Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2jp3-fvm5-pq7w

больше 3 лет назад

niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2jp3-2vfh-535w

около 1 года назад

Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS allows Privilege Escalation.This issue affects WPLMS: from n/a through 1.9.9.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jp2-fm6f-4vgc

почти 4 года назад

SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

EPSS: Низкий
github логотип

GHSA-2jp2-c8rx-5w8j

почти 4 года назад

Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.

EPSS: Низкий
github логотип

GHSA-2jp2-4gcw-39mv

около 1 года назад

Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2jmw-7gh4-3h48

больше 3 лет назад

In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-2jmv-xwch-pcqf

4 месяца назад

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2jmv-v5xf-w928

около 2 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Beautique beautique allows PHP Local File Inclusion.This issue affects Beautique: from n/a through <= 1.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2jmv-v2x6-mmv8

больше 3 лет назад

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.

EPSS: Низкий
github логотип

GHSA-2jmv-57qj-jwg6

больше 3 лет назад

Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season bans and SR losses for other users) by leaving a competitive match at a specific time during the initial loading of that match.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jmv-336w-9f9w

больше 3 лет назад

The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jmr-h5mm-35ff

почти 4 года назад

Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.

EPSS: Низкий
github логотип

GHSA-2jmq-v535-vr5r

больше 1 года назад

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. This affects an unknown part of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2jmq-pwpx-v2pq

2 месяца назад

Akamai Guardicore Platform Agent before 52.1.1 allows an unprivileged user to fully elevate privileges to SYSTEM. This affects versions before 50.15.0, 51.12.0, and 52.1.1.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jmq-6fx4-r49q

6 месяцев назад

EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its HTTP interface. When processing a GET request to list.html, the server fails to properly validate the length of the path parameter. Supplying an excessively long value causes a buffer overflow on the stack, potentially corrupting control flow structures. The vulnerability is exposed through the embedded web server and does not require authentication due to default anonymous access. The issue was resolved in version 1.7.0.12, after which the product was renamed to UplusFtp.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2jmj-6ff4-3p3w

больше 3 лет назад

The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target device is configured giving permission for the gateway device to act on its behalf. This means an authenticated device of a certain tenant, notably also a non-gateway device acting like a gateway, may receive command & control messages targeted at a different device of the same tenant without corresponding permissions getting checked.

EPSS: Низкий
github логотип

GHSA-2jmg-wxp9-5qfc

больше 2 лет назад

All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2jmf-ff5x-92qw

больше 3 лет назад

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

EPSS: Низкий
github логотип

GHSA-2jmf-7qjf-v556

больше 3 лет назад

Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jmc-8g4c-98px

12 месяцев назад

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jp3-fvm5-pq7w

niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks.

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2jp3-2vfh-535w

Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS allows Privilege Escalation.This issue affects WPLMS: from n/a through 1.9.9.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2jp2-fm6f-4vgc

SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2jp2-c8rx-5w8j

Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.

6%
Низкий
почти 4 года назад
github логотип
GHSA-2jp2-4gcw-39mv

Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.

CVSS3: 7.2
2%
Низкий
около 1 года назад
github логотип
GHSA-2jmw-7gh4-3h48

In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.

CVSS3: 8.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jmv-xwch-pcqf

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

CVSS3: 8.2
1%
Низкий
4 месяца назад
github логотип
GHSA-2jmv-v5xf-w928

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Beautique beautique allows PHP Local File Inclusion.This issue affects Beautique: from n/a through <= 1.5.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2jmv-v2x6-mmv8

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-2jmv-57qj-jwg6

Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season bans and SR losses for other users) by leaving a competitive match at a specific time during the initial loading of that match.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jmv-336w-9f9w

The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jmr-h5mm-35ff

Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2jmq-v535-vr5r

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. This affects an unknown part of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jmq-pwpx-v2pq

Akamai Guardicore Platform Agent before 52.1.1 allows an unprivileged user to fully elevate privileges to SYSTEM. This affects versions before 50.15.0, 51.12.0, and 52.1.1.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-2jmq-6fx4-r49q

EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its HTTP interface. When processing a GET request to list.html, the server fails to properly validate the length of the path parameter. Supplying an excessively long value causes a buffer overflow on the stack, potentially corrupting control flow structures. The vulnerability is exposed through the embedded web server and does not require authentication due to default anonymous access. The issue was resolved in version 1.7.0.12, after which the product was renamed to UplusFtp.

CVSS3: 9.8
63%
Средний
6 месяцев назад
github логотип
GHSA-2jmj-6ff4-3p3w

The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target device is configured giving permission for the gateway device to act on its behalf. This means an authenticated device of a certain tenant, notably also a non-gateway device acting like a gateway, may receive command & control messages targeted at a different device of the same tenant without corresponding permissions getting checked.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jmg-wxp9-5qfc

All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jmf-ff5x-92qw

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2jmf-7qjf-v556

Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2jmc-8g4c-98px

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
12 месяцев назад

Уязвимостей на страницу