Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-239q-57jm-9rwj

больше 3 лет назад

BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.

EPSS: Низкий
github логотип

GHSA-239p-q346-3xw9

больше 3 лет назад

Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device during an SG_IO ioctl call.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-239p-6rfv-62vf

больше 1 года назад

Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-14975.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-239m-chp6-538f

больше 3 лет назад

An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-239j-w696-2rhc

10 месяцев назад

A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-239j-vv78-jjcx

больше 3 лет назад

An out-of-bounds vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project files.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-239j-jjxf-wwcj

почти 4 года назад

Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.

EPSS: Низкий
github логотип

GHSA-239j-gmhr-4pcm

больше 3 лет назад

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.

EPSS: Низкий
github логотип

GHSA-239j-2cv5-j928

почти 2 года назад

OS command injection vulnerability in WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands by sending a specially crafted request to the product.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-239h-r383-7fqx

больше 3 лет назад

A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.

EPSS: Низкий
github логотип

GHSA-239h-283c-gxph

больше 3 лет назад

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

EPSS: Низкий
github логотип

GHSA-239g-m969-jgx2

около 1 года назад

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-239g-jrj8-mjwj

больше 3 лет назад

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

EPSS: Низкий
github логотип

GHSA-239g-crqj-qcfp

почти 4 года назад

Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block ACK (aka DELBA) packet that triggers a certain state change in the absence of an aggregation session.

EPSS: Низкий
github логотип

GHSA-239f-qw85-5278

9 месяцев назад

A vulnerability classified as critical was found in itsourcecode Restaurant Management System 1.0. This vulnerability affects unknown code of the file /admin/menu_save.php. The manipulation of the argument menu leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-239f-m535-8fmf

больше 3 лет назад

Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-239f-4376-67r8

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Dynamic Keywords Injector plugin <= 2.3.15 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-239c-jmhv-334g

больше 3 лет назад

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language.

EPSS: Низкий
github логотип

GHSA-239c-9qhp-4xc9

7 месяцев назад

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-239c-6cv2-wwx8

больше 2 лет назад

Swift-corelibs-foundation denial of service in JSON decoding with JSONDecoder

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-239q-57jm-9rwj

BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-239p-q346-3xw9

Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device during an SG_IO ioctl call.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-239p-6rfv-62vf

Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-14975.

CVSS3: 3.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-239m-chp6-538f

An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-239j-w696-2rhc

A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-239j-vv78-jjcx

An out-of-bounds vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project files.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-239j-jjxf-wwcj

Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.

5%
Низкий
почти 4 года назад
github логотип
GHSA-239j-gmhr-4pcm

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-239j-2cv5-j928

OS command injection vulnerability in WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands by sending a specially crafted request to the product.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-239h-r383-7fqx

A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-239h-283c-gxph

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-239g-m969-jgx2

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-239g-jrj8-mjwj

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-239g-crqj-qcfp

Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block ACK (aka DELBA) packet that triggers a certain state change in the absence of an aggregation session.

1%
Низкий
почти 4 года назад
github логотип
GHSA-239f-qw85-5278

A vulnerability classified as critical was found in itsourcecode Restaurant Management System 1.0. This vulnerability affects unknown code of the file /admin/menu_save.php. The manipulation of the argument menu leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-239f-m535-8fmf

Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-239f-4376-67r8

Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Dynamic Keywords Injector plugin <= 2.3.15 versions.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-239c-jmhv-334g

An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-239c-9qhp-4xc9

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-239c-6cv2-wwx8

Swift-corelibs-foundation denial of service in JSON decoding with JSONDecoder

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу