Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 306 694

Количество 306 694

github логотип

GHSA-252x-53mm-q5hm

больше 3 лет назад

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13055.

EPSS: Низкий
github логотип

GHSA-252w-xrw9-hfrv

больше 3 лет назад

The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.

EPSS: Низкий
github логотип

GHSA-252v-c8x9-rffm

около 1 года назад

The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-252v-9w3r-w4vm

больше 1 года назад

The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-252r-f55f-ff34

больше 3 лет назад

MantisBT allows arbitrary password reset

CVSS3: 8.8
EPSS: Критический
github логотип

GHSA-252r-cvww-g3vf

больше 1 года назад

A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258150 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-252r-7vwr-8rfh

почти 3 года назад

A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-252q-qph8-r7q3

около 1 года назад

Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network access and the user level ”Service”, an attacker can execute arbitrary system commands in the root user’s contexts.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-252p-r436-cv4f

больше 3 лет назад

There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.

EPSS: Низкий
github логотип

GHSA-252p-hhm3-3h4m

больше 3 лет назад

The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.

EPSS: Средний
github логотип

GHSA-252p-f457-cpj4

больше 3 лет назад

Unspecified vulnerability in the NetEase Pmail (com.netease.rpmms) application 0.5.0 and 0.5.2 for Android has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-252p-3jv2-8v3c

около 3 лет назад

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write. Exploitation of this issue does not require user interaction, but does require administrator privileges.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-252h-69rw-g2rp

больше 3 лет назад

The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.

EPSS: Низкий
github логотип

GHSA-252h-2cmq-pmr6

около 3 лет назад

easywebpack-cli Path Traversal vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-252g-gw8q-x2cc

больше 3 лет назад

OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

EPSS: Низкий
github логотип

GHSA-252g-9rpq-c6xw

почти 4 года назад

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

EPSS: Низкий
github логотип

GHSA-252f-47x2-rgxx

больше 3 лет назад

A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-252c-46fv-6xqv

больше 3 лет назад

ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.

EPSS: Низкий
github логотип

GHSA-2529-rwp4-75f6

больше 3 лет назад

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2529-cmp4-x7vg

больше 3 лет назад

HP-UX aserver program allows local users to gain privileges via a symlink attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-252x-53mm-q5hm

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13055.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-252w-xrw9-hfrv

The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-252v-c8x9-rffm

The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-252v-9w3r-w4vm

The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 8.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-252r-f55f-ff34

MantisBT allows arbitrary password reset

CVSS3: 8.8
93%
Критический
больше 3 лет назад
github логотип
GHSA-252r-cvww-g3vf

A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258150 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-252r-7vwr-8rfh

A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-252q-qph8-r7q3

Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network access and the user level ”Service”, an attacker can execute arbitrary system commands in the root user’s contexts.

CVSS3: 8.8
2%
Низкий
около 1 года назад
github логотип
GHSA-252p-r436-cv4f

There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-252p-hhm3-3h4m

The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.

22%
Средний
больше 3 лет назад
github логотип
GHSA-252p-f457-cpj4

Unspecified vulnerability in the NetEase Pmail (com.netease.rpmms) application 0.5.0 and 0.5.2 for Android has unknown impact and attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-252p-3jv2-8v3c

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system write. Exploitation of this issue does not require user interaction, but does require administrator privileges.

CVSS3: 7.2
4%
Низкий
около 3 лет назад
github логотип
GHSA-252h-69rw-g2rp

The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-252h-2cmq-pmr6

easywebpack-cli Path Traversal vulnerability

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-252g-gw8q-x2cc

OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-252g-9rpq-c6xw

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

0%
Низкий
почти 4 года назад
github логотип
GHSA-252f-47x2-rgxx

A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-252c-46fv-6xqv

ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2529-rwp4-75f6

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2529-cmp4-x7vg

HP-UX aserver program allows local users to gain privileges via a symlink attack.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу