Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2rcq-28xm-f7jp

3 месяца назад

A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.java. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rcp-rgq6-h5hc

почти 4 года назад

Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-2rcp-jvr4-r259

больше 2 лет назад

Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2rcp-jj9q-pcqp

больше 3 лет назад

Unspecified vulnerability in the ATRC codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2rcm-phc9-3945

больше 7 лет назад

Pyopenssl Incorrect Memory Management

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2rcm-mm94-fj4v

почти 4 года назад

Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2rcm-fq84-jjch

11 месяцев назад

Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rcm-9pw5-qh2h

почти 2 года назад

Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the configuration of the web server. The issue results from the lack of appropriate Content Security Policy headers. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM. Was ZDI-CAN-20539.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2rcm-7f2m-m5qc

почти 4 года назад

ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

EPSS: Низкий
github логотип

GHSA-2rcj-xx33-m8j8

почти 4 года назад

The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

EPSS: Средний
github логотип

GHSA-2rcj-xpff-488p

почти 4 года назад

Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered.

EPSS: Низкий
github логотип

GHSA-2rcj-jvwv-8rhr

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rcj-9v96-9vwg

больше 3 лет назад

Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted option that triggers access to an invalid memory location.

EPSS: Низкий
github логотип

GHSA-2rcj-3wpj-27f2

около 2 лет назад

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2rcg-mhmv-j368

больше 3 лет назад

nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS: Низкий
github логотип

GHSA-2rcg-6729-3c5c

почти 4 года назад

Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.

EPSS: Низкий
github логотип

GHSA-2rcf-hgr2-55mc

больше 3 лет назад

The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rcf-f7rp-mvx7

больше 3 лет назад

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

EPSS: Низкий
github логотип

GHSA-2rcf-99h2-99hm

4 дня назад

In the Linux kernel, the following vulnerability has been resolved: slimbus: core: fix device reference leak on report present Slimbus devices can be allocated dynamically upon reception of report-present messages. Make sure to drop the reference taken when looking up already registered devices. Note that this requires taking an extra reference in case the device has not yet been registered and has to be allocated.

EPSS: Низкий
github логотип

GHSA-2rcf-2963-c47m

почти 3 года назад

Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive information from API via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rcq-28xm-f7jp

A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.java. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2rcp-rgq6-h5hc

Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.

4%
Низкий
почти 4 года назад
github логотип
GHSA-2rcp-jvr4-r259

Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rcp-jj9q-pcqp

Unspecified vulnerability in the ATRC codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via unknown vectors.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-2rcm-phc9-3945

Pyopenssl Incorrect Memory Management

CVSS3: 5.9
0%
Низкий
больше 7 лет назад
github логотип
GHSA-2rcm-mm94-fj4v

Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

CVSS3: 9.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2rcm-fq84-jjch

Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-2rcm-9pw5-qh2h

Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the configuration of the web server. The issue results from the lack of appropriate Content Security Policy headers. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM. Was ZDI-CAN-20539.

CVSS3: 7.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-2rcm-7f2m-m5qc

ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2rcj-xx33-m8j8

The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

66%
Средний
почти 4 года назад
github логотип
GHSA-2rcj-xpff-488p

Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2rcj-jvwv-8rhr

Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2rcj-9v96-9vwg

Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted option that triggers access to an invalid memory location.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rcj-3wpj-27f2

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

CVSS3: 9.8
94%
Критический
около 2 лет назад
github логотип
GHSA-2rcg-mhmv-j368

nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rcg-6729-3c5c

Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2rcf-hgr2-55mc

The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rcf-f7rp-mvx7

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rcf-99h2-99hm

In the Linux kernel, the following vulnerability has been resolved: slimbus: core: fix device reference leak on report present Slimbus devices can be allocated dynamically upon reception of report-present messages. Make sure to drop the reference taken when looking up already registered devices. Note that this requires taking an extra reference in case the device has not yet been registered and has to be allocated.

0%
Низкий
4 дня назад
github логотип
GHSA-2rcf-2963-c47m

Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive information from API via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
0%
Низкий
почти 3 года назад

Уязвимостей на страницу