Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-25xr-qj8w-c4vf

7 месяцев назад

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25xq-f8xm-q632

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in wpsolutions SoundCloud Ultimate allows Cross Site Request Forgery. This issue affects SoundCloud Ultimate: from n/a through 1.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25xp-q574-q8mf

почти 4 года назад

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-25xp-grv3-xwjh

больше 3 лет назад

Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a crafted PDF file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25xm-wxrx-cgw8

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the galleryID parameter in a usergallery upload action; or the (2) upID, (3) tag, (4) month, (5) userID, or (6) year parameter in a calendar announce action.

EPSS: Низкий
github логотип

GHSA-25xm-hr59-7c27

больше 4 лет назад

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25xj-934p-cf7v

больше 3 лет назад

IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.

EPSS: Низкий
github логотип

GHSA-25xj-89g5-fm6h

больше 4 лет назад

Information Disclosure in HashiCorp Vault

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25xh-49vg-48xq

больше 3 лет назад

IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 187873.

EPSS: Низкий
github логотип

GHSA-25xg-m67p-ppc3

2 месяца назад

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions including creating, editing, and deleting resources and categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25xf-r6x8-6fw5

больше 2 лет назад

An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25xc-r4x7-g46h

около 3 лет назад

Fusiondirectory 1.3 suffers from Improper Session Handling.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25xc-jwfq-39jw

почти 5 лет назад

OSGi applications using Vaadin 12-14 and 19 vulnerable to server classes and resources exposure

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-25xc-32vr-fm66

больше 1 года назад

Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25x9-fv8f-q329

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in details.php in CjTagBoard 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) agent, or (6) msg parameter.

EPSS: Низкий
github логотип

GHSA-25x9-7wcv-mf35

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() > ret = brcmf_proto_tx_queue_data(drvr, ifp->ifidx, skb); may be schedule, and then complete before the line > ndev->stats.tx_bytes += skb->len; [ 46.912801] ================================================================== [ 46.920552] BUG: KASAN: use-after-free in brcmf_netdev_start_xmit+0x718/0x8c8 [brcmfmac] [ 46.928673] Read of size 4 at addr ffffff803f5882e8 by task systemd-resolve/328 [ 46.935991] [ 46.937514] CPU: 1 PID: 328 Comm: systemd-resolve Tainted: G O 5.4.199-[REDACTED] #1 [ 46.947255] Hardware name: [REDACTED] [ 46.954568] Call trace: [ 46.957037] dump_backtrace+0x0/0x2b8 [ 46.960719] show_stack+0x24/0x30 [ 46.964052] dump_stack+0x128/0x194 [ 46.967557] print_address_description.isra.0+0x64/0x380 [ 46.972877] __kasan_report+0x1d4/0x240 [ 46.976723] kasan_report+0xc/0x18 [ 46.980...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25x7-rqcx-mfwh

больше 3 лет назад

A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the encoded_options parameter.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25x7-jcpc-96r4

больше 1 года назад

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-25x7-989g-366h

больше 2 лет назад

A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-25x7-2m3g-jhfw

3 месяца назад

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.

CVSS3: 6.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25xr-qj8w-c4vf

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-25xq-f8xm-q632

Cross-Site Request Forgery (CSRF) vulnerability in wpsolutions SoundCloud Ultimate allows Cross Site Request Forgery. This issue affects SoundCloud Ultimate: from n/a through 1.5.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-25xp-q574-q8mf

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-25xp-grv3-xwjh

Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a crafted PDF file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25xm-wxrx-cgw8

Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the galleryID parameter in a usergallery upload action; or the (2) upID, (3) tag, (4) month, (5) userID, or (6) year parameter in a calendar announce action.

3%
Низкий
почти 4 года назад
github логотип
GHSA-25xm-hr59-7c27

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-25xj-934p-cf7v

IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-25xj-89g5-fm6h

Information Disclosure in HashiCorp Vault

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-25xh-49vg-48xq

IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 187873.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25xg-m67p-ppc3

The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing nonce validation on multiple administrative functions. This makes it possible for unauthenticated attackers to perform various unauthorized actions including creating, editing, and deleting resources and categories via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-25xf-r6x8-6fw5

An invalid ‘prepare write request’ command can cause the Bluetooth LE stack to run out of memory and fail to be able to handle subsequent connection requests, resulting in a denial-of-service.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-25xc-r4x7-g46h

Fusiondirectory 1.3 suffers from Improper Session Handling.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-25xc-jwfq-39jw

OSGi applications using Vaadin 12-14 and 19 vulnerable to server classes and resources exposure

CVSS3: 8.6
2%
Низкий
почти 5 лет назад
github логотип
GHSA-25xc-32vr-fm66

Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-25x9-fv8f-q329

Multiple cross-site scripting (XSS) vulnerabilities in details.php in CjTagBoard 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) agent, or (6) msg parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-25x9-7wcv-mf35

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() > ret = brcmf_proto_tx_queue_data(drvr, ifp->ifidx, skb); may be schedule, and then complete before the line > ndev->stats.tx_bytes += skb->len; [ 46.912801] ================================================================== [ 46.920552] BUG: KASAN: use-after-free in brcmf_netdev_start_xmit+0x718/0x8c8 [brcmfmac] [ 46.928673] Read of size 4 at addr ffffff803f5882e8 by task systemd-resolve/328 [ 46.935991] [ 46.937514] CPU: 1 PID: 328 Comm: systemd-resolve Tainted: G O 5.4.199-[REDACTED] #1 [ 46.947255] Hardware name: [REDACTED] [ 46.954568] Call trace: [ 46.957037] dump_backtrace+0x0/0x2b8 [ 46.960719] show_stack+0x24/0x30 [ 46.964052] dump_stack+0x128/0x194 [ 46.967557] print_address_description.isra.0+0x64/0x380 [ 46.972877] __kasan_report+0x1d4/0x240 [ 46.976723] kasan_report+0xc/0x18 [ 46.980...

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-25x7-rqcx-mfwh

A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the encoded_options parameter.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25x7-jcpc-96r4

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. By default, this can only be exploited by administrators, but the ability to use and configure Slider Revolution can be extended to authors.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-25x7-989g-366h

A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

CVSS3: 9.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-25x7-2m3g-jhfw

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.

CVSS3: 6.6
0%
Низкий
3 месяца назад

Уязвимостей на страницу