Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2gc7-w4hw-rr2m

почти 6 лет назад

class.upload.php in verot.net omits .pht from the set of dangerous file extensions

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2gc7-9j5g-v42f

почти 3 года назад

GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2gc7-6pfc-v239

больше 2 лет назад

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2gc6-xpq3-f7gm

почти 4 года назад

A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2gc6-9pfx-xpg3

больше 3 лет назад

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0035, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068.

EPSS: Средний
github логотип

GHSA-2gc6-52qh-cwwj

почти 4 года назад

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.

EPSS: Средний
github логотип

GHSA-2gc6-2h2g-ph48

больше 3 лет назад

Rambox RCE Vulnerability

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-2gc5-r3m4-5vgx

около 2 лет назад

An issue in the permission and access control components within ROS2 Foxy Fitzroy ROS_VERSION=2 and ROS_PYTHON_VERSION=3 allows attackers to gain escalate privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gc5-pcr2-vmgm

почти 2 года назад

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab_link’ attribute of the Panel Slider widget in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2gc5-3h3p-8vpf

больше 3 лет назад

Dolibarr reflected cross-site scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2gc3-gxvv-r87c

почти 2 года назад

Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gc3-8h7p-8j99

больше 3 лет назад

An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gc2-cm86-3pjx

больше 3 лет назад

In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gc2-4gm5-9ghf

больше 3 лет назад

The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2g9x-g93g-hv56

около 1 года назад

In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2g9w-mw43-7j8w

почти 2 года назад

A vulnerability classified as critical was found in code-projects Online Book System 1.0. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument username/password/login_username/login_password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258202 is the identifier assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2g9r-w7mh-f2h2

8 месяцев назад

A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-2g9r-9mj3-xx54

почти 4 года назад

Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2g9r-9f99-v27g

больше 3 лет назад

yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g9r-93qh-95qh

больше 3 лет назад

HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gc7-w4hw-rr2m

class.upload.php in verot.net omits .pht from the set of dangerous file extensions

CVSS3: 9.8
15%
Средний
почти 6 лет назад
github логотип
GHSA-2gc7-9j5g-v42f

GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

CVSS3: 9.8
28%
Средний
почти 3 года назад
github логотип
GHSA-2gc7-6pfc-v239

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2gc6-xpq3-f7gm

A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gc6-9pfx-xpg3

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0035, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068.

24%
Средний
больше 3 лет назад
github логотип
GHSA-2gc6-52qh-cwwj

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.

52%
Средний
почти 4 года назад
github логотип
GHSA-2gc6-2h2g-ph48

Rambox RCE Vulnerability

CVSS3: 9
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2gc5-r3m4-5vgx

An issue in the permission and access control components within ROS2 Foxy Fitzroy ROS_VERSION=2 and ROS_PYTHON_VERSION=3 allows attackers to gain escalate privileges.

CVSS3: 9.8
около 2 лет назад
github логотип
GHSA-2gc5-pcr2-vmgm

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab_link’ attribute of the Panel Slider widget in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2gc5-3h3p-8vpf

Dolibarr reflected cross-site scripting (XSS) vulnerability

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gc3-gxvv-r87c

Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2gc3-8h7p-8j99

An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gc2-cm86-3pjx

In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gc2-4gm5-9ghf

The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g9x-g93g-hv56

In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2g9w-mw43-7j8w

A vulnerability classified as critical was found in code-projects Online Book System 1.0. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument username/password/login_username/login_password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258202 is the identifier assigned to this vulnerability.

CVSS3: 7.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g9r-w7mh-f2h2

A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2g9r-9mj3-xx54

Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.

CVSS3: 4.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g9r-9f99-v27g

yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g9r-93qh-95qh

HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу