Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-2fp9-9cqm-x4p7

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in 10 Quality Post Gallery plugin <= 2.3.12 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2fp8-wvjf-2gv9

больше 3 лет назад

A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-2fp8-2m27-8mrc

больше 3 лет назад

An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device and disturb operations with connected devices.

EPSS: Низкий
github логотип

GHSA-2fp5-7g39-82f7

больше 3 лет назад

A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by crafting an HTTP request that could cause the web application to redirect the request to a specific malicious URL. This vulnerability is known as an open redirect attack and is used in phishing attacks to get users to visit malicious sites without their knowledge. Cisco Bug IDs: CSCve37646.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2fp4-xh7g-85v8

больше 3 лет назад

Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System.

EPSS: Низкий
github логотип

GHSA-2fp3-rg2c-rm44

больше 3 лет назад

Creolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a buffer, we can break out of the bounds checking of that buffer. When list.join is called on the data it will read past a buffer resulting in a Heap-Buffer-Overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fp3-p8fg-p963

больше 3 лет назад

Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow.

EPSS: Средний
github логотип

GHSA-2fp3-g54x-pvwq

больше 3 лет назад

FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends crafted responses. Long responses can also crash the FTP client with memory corruption.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2fp2-wfm4-76mp

больше 3 лет назад

The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990.

EPSS: Низкий
github логотип

GHSA-2fp2-v24h-74gp

больше 3 лет назад

In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD.

EPSS: Низкий
github логотип

GHSA-2fp2-f5qv-826q

больше 3 лет назад

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fmx-fw55-g6jg

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2fmx-8p94-cm2g

около 2 лет назад

Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fmw-vp29-wcgf

больше 3 лет назад

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2fmv-j5xj-4fmq

больше 3 лет назад

Moodle Reveals Student Information Meant To Be Anonymous

EPSS: Низкий
github логотип

GHSA-2fmv-g8v2-32hj

больше 3 лет назад

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.

EPSS: Низкий
github логотип

GHSA-2fmv-49qj-83rm

больше 2 лет назад

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fmr-xm36-8jjg

почти 4 года назад

The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

EPSS: Низкий
github логотип

GHSA-2fmr-2c6h-79j9

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through 2.2.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fmq-75qj-9j34

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fp9-9cqm-x4p7

Cross-Site Request Forgery (CSRF) vulnerability in 10 Quality Post Gallery plugin <= 2.3.12 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fp8-wvjf-2gv9

A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.

CVSS3: 8.1
18%
Средний
больше 3 лет назад
github логотип
GHSA-2fp8-2m27-8mrc

An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device and disturb operations with connected devices.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fp5-7g39-82f7

A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by crafting an HTTP request that could cause the web application to redirect the request to a specific malicious URL. This vulnerability is known as an open redirect attack and is used in phishing attacks to get users to visit malicious sites without their knowledge. Cisco Bug IDs: CSCve37646.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fp4-xh7g-85v8

Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fp3-rg2c-rm44

Creolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a buffer, we can break out of the bounds checking of that buffer. When list.join is called on the data it will read past a buffer resulting in a Heap-Buffer-Overflow.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fp3-p8fg-p963

Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow.

11%
Средний
больше 3 лет назад
github логотип
GHSA-2fp3-g54x-pvwq

FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends crafted responses. Long responses can also crash the FTP client with memory corruption.

CVSS3: 9.8
74%
Высокий
больше 3 лет назад
github логотип
GHSA-2fp2-wfm4-76mp

The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fp2-v24h-74gp

In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fp2-f5qv-826q

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fmx-fw55-g6jg

Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2fmx-8p94-cm2g

Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2fmw-vp29-wcgf

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

CVSS3: 9.8
70%
Высокий
больше 3 лет назад
github логотип
GHSA-2fmv-j5xj-4fmq

Moodle Reveals Student Information Meant To Be Anonymous

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fmv-g8v2-32hj

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fmv-49qj-83rm

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fmr-xm36-8jjg

The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fmr-2c6h-79j9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through 2.2.2.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2fmq-75qj-9j34

Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу