Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 306 694

Количество 306 694

github логотип

GHSA-2493-x4rf-23h9

больше 3 лет назад

Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

EPSS: Низкий
github логотип

GHSA-2493-frc2-g6pr

5 месяцев назад

FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no restrictions on file type or destination path. These conditions enable attackers to upload executable payloads and .mof files to locations such as system32 and wbem\mof, where Windows Management Instrumentation (WMI) automatically processes and executes them. This results in remote code execution with SYSTEM-level privileges, without requiring user interaction.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2493-c7mq-cpj4

больше 2 лет назад

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2493-8gg5-974x

почти 4 года назад

Windows IKE Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-21843, CVE-2022-21848, CVE-2022-21883, CVE-2022-21889.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2493-7x32-c5p8

больше 3 лет назад

Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2492-xxqf-6h78

около 2 лет назад

Cross Site Request Forgery in SwiftyEdit

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2492-95q9-ghpv

больше 3 лет назад

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-248x-4c3j-hcg7

больше 3 лет назад

Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-248v-wwj6-r5j3

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role allows Reflected XSS. This issue affects User Role: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-248v-73qf-wh7x

почти 4 года назад

A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.

EPSS: Низкий
github логотип

GHSA-248v-346w-9cwc

больше 1 года назад

Certifi removes GLOBALTRUST root certificate

EPSS: Средний
github логотип

GHSA-248r-f975-ppfj

больше 3 лет назад

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-248r-c6gj-jwpq

около 2 месяцев назад

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-248r-745f-7p46

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the themes_links function in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to class attributes in a list of links.

EPSS: Низкий
github логотип

GHSA-248r-2g9q-v634

больше 3 лет назад

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Server 2008 R2 SP1 does not properly consider thread-owned objects during the processing of window handles, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."

EPSS: Низкий
github логотип

GHSA-248q-qwj4-9945

больше 3 лет назад

D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of "GET" followed by a space and two newlines, possibly triggering the crash due to missing arguments.

EPSS: Низкий
github логотип

GHSA-248q-88c9-6cq3

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Opera before 9.63 allows remote attackers to inject arbitrary web script or HTML via built-in XSLT templates.

EPSS: Низкий
github логотип

GHSA-248p-qmc2-qc97

больше 1 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-248p-gq7w-24rp

больше 3 лет назад

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.

EPSS: Низкий
github логотип

GHSA-248j-xg68-6w85

около 3 лет назад

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2493-x4rf-23h9

Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2493-frc2-g6pr

FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no restrictions on file type or destination path. These conditions enable attackers to upload executable payloads and .mof files to locations such as system32 and wbem\mof, where Windows Management Instrumentation (WMI) automatically processes and executes them. This results in remote code execution with SYSTEM-level privileges, without requiring user interaction.

CVSS3: 9.8
64%
Средний
5 месяцев назад
github логотип
GHSA-2493-c7mq-cpj4

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2493-8gg5-974x

Windows IKE Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-21843, CVE-2022-21848, CVE-2022-21883, CVE-2022-21889.

CVSS3: 7.5
12%
Средний
почти 4 года назад
github логотип
GHSA-2493-7x32-c5p8

Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2492-xxqf-6h78

Cross Site Request Forgery in SwiftyEdit

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-2492-95q9-ghpv

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-248x-4c3j-hcg7

Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-248v-wwj6-r5j3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role allows Reflected XSS. This issue affects User Role: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-248v-73qf-wh7x

A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.

1%
Низкий
почти 4 года назад
github логотип
GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

21%
Средний
больше 1 года назад
github логотип
GHSA-248r-f975-ppfj

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-248r-c6gj-jwpq

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-248r-745f-7p46

Cross-site scripting (XSS) vulnerability in the themes_links function in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to class attributes in a list of links.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-248r-2g9q-v634

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Server 2008 R2 SP1 does not properly consider thread-owned objects during the processing of window handles, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."

2%
Низкий
больше 3 лет назад
github логотип
GHSA-248q-qwj4-9945

D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of "GET" followed by a space and two newlines, possibly triggering the crash due to missing arguments.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-248q-88c9-6cq3

Cross-site scripting (XSS) vulnerability in Opera before 9.63 allows remote attackers to inject arbitrary web script or HTML via built-in XSLT templates.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-248p-qmc2-qc97

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-248p-gq7w-24rp

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-248j-xg68-6w85

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVSS3: 9.8
2%
Низкий
около 3 лет назад

Уязвимостей на страницу