Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2h8p-w5q4-c3jq

больше 3 лет назад

Cookie.php in Piwik before 1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS: Низкий
github логотип

GHSA-2h8p-f7xr-xcpg

3 месяца назад

Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and configuration loss.

EPSS: Низкий
github логотип

GHSA-2h8m-mjqv-x98p

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check denominator pbn_div before used [WHAT & HOW] A denominator cannot be 0, and is checked before used. This fixes 1 DIVIDE_BY_ZERO issue reported by Coverity.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h8m-2p6j-5q33

больше 3 лет назад

Data Corruption in Intel Unite(R) Client before version 3.3.176.13 may allow an unauthenticated user to potentially cause a denial of service via network access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h8j-xgvj-94wp

больше 3 лет назад

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-2h8j-vgqm-q655

больше 3 лет назад

The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2h8j-8r9p-849f

5 месяцев назад

@digitalocean/do-markdownit has Type Confusion vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2h8j-6588-5qvp

почти 4 года назад

Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or hang) via a long argument to the connect command.

EPSS: Низкий
github логотип

GHSA-2h8j-5vrm-5737

больше 3 лет назад

The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0220, CVE-2017-0258, and CVE-2017-0259.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2h8h-h9vg-9cr4

больше 3 лет назад

The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h8h-53wp-5m9q

около 1 года назад

The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX action in all versions up to, and including, 1.1.2411060. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's log files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h8g-h9q5-4vvx

почти 2 года назад

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-2h8g-7g68-jc42

больше 3 лет назад

NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2h8f-c5j4-6pq8

почти 4 года назад

The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function.

EPSS: Низкий
github логотип

GHSA-2h8f-5758-wfx8

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h88-qxq3-v97j

больше 2 лет назад

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVSS3: 6.1
EPSS: Высокий
github логотип

GHSA-2h87-x45x-cx46

почти 4 года назад

LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.

EPSS: Низкий
github логотип

GHSA-2h87-mx3g-www9

больше 3 лет назад

The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h87-4q2w-v4hf

почти 3 года назад

Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin

CVSS3: 10
EPSS: Высокий
github логотип

GHSA-2h87-2x7p-9fjq

больше 3 лет назад

An issue has been found in libwav through 2017-04-20. It is a SEGV in the function apply_gain in wav_gain/wav_gain.c.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h8p-w5q4-c3jq

Cookie.php in Piwik before 1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h8p-f7xr-xcpg

Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and configuration loss.

1%
Низкий
3 месяца назад
github логотип
GHSA-2h8m-mjqv-x98p

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check denominator pbn_div before used [WHAT & HOW] A denominator cannot be 0, and is checked before used. This fixes 1 DIVIDE_BY_ZERO issue reported by Coverity.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h8m-2p6j-5q33

Data Corruption in Intel Unite(R) Client before version 3.3.176.13 may allow an unauthenticated user to potentially cause a denial of service via network access.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2h8j-xgvj-94wp

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

CVSS3: 6.1
36%
Средний
больше 3 лет назад
github логотип
GHSA-2h8j-vgqm-q655

The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2h8j-8r9p-849f

@digitalocean/do-markdownit has Type Confusion vulnerability

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-2h8j-6588-5qvp

Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or hang) via a long argument to the connect command.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2h8j-5vrm-5737

The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0220, CVE-2017-0258, and CVE-2017-0259.

CVSS3: 4.7
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2h8h-h9vg-9cr4

The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS3: 6.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2h8h-53wp-5m9q

The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX action in all versions up to, and including, 1.1.2411060. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's log files.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2h8g-h9q5-4vvx

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVSS3: 6.1
13%
Средний
почти 2 года назад
github логотип
GHSA-2h8g-7g68-jc42

NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h8f-c5j4-6pq8

The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2h8f-5758-wfx8

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h88-qxq3-v97j

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVSS3: 6.1
76%
Высокий
больше 2 лет назад
github логотип
GHSA-2h87-x45x-cx46

LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2h87-mx3g-www9

The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h87-4q2w-v4hf

Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin

CVSS3: 10
87%
Высокий
почти 3 года назад
github логотип
GHSA-2h87-2x7p-9fjq

An issue has been found in libwav through 2017-04-20. It is a SEGV in the function apply_gain in wav_gain/wav_gain.c.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу