Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-26xv-73mx-mq4r

6 месяцев назад

YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

EPSS: Низкий
github логотип

GHSA-26xv-5c8j-w237

больше 3 лет назад

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26xv-4xf9-c953

больше 3 лет назад

In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26xq-m8xw-6373

11 месяцев назад

Froxlor has an HTML Injection Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26xq-4h5f-fhh8

больше 3 лет назад

Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26xp-wjvm-542h

больше 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26xp-w34p-3h6q

больше 3 лет назад

In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_error= on the login screen of the Web application.

EPSS: Низкий
github логотип

GHSA-26xp-84m3-w6wh

почти 4 года назад

The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.

EPSS: Низкий
github логотип

GHSA-26xm-phwj-2pmp

больше 3 лет назад

Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0610.

EPSS: Низкий
github логотип

GHSA-26xj-xw26-4hf7

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.

EPSS: Низкий
github логотип

GHSA-26xj-r8r2-vvgx

8 месяцев назад

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26xj-hxvp-rc79

больше 2 лет назад

Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26xh-wmc4-35qp

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer 15.16.8.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TVS files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13697.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26xh-4mrc-q8jf

больше 3 лет назад

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
EPSS: Критический
github логотип

GHSA-26xg-p8p3-27cv

больше 3 лет назад

JR East Japan train operation information push notification App for Android version 1.2.4 and earlier allows remote attackers to bypass access restriction to obtain or alter the user's registered information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-26xf-664m-jmwq

2 месяца назад

The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-26xc-8c8f-fp83

почти 4 года назад

Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.

EPSS: Низкий
github логотип

GHSA-26x9-xv78-34rx

около 2 лет назад

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grnprint.php, in the grnno parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-26x9-cxwc-jfqw

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entries In the case of the directory size is greater than or equal to the cluster size, if start_clu becomes an EOF cluster(an invalid cluster) due to file system corruption, then the directory entry where ei->hint_femp.eidx hint is outside the directory, resulting in an out-of-bounds access, which may cause further file system corruption. This commit adds a check for start_clu, if it is an invalid cluster, the file or directory will be treated as empty.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-26x8-wc99-6x99

больше 3 лет назад

read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26xv-73mx-mq4r

YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

0%
Низкий
6 месяцев назад
github логотип
GHSA-26xv-5c8j-w237

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26xv-4xf9-c953

In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.

CVSS3: 9.8
8%
Низкий
больше 3 лет назад
github логотип
GHSA-26xq-m8xw-6373

Froxlor has an HTML Injection Vulnerability

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-26xq-4h5f-fhh8

Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26xp-wjvm-542h

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

CVSS3: 5.3
2%
Низкий
больше 3 лет назад
github логотип
GHSA-26xp-w34p-3h6q

In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_error= on the login screen of the Web application.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-26xp-84m3-w6wh

The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26xm-phwj-2pmp

Stack-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0610.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-26xj-xw26-4hf7

Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26xj-r8r2-vvgx

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-26xj-hxvp-rc79

Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26xh-wmc4-35qp

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TeamViewer 15.16.8.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TVS files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13697.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-26xh-4mrc-q8jf

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
94%
Критический
больше 3 лет назад
github логотип
GHSA-26xg-p8p3-27cv

JR East Japan train operation information push notification App for Android version 1.2.4 and earlier allows remote attackers to bypass access restriction to obtain or alter the user's registered information via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26xf-664m-jmwq

The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
2 месяца назад
github логотип
GHSA-26xc-8c8f-fp83

Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-26x9-xv78-34rx

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grnprint.php, in the grnno parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-26x9-cxwc-jfqw

In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entries In the case of the directory size is greater than or equal to the cluster size, if start_clu becomes an EOF cluster(an invalid cluster) due to file system corruption, then the directory entry where ei->hint_femp.eidx hint is outside the directory, resulting in an out-of-bounds access, which may cause further file system corruption. This commit adds a check for start_clu, if it is an invalid cluster, the file or directory will be treated as empty.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-26x8-wc99-6x99

read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу