Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 109

Количество 326 109

github логотип

GHSA-2g83-93g3-qr66

почти 4 года назад

Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service via a crafted app.

EPSS: Низкий
github логотип

GHSA-2g83-7hf9-c7mr

почти 4 года назад

Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data via a crafted web site.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2g83-63pc-qvx7

почти 4 года назад

An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c draws a Particle object. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in order to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2g7w-59mh-c4mv

почти 4 года назад

Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.

EPSS: Низкий
github логотип

GHSA-2g7v-hgr5-5mvv

почти 4 года назад

Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registered device.

EPSS: Низкий
github логотип

GHSA-2g7v-hghf-grg4

2 месяца назад

mcp-maigret vulnerable to command injection

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2g7v-9r87-x6xh

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wrap dcn301_calculate_wm_and_dlg for FPU. Mirrors the logic for dcn30. Cue lots of WARNs and some kernel panics without this fix.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g7v-93hf-j2h4

почти 4 года назад

Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the form parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2g7v-6q7q-7mp6

3 месяца назад

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2g7r-9xq5-c6hv

больше 2 лет назад

Cross-Site Request Forgery (CSRF) in usememos/memos

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g7q-wj3m-7h2r

почти 4 года назад

packages/core/contact.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?p=core/contact request, aka Open Bug Bounty ID OBB-278503.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2g7p-7mvp-pw7m

около 2 лет назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Inpersttion Slivery Extender allows Code Injection.This issue affects Slivery Extender: from n/a through 1.0.2.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2g7m-ph9x-7q7m

9 месяцев назад

Calibre Web and Autocaliweb have a ReDoS vulnerability

EPSS: Низкий
github логотип

GHSA-2g7j-m3mp-pr8p

почти 4 года назад

An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version 03.02.02(14), version 03.01.07(13), and version 03.00.39(12)

EPSS: Низкий
github логотип

GHSA-2g7j-7338-6vq9

почти 4 года назад

Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a globallineno integer overflow.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g7h-x5vj-qp64

почти 4 года назад

IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g7h-7rqr-9p4r

1 день назад

Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-2g7h-4jrf-ppfh

почти 2 года назад

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2g7f-fm5g-52cj

больше 1 года назад

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g7c-w4c3-p872

почти 4 года назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g83-93g3-qr66

Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service via a crafted app.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2g83-7hf9-c7mr

Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data via a crafted web site.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g83-63pc-qvx7

An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c draws a Particle object. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in order to trigger this vulnerability.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2g7w-59mh-c4mv

Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2g7v-hgr5-5mvv

Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registered device.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2g7v-hghf-grg4

mcp-maigret vulnerable to command injection

CVSS3: 6.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2g7v-9r87-x6xh

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wrap dcn301_calculate_wm_and_dlg for FPU. Mirrors the logic for dcn30. Cue lots of WARNs and some kernel panics without this fix.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g7v-93hf-j2h4

Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the form parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2g7v-6q7q-7mp6

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

CVSS3: 4.7
0%
Низкий
3 месяца назад
github логотип
GHSA-2g7r-9xq5-c6hv

Cross-Site Request Forgery (CSRF) in usememos/memos

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2g7q-wj3m-7h2r

packages/core/contact.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?p=core/contact request, aka Open Bug Bounty ID OBB-278503.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g7p-7mvp-pw7m

Improper Control of Generation of Code ('Code Injection') vulnerability in Inpersttion Slivery Extender allows Code Injection.This issue affects Slivery Extender: from n/a through 1.0.2.

CVSS3: 8.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2g7m-ph9x-7q7m

Calibre Web and Autocaliweb have a ReDoS vulnerability

0%
Низкий
9 месяцев назад
github логотип
GHSA-2g7j-m3mp-pr8p

An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version 03.02.02(14), version 03.01.07(13), and version 03.00.39(12)

2%
Низкий
почти 4 года назад
github логотип
GHSA-2g7j-7338-6vq9

Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a globallineno integer overflow.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g7h-x5vj-qp64

IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g7h-7rqr-9p4r

Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output

CVSS3: 4.1
1 день назад
github логотип
GHSA-2g7h-4jrf-ppfh

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g7f-fm5g-52cj

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVSS3: 8.8
5%
Низкий
больше 1 года назад
github логотип
GHSA-2g7c-w4c3-p872

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу