Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2w3m-74v7-48pp

больше 1 года назад

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validation on the PDF embed block in all versions up to, and including, 3.9.12. This makes it possible for authenticated attackers, with contributor-level access and above, to embed PDF blocks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2w3j-8r4x-f4mg

около 3 лет назад

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2w3j-7x55-5cx2

больше 3 лет назад

The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w3h-xfcq-hh2j

больше 3 лет назад

Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not restrict access to the USB interface from an unauthorized user with physical access. Successful exploitation of this vulnerability may allow an attacker with physical access to the system the ability to load an unauthorized payload or unauthorized access to the hard drive by booting a live USB OS. This could impact confidentiality and integrity of the system and risk exposure of sensitive information including PHI.

EPSS: Низкий
github логотип

GHSA-2w3h-g44g-mrhv

больше 3 лет назад

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

EPSS: Низкий
github логотип

GHSA-2w3g-r4c9-2jp8

почти 2 года назад

Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2w3g-954c-vrfq

больше 3 лет назад

Stack-based buffer overflow in the milliwatt_generate function in the Miliwatt application in Asterisk 1.4.x before 1.4.44, 1.6.x before 1.6.2.23, 1.8.x before 1.8.10.1, and 10.x before 10.2.1, when the o option is used and the internal_timing option is off, allows remote attackers to cause a denial of service (application crash) via a large number of samples in an audio packet.

EPSS: Низкий
github логотип

GHSA-2w3g-246v-q74q

больше 3 лет назад

Microsoft Internet Explorer 7 through 11 allows remote attackers to obtain sensitive clipboard information via a crafted web site, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-2w3f-x9p7-9w42

больше 2 лет назад

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the payment status of arbitrary form submissions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2w3f-f73w-vf7r

больше 3 лет назад

An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.

EPSS: Низкий
github логотип

GHSA-2w3f-9w3q-qw77

больше 4 лет назад

Prototype Pollution in config-handler

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w3c-55r2-325r

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Jease 2.11 allows remote authenticated users to inject arbitrary web script or HTML via a content section note.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2w3c-4838-666w

больше 3 лет назад

Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.

EPSS: Низкий
github логотип

GHSA-2w39-q85c-jqcx

больше 3 лет назад

SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2w39-4r85-2c9m

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix obj leak in VM_BIND error path If we fail a handle-lookup part way thru, we need to drop the already obtained obj references. Patchwork: https://patchwork.freedesktop.org/patch/669784/

EPSS: Низкий
github логотип

GHSA-2w38-c69v-2x84

больше 2 лет назад

An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2w37-mhq2-wfgv

больше 3 лет назад

SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2w36-grgh-xprc

11 месяцев назад

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device. This vulnerability is due to insufficient verification of modules in the software load process. An attacker could exploit this vulnerability by manipulating the loaded binaries to bypass some of the integrity checks that are performed during the booting process. A successful exploit could allow the attacker to control the boot configuration, which could enable them to bypass the requirement to run Cisco-signed images or alter the security properties of the running system. Note: This vulnerability affects Cisco IOS XR Software, not the Secure Boot feature. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vu...

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2w35-7f77-cj55

почти 4 года назад

A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2w35-685f-3mpc

10 месяцев назад

This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access contacts.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2w3m-74v7-48pp

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validation on the PDF embed block in all versions up to, and including, 3.9.12. This makes it possible for authenticated attackers, with contributor-level access and above, to embed PDF blocks.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2w3j-8r4x-f4mg

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.

CVSS3: 6.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-2w3j-7x55-5cx2

The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2w3h-xfcq-hh2j

Baxter ExactaMix EM 2400 versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 does not restrict access to the USB interface from an unauthorized user with physical access. Successful exploitation of this vulnerability may allow an attacker with physical access to the system the ability to load an unauthorized payload or unauthorized access to the hard drive by booting a live USB OS. This could impact confidentiality and integrity of the system and risk exposure of sensitive information including PHI.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w3h-g44g-mrhv

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w3g-r4c9-2jp8

Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2w3g-954c-vrfq

Stack-based buffer overflow in the milliwatt_generate function in the Miliwatt application in Asterisk 1.4.x before 1.4.44, 1.6.x before 1.6.2.23, 1.8.x before 1.8.10.1, and 10.x before 10.2.1, when the o option is used and the internal_timing option is off, allows remote attackers to cause a denial of service (application crash) via a large number of samples in an audio packet.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w3g-246v-q74q

Microsoft Internet Explorer 7 through 11 allows remote attackers to obtain sensitive clipboard information via a crafted web site, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."

41%
Средний
больше 3 лет назад
github логотип
GHSA-2w3f-x9p7-9w42

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_payment_status' shortcode in versions up to, and including, 3.3.1. This allows authenticated attackers, with subscriber-level capabilities or above to obtain sensitive information about the payment status of arbitrary form submissions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2w3f-f73w-vf7r

An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w3f-9w3q-qw77

Prototype Pollution in config-handler

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2w3c-55r2-325r

Cross-site scripting (XSS) vulnerability in Jease 2.11 allows remote authenticated users to inject arbitrary web script or HTML via a content section note.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w3c-4838-666w

Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2w39-q85c-jqcx

SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2w39-4r85-2c9m

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix obj leak in VM_BIND error path If we fail a handle-lookup part way thru, we need to drop the already obtained obj references. Patchwork: https://patchwork.freedesktop.org/patch/669784/

0%
Низкий
3 месяца назад
github логотип
GHSA-2w38-c69v-2x84

An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2w37-mhq2-wfgv

SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w36-grgh-xprc

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device. This vulnerability is due to insufficient verification of modules in the software load process. An attacker could exploit this vulnerability by manipulating the loaded binaries to bypass some of the integrity checks that are performed during the booting process. A successful exploit could allow the attacker to control the boot configuration, which could enable them to bypass the requirement to run Cisco-signed images or alter the security properties of the running system. Note: This vulnerability affects Cisco IOS XR Software, not the Secure Boot feature. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vu...

CVSS3: 6.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-2w35-7f77-cj55

A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2w35-685f-3mpc

This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access contacts.

CVSS3: 9.8
0%
Низкий
10 месяцев назад

Уязвимостей на страницу