Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2vfm-wf45-cf66

больше 3 лет назад

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

EPSS: Низкий
github логотип

GHSA-2vfm-rw86-mwjv

почти 4 года назад

David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_convert_YCbCr_to_RGB() in "/ok_jpg.c:513" .

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vfm-65cj-5j48

почти 4 года назад

Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2vfj-ww29-h4x2

около 2 лет назад

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. Processing a maliciously crafted image may result in disclosure of process memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vfj-3h9f-v378

больше 3 лет назад

On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.

EPSS: Низкий
github логотип

GHSA-2vfh-w2hp-mr2m

больше 3 лет назад

eDeploy has RCE via cPickle deserialization of untrusted data

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vfh-6ppw-453g

больше 1 года назад

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2vfg-x9vh-wg4m

больше 3 лет назад

Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.

EPSS: Низкий
github логотип

GHSA-2vfg-m6gf-wcr4

больше 3 лет назад

An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.

EPSS: Низкий
github логотип

GHSA-2vfc-ww3w-459q

больше 3 лет назад

The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vf9-33mf-fjw2

6 месяцев назад

A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2vf8-hmhp-gw9x

почти 2 года назад

This issue was addressed through improved state management. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.

EPSS: Низкий
github логотип

GHSA-2vf7-h2xh-7v4v

больше 3 лет назад

The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (NULL pointer dereference and host OS crash) by creating concurrent domains and holding references to them, related to VMID exhaustion.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-2vf7-cqh6-hh52

2 месяца назад

Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2vf7-97fr-5gfj

больше 3 лет назад

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vf6-7r77-ggp5

9 дней назад

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vf5-wxw3-xq3g

больше 3 лет назад

Reflected XSS in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2vf4-v2rm-3993

больше 1 года назад

An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vf4-9qc5-m6pf

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

EPSS: Низкий
github логотип

GHSA-2vf3-pgp6-m4w5

больше 3 лет назад

Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU modules and GX Works3 and/or GX Works2 via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vfm-wf45-cf66

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfm-rw86-mwjv

David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_convert_YCbCr_to_RGB() in "/ok_jpg.c:513" .

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2vfm-65cj-5j48

Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.

CVSS3: 4.6
0%
Низкий
почти 4 года назад
github логотип
GHSA-2vfj-ww29-h4x2

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. Processing a maliciously crafted image may result in disclosure of process memory.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2vfj-3h9f-v378

On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfh-w2hp-mr2m

eDeploy has RCE via cPickle deserialization of untrusted data

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfh-6ppw-453g

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
5%
Низкий
больше 1 года назад
github логотип
GHSA-2vfg-x9vh-wg4m

Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfg-m6gf-wcr4

An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vfc-ww3w-459q

The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vf9-33mf-fjw2

A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2vf8-hmhp-gw9x

This issue was addressed through improved state management. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.

0%
Низкий
почти 2 года назад
github логотип
GHSA-2vf7-h2xh-7v4v

The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (NULL pointer dereference and host OS crash) by creating concurrent domains and holding references to them, related to VMID exhaustion.

CVSS3: 5.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vf7-cqh6-hh52

Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

CVSS3: 4.4
0%
Низкий
2 месяца назад
github логотип
GHSA-2vf7-97fr-5gfj

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vf6-7r77-ggp5

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.

CVSS3: 6.5
0%
Низкий
9 дней назад
github логотип
GHSA-2vf5-wxw3-xq3g

Reflected XSS in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vf4-v2rm-3993

An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2vf4-9qc5-m6pf

Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vf3-pgp6-m4w5

Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series CPU modules all versions contain a vulnerability that allows cleartext transmission of sensitive information between CPU modules and GX Works3 and/or GX Works2 via unspecified vectors.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу