Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-24q3-549v-f57v

почти 4 года назад

SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.

EPSS: Низкий
github логотип

GHSA-24q3-2w85-x8p7

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field allows Stored XSS. This issue affects Language Field: from n/a through 0.9.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24q2-qw2x-xxpj

больше 3 лет назад

The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.

EPSS: Низкий
github логотип

GHSA-24q2-f22j-vg5m

больше 3 лет назад

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a race condition vulnerability. Successful exploitation could lead to security feature bypass.

EPSS: Низкий
github логотип

GHSA-24q2-6x37-cgcx

больше 3 лет назад

Dolibarr SQL injection vulnerability in product/card.php

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24q2-59hm-rh9r

больше 2 лет назад

Strapi Improper Rate Limiting vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-24q2-4vqq-qcx6

почти 3 года назад

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24px-m2q8-87hf

около 1 года назад

Missing Authorization vulnerability in WpMaspik Maspik – Spam blacklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Maspik – Spam blacklist: from n/a through 2.2.7.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24px-fh32-jvj7

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24pw-pfmp-w2w4

около 3 лет назад

In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an attacker to cause SMRAM corruption and escalation of privileges The UsbCoreDxe module creates a working buffer for USB transactions outside of SMRAM. The code which uses can be inside of SMM, making the working buffer untrusted input. The buffer can be corrupted by DMA transfers. The SMM code code attempts to sanitize pointers to ensure all pointers refer to the working buffer, but when a pointer is not found in the list of pointers to sanitize, the current action is not aborted, leading to undefined behavior. This issue was discovered by Insyde engineering based on the general description provided by Intel's iSTARE group. Fixed in: Kernel 5.0: Version 05.09. 21 Kernel 5.1: Version 05.17.21 Kernel 5.2: Version 05.27.21 Kernel 5.3: Version 05.36.21 Kernel 5.4: Version 05.44.21 Kernel 5.5: Version 05.52.21 https...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24pw-p8jc-r7j5

почти 4 года назад

SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.

EPSS: Низкий
github логотип

GHSA-24pw-h6w3-6pgm

6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rewish WP Emmet allows Stored XSS. This issue affects WP Emmet: from n/a through 0.3.4.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-24pv-x5f7-pv4r

больше 2 лет назад

WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24pv-3jc8-2432

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24pr-9rc2-6xv5

почти 4 года назад

The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-12 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24pq-phfq-785f

больше 3 лет назад

Linear eMerge E3-Series devices allow Command Injections.

CVSS3: 10
EPSS: Критический
github логотип

GHSA-24pq-f9c8-764p

больше 3 лет назад

ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.

EPSS: Низкий
github логотип

GHSA-24pq-9mvp-239w

больше 3 лет назад

Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of service via local access.

EPSS: Низкий
github логотип

GHSA-24pp-jv4q-cp8j

около 2 месяцев назад

Privilege escalation in the DOM: Notifications component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24pm-f3f4-m533

больше 3 лет назад

Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24q3-549v-f57v

SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.

5%
Низкий
почти 4 года назад
github логотип
GHSA-24q3-2w85-x8p7

Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field allows Stored XSS. This issue affects Language Field: from n/a through 0.9.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-24q2-qw2x-xxpj

The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-24q2-f22j-vg5m

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a race condition vulnerability. Successful exploitation could lead to security feature bypass.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24q2-6x37-cgcx

Dolibarr SQL injection vulnerability in product/card.php

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24q2-59hm-rh9r

Strapi Improper Rate Limiting vulnerability

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24q2-4vqq-qcx6

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-24px-m2q8-87hf

Missing Authorization vulnerability in WpMaspik Maspik – Spam blacklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Maspik – Spam blacklist: from n/a through 2.2.7.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-24px-fh32-jvj7

Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24pw-pfmp-w2w4

In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an attacker to cause SMRAM corruption and escalation of privileges The UsbCoreDxe module creates a working buffer for USB transactions outside of SMRAM. The code which uses can be inside of SMM, making the working buffer untrusted input. The buffer can be corrupted by DMA transfers. The SMM code code attempts to sanitize pointers to ensure all pointers refer to the working buffer, but when a pointer is not found in the list of pointers to sanitize, the current action is not aborted, leading to undefined behavior. This issue was discovered by Insyde engineering based on the general description provided by Intel's iSTARE group. Fixed in: Kernel 5.0: Version 05.09. 21 Kernel 5.1: Version 05.17.21 Kernel 5.2: Version 05.27.21 Kernel 5.3: Version 05.36.21 Kernel 5.4: Version 05.44.21 Kernel 5.5: Version 05.52.21 https...

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-24pw-p8jc-r7j5

SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-24pw-h6w3-6pgm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rewish WP Emmet allows Stored XSS. This issue affects WP Emmet: from n/a through 0.3.4.

CVSS3: 5.9
0%
Низкий
6 месяцев назад
github логотип
GHSA-24pv-x5f7-pv4r

WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24pv-3jc8-2432

Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-24pr-9rc2-6xv5

The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-12 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-24pq-phfq-785f

Linear eMerge E3-Series devices allow Command Injections.

CVSS3: 10
94%
Критический
больше 3 лет назад
github логотип
GHSA-24pq-f9c8-764p

ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24pq-9mvp-239w

Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of service via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24pp-jv4q-cp8j

Privilege escalation in the DOM: Notifications component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, and Firefox ESR < 140.6.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-24pm-f3f4-m533

Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу