Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-2pp9-chc4-wvrv

больше 3 лет назад

extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverShield.config.sqlite with a version containing an additional user account, and then use SSH and port forwarding to reach a 127.0.0.1 service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pp9-7rv9-4rpg

почти 4 года назад

The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.

EPSS: Низкий
github логотип

GHSA-2pp9-43xx-6258

больше 1 года назад

Secure Boot Security Feature Bypass Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2pp8-vrh8-g482

больше 3 лет назад

Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code via long device information that is mishandled during a strcat to a device list.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2pp8-pw5r-cpxh

больше 3 лет назад

The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attackers to obtain sensitive information by reading this character.

EPSS: Низкий
github логотип

GHSA-2pp8-cqff-m6w4

около 2 лет назад

Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2pp8-6rm9-qr6v

больше 3 лет назад

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. A plug-in may be able to inherit the application's permissions and access user data.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2pp7-rwqg-2gcx

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() returns NULL, we need check the return value.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pp6-55c2-pfx4

больше 3 лет назад

libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pp6-48h2-93h6

больше 3 лет назад

Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to cross-site scripting (XSS).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pp5-qr47-7qv2

больше 3 лет назад

A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6, iOS 13, tvOS 13. An application may be able to execute arbitrary code with system privileges.

EPSS: Низкий
github логотип

GHSA-2pp5-7m97-7f6x

больше 3 лет назад

OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2pp4-x986-8w45

больше 3 лет назад

The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.

EPSS: Низкий
github логотип

GHSA-2pp4-6872-69xx

больше 3 лет назад

A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pp3-pxpf-p8gg

5 дней назад

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2pp3-576m-vhmq

больше 3 лет назад

An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This enables an attacker to get full access to all emails sent or received by the system including password reset emails, making it possible to reset any user's password.

EPSS: Низкий
github логотип

GHSA-2pp3-2hr3-936m

около 1 года назад

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2pp2-5h73-4wxg

почти 4 года назад

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2pmx-6mm6-6v72

больше 3 лет назад

Smarty arbitrary PHP code execution

EPSS: Низкий
github логотип

GHSA-2pmw-cvc7-frvh

почти 4 года назад

SQL injection in MCMS

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pp9-chc4-wvrv

extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverShield.config.sqlite with a version containing an additional user account, and then use SSH and port forwarding to reach a 127.0.0.1 service.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp9-7rv9-4rpg

The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2pp9-43xx-6258

Secure Boot Security Feature Bypass Vulnerability

CVSS3: 8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2pp8-vrh8-g482

Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code via long device information that is mishandled during a strcat to a device list.

CVSS3: 9.8
15%
Средний
больше 3 лет назад
github логотип
GHSA-2pp8-pw5r-cpxh

The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attackers to obtain sensitive information by reading this character.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp8-cqff-m6w4

Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2pp8-6rm9-qr6v

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. A plug-in may be able to inherit the application's permissions and access user data.

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp7-rwqg-2gcx

In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() returns NULL, we need check the return value.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2pp6-55c2-pfx4

libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp6-48h2-93h6

Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to cross-site scripting (XSS).

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp5-qr47-7qv2

A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6, iOS 13, tvOS 13. An application may be able to execute arbitrary code with system privileges.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp5-7m97-7f6x

OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp4-x986-8w45

The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp4-6872-69xx

A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.

CVSS3: 8.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp3-pxpf-p8gg

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
0%
Низкий
5 дней назад
github логотип
GHSA-2pp3-576m-vhmq

An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This enables an attacker to get full access to all emails sent or received by the system including password reset emails, making it possible to reset any user's password.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp3-2hr3-936m

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.

CVSS3: 9.8
53%
Средний
около 1 года назад
github логотип
GHSA-2pp2-5h73-4wxg

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVSS3: 6.1
5%
Низкий
почти 4 года назад
github логотип
GHSA-2pmx-6mm6-6v72

Smarty arbitrary PHP code execution

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pmw-cvc7-frvh

SQL injection in MCMS

CVSS3: 9.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу