Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-2gfh-cg4p-chjr

почти 4 года назад

Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.

EPSS: Низкий
github логотип

GHSA-2gfg-vm36-6mvj

почти 4 года назад

The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.

EPSS: Низкий
github логотип

GHSA-2gfg-v7vx-m6gx

почти 4 года назад

COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2gfg-p5mp-gf94

почти 4 года назад

CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.

EPSS: Низкий
github логотип

GHSA-2gff-x2x6-mqv3

почти 4 года назад

For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-5852 ID is for the NVTray Plugin unquoted service path.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gff-65gq-h5qw

почти 4 года назад

If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer making "view-source:" linkable. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gfc-j4qr-8wcc

почти 4 года назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gfc-3f49-cfq7

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sohelwpexpert WP Responsive Video allows DOM-Based XSS.This issue affects WP Responsive Video: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gf9-crwq-fg52

почти 4 года назад

The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.

EPSS: Низкий
github логотип

GHSA-2gf8-x72h-g57r

почти 4 года назад

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2gf8-64pg-49p7

почти 2 года назад

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gf7-wf94-4pqj

почти 4 года назад

Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2gf7-pwpq-8w42

почти 4 года назад

Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.

EPSS: Средний
github логотип

GHSA-2gf7-5h4r-x3p6

около 2 лет назад

Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gf7-3qxp-c9rr

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/cadence-ttc: Fix memory leak in ttc_timer_probe Smatch reports: drivers/clocksource/timer-cadence-ttc.c:529 ttc_timer_probe() warn: 'timer_baseaddr' from of_iomap() not released on lines: 498,508,516. timer_baseaddr may have the problem of not being released after use, I replaced it with the devm_of_iomap() function and added the clk_put() function to cleanup the "clk_ce" and "clk_cs".

EPSS: Низкий
github логотип

GHSA-2gf6-qx54-c8vp

больше 1 года назад

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2gf6-g5m3-qg3c

почти 4 года назад

Technicolor DPC2320 dpc2300r2-v202r1244101-150420a-v6 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gf5-qcr8-g3jg

больше 2 лет назад

A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-2gf5-7xvc-c7p8

почти 4 года назад

Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.

EPSS: Средний
github логотип

GHSA-2gf4-m97g-cvpw

почти 2 года назад

Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gfh-cg4p-chjr

Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gfg-vm36-6mvj

The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2gfg-v7vx-m6gx

COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gfg-p5mp-gf94

CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gff-x2x6-mqv3

For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-5852 ID is for the NVTray Plugin unquoted service path.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gff-65gq-h5qw

If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer making "view-source:" linkable. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2gfc-j4qr-8wcc

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2gfc-3f49-cfq7

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sohelwpexpert WP Responsive Video allows DOM-Based XSS.This issue affects WP Responsive Video: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gf9-crwq-fg52

The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gf8-x72h-g57r

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier.

CVSS3: 9.8
81%
Высокий
почти 4 года назад
github логотип
GHSA-2gf8-64pg-49p7

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2gf7-wf94-4pqj

Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gf7-pwpq-8w42

Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.

63%
Средний
почти 4 года назад
github логотип
GHSA-2gf7-5h4r-x3p6

Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2gf7-3qxp-c9rr

In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/cadence-ttc: Fix memory leak in ttc_timer_probe Smatch reports: drivers/clocksource/timer-cadence-ttc.c:529 ttc_timer_probe() warn: 'timer_baseaddr' from of_iomap() not released on lines: 498,508,516. timer_baseaddr may have the problem of not being released after use, I replaced it with the devm_of_iomap() function and added the clk_put() function to cleanup the "clk_ce" and "clk_cs".

0%
Низкий
6 месяцев назад
github логотип
GHSA-2gf6-qx54-c8vp

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gf6-g5m3-qg3c

Technicolor DPC2320 dpc2300r2-v202r1244101-150420a-v6 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2gf5-qcr8-g3jg

A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens.

CVSS3: 4.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2gf5-7xvc-c7p8

Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.

50%
Средний
почти 4 года назад
github логотип
GHSA-2gf4-m97g-cvpw

Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
1%
Низкий
почти 2 года назад

Уязвимостей на страницу