Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2jc7-rj7p-gqwv

почти 2 года назад

A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/vacancy/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257370 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2jc7-c7q8-q3g4

почти 4 года назад

PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.

EPSS: Низкий
github логотип

GHSA-2jc7-5p87-mq2h

больше 3 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a video driver, a race condition exists which can potentially lead to a buffer overflow.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2jc6-p9hh-c8rp

больше 3 лет назад

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. PROCA allows a use-after-free and arbitrary code execution. The Samsung ID is SVE-2019-16132 (February 2020).

EPSS: Низкий
github логотип

GHSA-2jc6-3fhj-8q84

больше 2 лет назад

OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2jc5-w7hj-r4r8

больше 3 лет назад

Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' parameter which allows an authenticated attacker to inject a malicious SQL query.

EPSS: Низкий
github логотип

GHSA-2jc5-gq79-mgfc

больше 3 лет назад

An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android IDs: A-32438594, A-32635664.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jc5-4g6p-2928

больше 3 лет назад

TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jc4-r94c-rp7h

больше 2 лет назад

Apache Ivy External Entity Reference vulnerability

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2jc3-r6g9-7j93

больше 1 года назад

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, Modem 5300. There is an out-of-bounds write due to a heap overflow in the GPRS protocol.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-2jc3-9523-wwmj

почти 4 года назад

The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.

EPSS: Средний
github логотип

GHSA-2jc3-8rq8-7x2x

больше 3 лет назад

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jc2-px89-8qfh

почти 3 года назад

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2j9x-6xvx-g2r4

больше 3 лет назад

Vulnerability in the Oracle Global Order Promising component of Oracle E-Business Suite (subcomponent: Reschedule Sales Orders). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Order Promising. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Global Order Promising accessible data as well as unauthorized access to critical data or complete access to all Oracle Global Order Promising accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2j9w-mc69-3577

почти 4 года назад

MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.

EPSS: Низкий
github логотип

GHSA-2j9v-8g47-mxh2

больше 3 лет назад

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2j9v-7pmx-33wm

больше 3 лет назад

A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written outside of the currently computed boundaries. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j9v-5rc4-qhx2

больше 3 лет назад

Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.

EPSS: Низкий
github логотип

GHSA-2j9r-hm6r-5phq

почти 4 года назад

Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2j9r-f764-3c88

больше 3 лет назад

The "Fountain Trust Mobile Banking" by FOUNTAIN TRUST COMPANY app before 3.2.0 -- aka fountain-trust-mobile-banking/id891343006 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jc7-rj7p-gqwv

A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/vacancy/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257370 is the identifier assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2jc7-c7q8-q3g4

PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.

4%
Низкий
почти 4 года назад
github логотип
GHSA-2jc7-5p87-mq2h

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a video driver, a race condition exists which can potentially lead to a buffer overflow.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jc6-p9hh-c8rp

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. PROCA allows a use-after-free and arbitrary code execution. The Samsung ID is SVE-2019-16132 (February 2020).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jc6-3fhj-8q84

OroCommerce Cross-site Scripting vulnerability in add note dialog of Shopping List line item

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jc5-w7hj-r4r8

Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' parameter which allows an authenticated attacker to inject a malicious SQL query.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2jc5-gq79-mgfc

An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android IDs: A-32438594, A-32635664.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jc5-4g6p-2928

TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.

CVSS3: 8.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2jc4-r94c-rp7h

Apache Ivy External Entity Reference vulnerability

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jc3-r6g9-7j93

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, Modem 5300. There is an out-of-bounds write due to a heap overflow in the GPRS protocol.

CVSS3: 5.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jc3-9523-wwmj

The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.

10%
Средний
почти 4 года назад
github логотип
GHSA-2jc3-8rq8-7x2x

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jc2-px89-8qfh

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-2j9x-6xvx-g2r4

Vulnerability in the Oracle Global Order Promising component of Oracle E-Business Suite (subcomponent: Reschedule Sales Orders). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Order Promising. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Global Order Promising accessible data as well as unauthorized access to critical data or complete access to all Oracle Global Order Promising accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 9.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2j9w-mc69-3577

MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2j9v-8g47-mxh2

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j9v-7pmx-33wm

A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written outside of the currently computed boundaries. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2j9v-5rc4-qhx2

Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j9r-hm6r-5phq

Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2j9r-f764-3c88

The "Fountain Trust Mobile Banking" by FOUNTAIN TRUST COMPANY app before 3.2.0 -- aka fountain-trust-mobile-banking/id891343006 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу