA-2wcj-qr76-9768

PaddlePaddle segfault in paddle.put_along_axis

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-2wcj-p2hm-6ff7

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

23%
Средний
больше 3 лет назад
github логотип
GHSA-2wch-qhpr-mqp5

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

91%
Критический
больше 3 лет назад
github логотип
GHSA-2wch-pp5g-pc57

The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wch-9pmc-8h8m

In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wcg-78mh-f9m8

Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.

10%
Низкий
почти 4 года назад
github логотип
GHSA-2wcf-8w35-jp7x

Microsoft SharePoint Spoofing Vulnerability This CVE ID is unique from CVE-2020-17015, CVE-2020-17060.

CVSS3: 8
17%
Средний
больше 3 лет назад
github логотип
GHSA-2wcf-7wvx-2jw3

Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wcf-273g-9c2w

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263110 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-2wc9-q6m7-wqrq

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wc9-6hm3-wjmr

Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wc8-fx5r-628m

Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wc8-2pc2-v659

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2wc8-2hmm-w3qm

Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wc7-rq3v-m6mj

The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with admin-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-2wc7-p52f-xgxm

Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.

52%
Средний
почти 4 года назад
github логотип
GHSA-2wc7-jrqh-277g

Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2wc6-h889-742q

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wc6-2rcj-8v76

scalarmult() vulnerable to degenerate public keys

CVSS3: 6.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу