Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2rrf-398j-6q9g

больше 3 лет назад

A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4 on HP-UX 11i v3, 10.0 for IIS on Windows, 11.0 for Apache 2.4 on RHEL 7, MFA Proxy 4.0 (Agent module only) for Apache 2.4 on RHEL 7.

EPSS: Низкий
github логотип

GHSA-2rr9-vr7w-3p56

больше 3 лет назад

IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote attackers to bypass intended access restrictions and read the image files of arbitrary users via a crafted URL.

EPSS: Низкий
github логотип

GHSA-2rr9-6rwp-36pg

почти 2 года назад

A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-253382 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rr8-9c6g-8j5c

больше 3 лет назад

Missing Authorization in Crafter CMS

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2rr7-xrrm-67cf

11 месяцев назад

A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process these characters, rendering privateGPT inaccessible. This uncontrolled resource consumption can lead to prolonged unavailability of the service, disrupting operations and causing potential data inaccessibility and loss of productivity.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rr7-pjcq-c7fj

около 1 года назад

Memory corruption while reading CPU state data during guest VM suspend.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rr6-rqrq-g5r8

больше 3 лет назад

Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 before 1.0.1.46, R6400v2 before 1.0.2.66, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R8300 before 1.0.2.128, and R8500 before 1.0.2.128.

EPSS: Низкий
github логотип

GHSA-2rr6-jrx8-xrg7

12 месяцев назад

A CWE-20 "Improper Input Validation" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rr6-hjw5-xch6

больше 3 лет назад

Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rr6-9w84-3v7p

11 дней назад

Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files sds.C. This issue affects swoole-src: before 6.0.2.

EPSS: Низкий
github логотип

GHSA-2rr5-8q37-2w7h

больше 4 лет назад

Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rr5-68hg-rwmh

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: filemap: replace pte_offset_map() with pte_offset_map_nolock() The vmf->ptl in filemap_fault_recheck_pte_none() is still set from handle_pte_fault(). But at the same time, we did a pte_unmap(vmf->pte). After a pte_unmap(vmf->pte) unmap and rcu_read_unlock(), the page table may be racily changed and vmf->ptl maybe fails to protect the actual page table. Fix this by replacing pte_offset_map() with pte_offset_map_nolock(). As David said, the PTL pointer might be stale so if we continue to use it infilemap_fault_recheck_pte_none(), it might trigger UAF. Also, if the PTL fails, the issue fixed by commit 58f327f2ce80 ("filemap: avoid unnecessary major faults in filemap_fault()") might reappear.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2rr3-vw22-qpv2

больше 3 лет назад

In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rr3-rv49-p42f

больше 3 лет назад

phpMyFAQ contains Weak Password Requirements

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rr2-57v3-7cvx

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web Page vulnerability in Veribilim Software Veribase Order allows Stored XSS, Cross-Site Scripting (XSS), Exploit Script-Based APIs, XSS Through HTTP Headers.This issue affects Veribase Order: before v4.010.3.

EPSS: Низкий
github логотип

GHSA-2rqx-pq8v-wx7j

12 месяцев назад

The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2rqx-6v8j-7xmq

около 1 месяца назад

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rqw-x4fp-36cv

почти 4 года назад

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

EPSS: Низкий
github логотип

GHSA-2rqw-vx2c-xfgw

больше 3 лет назад

Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rqw-v265-jf8c

больше 4 лет назад

Open Redirect in ActionPack

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rrf-398j-6q9g

A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4 on HP-UX 11i v3, 10.0 for IIS on Windows, 11.0 for Apache 2.4 on RHEL 7, MFA Proxy 4.0 (Agent module only) for Apache 2.4 on RHEL 7.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rr9-vr7w-3p56

IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 3.3.2.3, and 3.4.1 before 3.4.1.1 allows remote attackers to bypass intended access restrictions and read the image files of arbitrary users via a crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rr9-6rwp-36pg

A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-253382 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2rr8-9c6g-8j5c

Missing Authorization in Crafter CMS

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rr7-xrrm-67cf

A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process these characters, rendering privateGPT inaccessible. This uncontrolled resource consumption can lead to prolonged unavailability of the service, disrupting operations and causing potential data inaccessibility and loss of productivity.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2rr7-pjcq-c7fj

Memory corruption while reading CPU state data during guest VM suspend.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2rr6-rqrq-g5r8

Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 before 1.0.1.46, R6400v2 before 1.0.2.66, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R8300 before 1.0.2.128, and R8500 before 1.0.2.128.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rr6-jrx8-xrg7

A CWE-20 "Improper Input Validation" in ldbMT.so in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to modify system configuration via crafted HTTP requests.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-2rr6-hjw5-xch6

Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rr6-9w84-3v7p

Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files sds.C. This issue affects swoole-src: before 6.0.2.

0%
Низкий
11 дней назад
github логотип
GHSA-2rr5-8q37-2w7h

Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2rr5-68hg-rwmh

In the Linux kernel, the following vulnerability has been resolved: filemap: replace pte_offset_map() with pte_offset_map_nolock() The vmf->ptl in filemap_fault_recheck_pte_none() is still set from handle_pte_fault(). But at the same time, we did a pte_unmap(vmf->pte). After a pte_unmap(vmf->pte) unmap and rcu_read_unlock(), the page table may be racily changed and vmf->ptl maybe fails to protect the actual page table. Fix this by replacing pte_offset_map() with pte_offset_map_nolock(). As David said, the PTL pointer might be stale so if we continue to use it infilemap_fault_recheck_pte_none(), it might trigger UAF. Also, if the PTL fails, the issue fixed by commit 58f327f2ce80 ("filemap: avoid unnecessary major faults in filemap_fault()") might reappear.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rr3-vw22-qpv2

In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rr3-rv49-p42f

phpMyFAQ contains Weak Password Requirements

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rr2-57v3-7cvx

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script in Attributes in a Web Page vulnerability in Veribilim Software Veribase Order allows Stored XSS, Cross-Site Scripting (XSS), Exploit Script-Based APIs, XSS Through HTTP Headers.This issue affects Veribase Order: before v4.010.3.

0%
Низкий
больше 1 года назад
github логотип
GHSA-2rqx-pq8v-wx7j

The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
1%
Низкий
12 месяцев назад
github логотип
GHSA-2rqx-6v8j-7xmq

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2rqw-x4fp-36cv

The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2rqw-vx2c-xfgw

Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rqw-v265-jf8c

Open Redirect in ActionPack

CVSS3: 6.1
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу