Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2rvj-jqm9-chgx

около 4 лет назад

FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rvj-j9cf-63c3

больше 3 лет назад

The MPL-Publisher WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/libs/PublisherController.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.30.2. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2rvj-6xx4-893j

почти 3 года назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rvj-5mf3-jpwf

7 месяцев назад

The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are later exported. This makes it possible for authenticated attackers, with Contributor-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-2rvh-q539-q33v

больше 3 лет назад

Cross-Site Request Forgery in Apache Struts

EPSS: Низкий
github логотип

GHSA-2rvg-p9mc-wr6c

11 дней назад

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-2rvg-m24j-3h35

около 2 месяцев назад

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rvf-q645-cfj6

больше 1 года назад

A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown function of the file TS/export/contentpage of the component Export Page. The manipulation of the argument ID leads to direct request. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-270000. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rvf-329f-p99g

больше 3 лет назад

System Property Disclosure in Apache Tomcat

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rvc-wpwm-6p6x

больше 3 лет назад

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2rvc-939c-p372

больше 3 лет назад

The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read Java class files via a direct request, aka Bug ID CSCum46497.

EPSS: Низкий
github логотип

GHSA-2rvc-4fj7-2p7v

почти 4 года назад

Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter. NOTE: this issue reportedly exists because of a regression that followed a fix at an unspecified earlier date.

EPSS: Низкий
github логотип

GHSA-2rv9-m7pg-rvf8

5 дней назад

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rv9-h6gv-q3f9

больше 3 лет назад

Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL API call, which allows attackers to execute arbitrary code via a crafted application.

EPSS: Низкий
github логотип

GHSA-2rv9-5cw2-mmfg

почти 4 года назад

Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .rws file with a long RWS010 entry.

EPSS: Средний
github логотип

GHSA-2rv8-xmpq-rpfx

почти 4 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

EPSS: Высокий
github логотип

GHSA-2rv8-rcwh-2x8r

почти 3 года назад

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rv8-p95w-9w54

больше 1 года назад

Memory corruption while processing IOCTL call to set metainfo.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2rv8-6398-pqxg

больше 1 года назад

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2rv6-mjm4-w26j

больше 2 лет назад

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to disclose kernel memory.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rvj-jqm9-chgx

FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2rvj-j9cf-63c3

The MPL-Publisher WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/libs/PublisherController.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.30.2. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rvj-6xx4-893j

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2rvj-5mf3-jpwf

The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are later exported. This makes it possible for authenticated attackers, with Contributor-level access and above, to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVSS3: 4.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-2rvh-q539-q33v

Cross-Site Request Forgery in Apache Struts

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2rvg-p9mc-wr6c

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

CVSS3: 4
0%
Низкий
11 дней назад
github логотип
GHSA-2rvg-m24j-3h35

OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVSS3: 8.8
2%
Низкий
около 2 месяцев назад
github логотип
GHSA-2rvf-q645-cfj6

A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown function of the file TS/export/contentpage of the component Export Page. The manipulation of the argument ID leads to direct request. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-270000. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rvf-329f-p99g

System Property Disclosure in Apache Tomcat

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rvc-wpwm-6p6x

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.

CVSS3: 9.8
16%
Средний
больше 3 лет назад
github логотип
GHSA-2rvc-939c-p372

The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read Java class files via a direct request, aka Bug ID CSCum46497.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rvc-4fj7-2p7v

Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter. NOTE: this issue reportedly exists because of a regression that followed a fix at an unspecified earlier date.

8%
Низкий
почти 4 года назад
github логотип
GHSA-2rv9-m7pg-rvf8

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVSS3: 9.8
0%
Низкий
5 дней назад
github логотип
GHSA-2rv9-h6gv-q3f9

Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL API call, which allows attackers to execute arbitrary code via a crafted application.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rv9-5cw2-mmfg

Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .rws file with a long RWS010 entry.

17%
Средний
почти 4 года назад
github логотип
GHSA-2rv8-xmpq-rpfx

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

78%
Высокий
почти 4 года назад
github логотип
GHSA-2rv8-rcwh-2x8r

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2rv8-p95w-9w54

Memory corruption while processing IOCTL call to set metainfo.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rv8-6398-pqxg

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rv6-mjm4-w26j

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to disclose kernel memory.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу