Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-2m44-793w-9x5c

больше 1 года назад

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m43-qgqq-69c7

около 1 года назад

A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial target and potentially leading to broader security vulnerabilities.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2m42-3qgm-3769

почти 4 года назад

PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2m3x-c3pv-g7qv

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title, which is used as the default title of a webform block.

EPSS: Низкий
github логотип

GHSA-2m3w-xcjp-43pq

больше 3 лет назад

Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40,11.41 , 2018.05(11.50), 2018.08(11.51), 2018.11(11.60), 2019.02(11.70), 2019.05(11.80), 2019.08(11.90), 2019.11(11.91), 2020.05(11.92), 2020.10(11.93). The vulnerability could allow remote attackers to execute arbitrary code on affected installations of SiteScope.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m3w-662q-8c6m

больше 3 лет назад

lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m3v-v2m8-q956

2 месяца назад

Denial of Service Vulnerability in React Server Components

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2m3v-qx42-rv95

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.

EPSS: Низкий
github логотип

GHSA-2m3v-5ccr-mrmf

больше 1 года назад

A vulnerability classified as critical has been found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. This affects an unknown part of the file /cgi-bin/tosei_kikai.php. The manipulation of the argument kikaibangou leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2m3v-4j99-jmf6

2 месяца назад

Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ElasticNet UME R32: ElasticNet_UME_R32_V16.23.20.04.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2m3r-v75v-2v9p

почти 4 года назад

FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.

EPSS: Низкий
github логотип

GHSA-2m3q-qmg5-8x72

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2m3p-pgf6-5rx3

больше 3 лет назад

A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been classified as problematic. This affects an unknown part of the file /goform/RgDhcp. The manipulation of the argument PppUserName with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2m3m-xv57-xrmm

около 1 года назад

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.1.2 before 6.1.2.21, from 5.3.1.40 before 5.3.1.41.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2m3m-x4cj-rqrm

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: USB: gadget: pxa27x_udc: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2m3m-g8h2-cx6m

почти 4 года назад

The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2m3m-f775-94xc

больше 3 лет назад

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.

EPSS: Низкий
github логотип

GHSA-2m3m-4f43-3vh4

больше 1 года назад

In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m3h-q8m9-j9pg

больше 3 лет назад

An issue in the SeChangeNotifyPrivilege component of Abloy Key Manager Version 7.14301.0.0 allows attackers to escalate privileges via a change in permissions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m3h-p692-qjp7

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix connection failure handling In case immediate MPA request processing fails, the newly created endpoint unlinks the listening endpoint and is ready to be dropped. This special case was not handled correctly by the code handling the later TCP socket close, causing a NULL dereference crash in siw_cm_work_handler() when dereferencing a NULL listener. We now also cancel the useless MPA timeout, if immediate MPA request processing fails. This patch furthermore simplifies MPA processing in general: Scheduling a useless TCP socket read in sk_data_ready() upcall is now surpressed, if the socket is already moved out of TCP_ESTABLISHED state.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2m44-793w-9x5c

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

CVSS3: 9.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-2m43-qgqq-69c7

A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial target and potentially leading to broader security vulnerabilities.

CVSS3: 7.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2m42-3qgm-3769

PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-2m3x-c3pv-g7qv

Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title, which is used as the default title of a webform block.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m3w-xcjp-43pq

Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40,11.41 , 2018.05(11.50), 2018.08(11.51), 2018.11(11.60), 2019.02(11.70), 2019.05(11.80), 2019.08(11.90), 2019.11(11.91), 2020.05(11.92), 2020.10(11.93). The vulnerability could allow remote attackers to execute arbitrary code on affected installations of SiteScope.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2m3w-662q-8c6m

lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2m3v-v2m8-q956

Denial of Service Vulnerability in React Server Components

CVSS3: 7.5
19%
Средний
2 месяца назад
github логотип
GHSA-2m3v-qx42-rv95

Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2m3v-5ccr-mrmf

A vulnerability classified as critical has been found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. This affects an unknown part of the file /cgi-bin/tosei_kikai.php. The manipulation of the argument kikaibangou leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2m3v-4j99-jmf6

Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ElasticNet UME R32: ElasticNet_UME_R32_V16.23.20.04.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-2m3r-v75v-2v9p

FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2m3q-qmg5-8x72

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-2m3p-pgf6-5rx3

A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been classified as problematic. This affects an unknown part of the file /goform/RgDhcp. The manipulation of the argument PppUserName with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m3m-xv57-xrmm

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.1.2 before 6.1.2.21, from 5.3.1.40 before 5.3.1.41.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2m3m-x4cj-rqrm

In the Linux kernel, the following vulnerability has been resolved: USB: gadget: pxa27x_udc: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2m3m-g8h2-cx6m

The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2m3m-f775-94xc

IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m3m-4f43-3vh4

In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 9.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-2m3h-q8m9-j9pg

An issue in the SeChangeNotifyPrivilege component of Abloy Key Manager Version 7.14301.0.0 allows attackers to escalate privileges via a change in permissions.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m3h-p692-qjp7

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix connection failure handling In case immediate MPA request processing fails, the newly created endpoint unlinks the listening endpoint and is ready to be dropped. This special case was not handled correctly by the code handling the later TCP socket close, causing a NULL dereference crash in siw_cm_work_handler() when dereferencing a NULL listener. We now also cancel the useless MPA timeout, if immediate MPA request processing fails. This patch furthermore simplifies MPA processing in general: Scheduling a useless TCP socket read in sk_data_ready() upcall is now surpressed, if the socket is already moved out of TCP_ESTABLISHED state.

CVSS3: 5.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу