Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2rrx-q65f-8945

больше 3 лет назад

Credentials transmitted in plain text by OpenShift Deployer Plugin

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2rrx-pphc-qfv9

10 месяцев назад

pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result Rendering

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2rrx-pmxc-v674

больше 3 лет назад

A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2rrx-p33r-295r

11 месяцев назад

This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API endpoints. An authenticated remote attacker with a valid login ID could exploit this vulnerability through vulnerable API endpoint which could lead to account takeover of targeted users.

EPSS: Низкий
github логотип

GHSA-2rrw-64r4-g2c2

около 2 месяцев назад

A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2rrv-8ph2-rj83

больше 3 лет назад

IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS: Низкий
github логотип

GHSA-2rrv-22x6-4f23

около 2 лет назад

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rrr-hqx9-8q6w

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to widget/index/content_id/*.

EPSS: Низкий
github логотип

GHSA-2rrp-mjwj-c49q

почти 4 года назад

Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_file parameter.

EPSS: Низкий
github логотип

GHSA-2rrp-7c8v-xf6v

почти 4 года назад

Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and beta 39a, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via an HTTP request with multiple long headers to webmail.exe and unspecified other CGI executables, which triggers an overflow when assigning values to environment variables. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-2rrm-fcjm-q77w

больше 3 лет назад

Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

EPSS: Низкий
github логотип

GHSA-2rrm-c66p-mgc8

15 дней назад

ALGO 8180 IP Audio Alerter Web UI Direct Request Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface. By navigating directly to a URL, a user can gain unauthorized access to data. An attacker can leverage this vulnerability to disclose information in the context of the device. Was ZDI-CAN-28299.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rrm-8grr-qvmv

больше 3 лет назад

Frame replay vulnerability in Wi-Fi subsystem in Intel Dual-Band and Tri-Band Wireless-AC Products allows remote attacker to replay frames via channel-based man-in-the-middle.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2rrm-7h4w-qg5g

больше 2 лет назад

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2rrj-r6g7-f5gj

почти 4 года назад

VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users."

EPSS: Низкий
github логотип

GHSA-2rrj-g8ch-3g5f

почти 2 года назад

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rrh-f9c7-cc73

почти 4 года назад

SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the bookid parameter.

EPSS: Низкий
github логотип

GHSA-2rrh-8pm2-3q2c

больше 2 лет назад

iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rrf-rvr2-f97v

5 дней назад

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689254 (Note: For N15 and NR16) / MOLY01689259 (Note: For NR17 and NR17R); Issue ID: MSV-4843.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rrf-qm4c-8229

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rrx-q65f-8945

Credentials transmitted in plain text by OpenShift Deployer Plugin

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rrx-pphc-qfv9

pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result Rendering

CVSS3: 9.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-2rrx-pmxc-v674

A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rrx-p33r-295r

This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API endpoints. An authenticated remote attacker with a valid login ID could exploit this vulnerability through vulnerable API endpoint which could lead to account takeover of targeted users.

0%
Низкий
11 месяцев назад
github логотип
GHSA-2rrw-64r4-g2c2

A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges.

CVSS3: 8.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2rrv-8ph2-rj83

IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rrv-22x6-4f23

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2rrr-hqx9-8q6w

Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to widget/index/content_id/*.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2rrp-mjwj-c49q

Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_file parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2rrp-7c8v-xf6v

Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and beta 39a, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via an HTTP request with multiple long headers to webmail.exe and unspecified other CGI executables, which triggers an overflow when assigning values to environment variables. NOTE: some of these details are obtained from third party information.

20%
Средний
почти 4 года назад
github логотип
GHSA-2rrm-fcjm-q77w

Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rrm-c66p-mgc8

ALGO 8180 IP Audio Alerter Web UI Direct Request Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface. By navigating directly to a URL, a user can gain unauthorized access to data. An attacker can leverage this vulnerability to disclose information in the context of the device. Was ZDI-CAN-28299.

CVSS3: 5.3
0%
Низкий
15 дней назад
github логотип
GHSA-2rrm-8grr-qvmv

Frame replay vulnerability in Wi-Fi subsystem in Intel Dual-Band and Tri-Band Wireless-AC Products allows remote attacker to replay frames via channel-based man-in-the-middle.

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rrm-7h4w-qg5g

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

CVSS3: 9.8
93%
Критический
больше 2 лет назад
github логотип
GHSA-2rrj-r6g7-f5gj

VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users."

0%
Низкий
почти 4 года назад
github логотип
GHSA-2rrj-g8ch-3g5f

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2rrh-f9c7-cc73

SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the bookid parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2rrh-8pm2-3q2c

iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rrf-rvr2-f97v

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689254 (Note: For N15 and NR16) / MOLY01689259 (Note: For NR17 and NR17R); Issue ID: MSV-4843.

CVSS3: 7.5
0%
Низкий
5 дней назад
github логотип
GHSA-2rrf-qm4c-8229

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

10%
Средний
больше 3 лет назад

Уязвимостей на страницу