Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 903

Количество 325 903

github логотип

GHSA-2fp2-wfm4-76mp

почти 4 года назад

The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990.

EPSS: Низкий
github логотип

GHSA-2fp2-v24h-74gp

почти 4 года назад

In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD.

EPSS: Низкий
github логотип

GHSA-2fp2-f5qv-826q

почти 4 года назад

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fmx-fw55-g6jg

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2fmx-8p94-cm2g

больше 2 лет назад

Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fmw-vp29-wcgf

почти 4 года назад

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2fmw-p7gw-97jj

около 2 месяцев назад

A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2fmv-j5xj-4fmq

почти 4 года назад

Moodle Reveals Student Information Meant To Be Anonymous

EPSS: Низкий
github логотип

GHSA-2fmv-g8v2-32hj

почти 4 года назад

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.

EPSS: Низкий
github логотип

GHSA-2fmv-49qj-83rm

больше 2 лет назад

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fmr-xm36-8jjg

почти 4 года назад

The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

EPSS: Низкий
github логотип

GHSA-2fmr-2c6h-79j9

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through 2.2.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fmq-75qj-9j34

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.

EPSS: Низкий
github логотип

GHSA-2fmp-mw85-gxqw

больше 2 лет назад

An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an authenticated local attacker to modify the URL of the registration page in the web GUI of an affected device.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fmp-7xwf-wvwr

почти 6 лет назад

Arbitrary File Read in Snyk Broker

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fmj-pq77-gvj7

почти 3 года назад

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin through 2.4 use a third-party library that removes the escaping on some HTML characters, leading to a Cross-Site Scripting vulnerability.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-2fmj-fcp4-f992

почти 4 года назад

Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fmh-chfc-392c

11 месяцев назад

mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fmg-qfp6-p727

почти 4 года назад

An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.

EPSS: Низкий
github логотип

GHSA-2fmc-hw9p-wg9h

почти 4 года назад

service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with GBK encoding, aka Qualcomm internal bug CR 978452.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fp2-wfm4-76mp

The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fp2-v24h-74gp

In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fp2-f5qv-826q

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fmx-fw55-g6jg

Cross-Site Request Forgery (CSRF) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.6.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fmx-8p94-cm2g

Adobe After Effects version 24.0.2 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fmw-vp29-wcgf

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

CVSS3: 9.8
70%
Высокий
почти 4 года назад
github логотип
GHSA-2fmw-p7gw-97jj

A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.

CVSS3: 4.9
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2fmv-j5xj-4fmq

Moodle Reveals Student Information Meant To Be Anonymous

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fmv-g8v2-32hj

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fmv-49qj-83rm

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fmr-xm36-8jjg

The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fmr-2c6h-79j9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through 2.2.2.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2fmq-75qj-9j34

Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fmp-mw85-gxqw

An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an authenticated local attacker to modify the URL of the registration page in the web GUI of an affected device.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fmp-7xwf-wvwr

Arbitrary File Read in Snyk Broker

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
github логотип
GHSA-2fmj-pq77-gvj7

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin through 2.4 use a third-party library that removes the escaping on some HTML characters, leading to a Cross-Site Scripting vulnerability.

CVSS3: 6.1
24%
Средний
почти 3 года назад
github логотип
GHSA-2fmj-fcp4-f992

Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2fmh-chfc-392c

mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.

CVSS3: 9.8
2%
Низкий
11 месяцев назад
github логотип
GHSA-2fmg-qfp6-p727

An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fmc-hw9p-wg9h

service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework crash) or possibly have unspecified other impact via an access point that has a malformed SSID with GBK encoding, aka Qualcomm internal bug CR 978452.

CVSS3: 9.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу