Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2r8q-2j9h-3chh

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: dpaa: Pad packets to ETH_ZLEN When sending packets under 60 bytes, up to three bytes of the buffer following the data may be leaked. Avoid this by extending all packets to ETH_ZLEN, ensuring nothing is leaked in the padding. This bug can be reproduced by running $ ping -s 11 destination

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2r8p-fg3c-wcj4

больше 4 лет назад

Heap OOB and CHECK fail in `ResourceGather`

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2r8p-4r3c-hw34

около 1 месяца назад

The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalign' parameters of the 'app-store-download' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2r8j-rf53-9g72

больше 1 года назад

Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2r8h-ccmx-mmjc

почти 4 года назад

Unspecified vulnerability in the Application Express Application Builder component in Oracle Database 3.2.1.00.10 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2r8h-2rq3-qxmx

4 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forgery.This issue affects Search & Filter: from n/a through <= 1.2.17.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2r8f-cf6w-x5vq

5 дней назад

FUXA contains a hard-coded credential vulnerability

EPSS: Низкий
github логотип

GHSA-2r8f-2665-3gxq

больше 5 лет назад

Malicious Package in froever

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2r89-wvrg-9qjh

больше 3 лет назад

Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2r89-3cpr-6vj2

больше 3 лет назад

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2r88-ww5g-vx3h

больше 3 лет назад

EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2r87-96mr-fgv7

почти 4 года назад

Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."

EPSS: Высокий
github логотип

GHSA-2r87-74cx-2p7c

около 1 года назад

XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-2r87-2697-cjpc

больше 2 лет назад

Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2r86-vxrq-rr24

около 3 лет назад

The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2r86-v6pg-m26j

больше 3 лет назад

A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Reservation List settings.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2r86-h346-r99c

больше 3 лет назад

The Huawei viewpoint VP9610 and VP9620 units for the Huawei Video Conference system do not update the Session ID upon successful establishment of a login session, which allows remote authenticated users to hijack sessions via an unspecified interception method.

EPSS: Низкий
github логотип

GHSA-2r85-x553-vqw2

больше 3 лет назад

A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficiently verify the data reliability, attackers could replace an authenticated optical module on the equipment with an unauthenticated one, bypassing system authentication and detection, thus affecting signal transmission. This affects: <ZXCTN 6120H><V5.10.00B24>

EPSS: Низкий
github логотип

GHSA-2r85-wfhw-9qqf

больше 3 лет назад

The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2r84-x97c-3ch4

около 4 лет назад

An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2r8q-2j9h-3chh

In the Linux kernel, the following vulnerability has been resolved: net: dpaa: Pad packets to ETH_ZLEN When sending packets under 60 bytes, up to three bytes of the buffer following the data may be leaked. Avoid this by extending all packets to ETH_ZLEN, ensuring nothing is leaked in the padding. This bug can be reproduced by running $ ping -s 11 destination

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2r8p-fg3c-wcj4

Heap OOB and CHECK fail in `ResourceGather`

CVSS3: 7.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2r8p-4r3c-hw34

The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalign' parameters of the 'app-store-download' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2r8j-rf53-9g72

Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2r8h-ccmx-mmjc

Unspecified vulnerability in the Application Express Application Builder component in Oracle Database 3.2.1.00.10 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2r8h-2rq3-qxmx

Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forgery.This issue affects Search & Filter: from n/a through <= 1.2.17.

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-2r8f-cf6w-x5vq

FUXA contains a hard-coded credential vulnerability

0%
Низкий
5 дней назад
github логотип
GHSA-2r8f-2665-3gxq

Malicious Package in froever

CVSS3: 9.8
больше 5 лет назад
github логотип
GHSA-2r89-wvrg-9qjh

Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r89-3cpr-6vj2

Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.

CVSS3: 9.8
38%
Средний
больше 3 лет назад
github логотип
GHSA-2r88-ww5g-vx3h

EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r87-96mr-fgv7

Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."

82%
Высокий
почти 4 года назад
github логотип
GHSA-2r87-74cx-2p7c

XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList

CVSS3: 9.9
27%
Средний
около 1 года назад
github логотип
GHSA-2r87-2697-cjpc

Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2r86-vxrq-rr24

The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2r86-v6pg-m26j

A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Reservation List settings.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2r86-h346-r99c

The Huawei viewpoint VP9610 and VP9620 units for the Huawei Video Conference system do not update the Session ID upon successful establishment of a login session, which allows remote authenticated users to hijack sessions via an unspecified interception method.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r85-x553-vqw2

A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficiently verify the data reliability, attackers could replace an authenticated optical module on the equipment with an unauthenticated one, bypassing system authentication and detection, thus affecting signal transmission. This affects: <ZXCTN 6120H><V5.10.00B24>

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r85-wfhw-9qqf

The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r84-x97c-3ch4

An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.

CVSS3: 5.4
1%
Низкий
около 4 лет назад

Уязвимостей на страницу