Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2g4w-jfv5-fgmr

около 2 месяцев назад

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g4w-fv9w-h3mm

больше 3 лет назад

SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g4w-cqhh-m9w9

почти 2 года назад

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2g4w-262r-45rr

больше 3 лет назад

In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2g4v-qc3v-672p

почти 4 года назад

Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

EPSS: Низкий
github логотип

GHSA-2g4v-8vvw-r8m9

больше 1 года назад

An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g4r-w789-9wg5

больше 3 лет назад

In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g4r-fqm7-xqfm

около 2 лет назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g4r-3v66-3h7f

около 1 года назад

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2g4q-9vm9-9fw4

почти 2 года назад

Jenkins Script Security Plugin sandbox bypass vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g4q-4f6w-5q4g

почти 4 года назад

Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbitrary SQL commands via the ID parameter in a Detail action to (2) kategorie.php, (3) medium.php, (4) person.php, or (5) schlagwort.php in modules/, related to classes/class.perform.php.

EPSS: Низкий
github логотип

GHSA-2g4p-864h-334x

больше 3 лет назад

Click Studios Passwordstate before 8.3 Build 8397 allows XSS by authenticated users via an uploaded HTML document.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2g4m-frjw-86jj

почти 4 года назад

The rfc2231 function in message.c in libclamav in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via a crafted message that produces a string that is not null terminated, which triggers a buffer over-read.

EPSS: Низкий
github логотип

GHSA-2g4j-2xqp-4hq5

больше 3 лет назад

In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted XBM file, which claims large rows and columns fields in the header but does not contain sufficient backing data, is provided, the loop over the rows would consume huge CPU resources, since there is no EOF check inside the loop.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2g4h-jr8q-95q6

около 1 года назад

The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, and including, 2.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2g4f-rm2w-x596

почти 2 года назад

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2g4f-r7cc-55q9

больше 3 лет назад

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.

EPSS: Низкий
github логотип

GHSA-2g4c-jphf-67p6

около 2 лет назад

The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2g4c-jh83-m9h4

больше 3 лет назад

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow remote attackers to establish sessions via a crafted message that leverages (1) a signature-validation bypass for SAML messages containing unsigned elements, (2) incorrect validation of XML messages, or (3) a certificate-chain validation bypass for an XML signature element that contains the signing certificate.

EPSS: Низкий
github логотип

GHSA-2g4c-8fpm-c46v

почти 2 года назад

web3-utils Prototype Pollution vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g4w-jfv5-fgmr

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2g4w-fv9w-h3mm

SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4w-cqhh-m9w9

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS3: 4.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g4w-262r-45rr

In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4v-qc3v-672p

Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2g4v-8vvw-r8m9

An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g4r-w789-9wg5

In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4r-fqm7-xqfm

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2g4r-3v66-3h7f

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVSS3: 8.6
0%
Низкий
около 1 года назад
github логотип
GHSA-2g4q-9vm9-9fw4

Jenkins Script Security Plugin sandbox bypass vulnerability

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g4q-4f6w-5q4g

Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbitrary SQL commands via the ID parameter in a Detail action to (2) kategorie.php, (3) medium.php, (4) person.php, or (5) schlagwort.php in modules/, related to classes/class.perform.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2g4p-864h-334x

Click Studios Passwordstate before 8.3 Build 8397 allows XSS by authenticated users via an uploaded HTML document.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4m-frjw-86jj

The rfc2231 function in message.c in libclamav in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via a crafted message that produces a string that is not null terminated, which triggers a buffer over-read.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2g4j-2xqp-4hq5

In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted XBM file, which claims large rows and columns fields in the header but does not contain sufficient backing data, is provided, the loop over the rows would consume huge CPU resources, since there is no EOF check inside the loop.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4h-jr8q-95q6

The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, and including, 2.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
около 1 года назад
github логотип
GHSA-2g4f-rm2w-x596

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g4f-r7cc-55q9

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4c-jphf-67p6

The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2g4c-jh83-m9h4

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow remote attackers to establish sessions via a crafted message that leverages (1) a signature-validation bypass for SAML messages containing unsigned elements, (2) incorrect validation of XML messages, or (3) a certificate-chain validation bypass for an XML signature element that contains the signing certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4c-8fpm-c46v

web3-utils Prototype Pollution vulnerability

CVSS3: 7.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу