Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 903

Количество 325 903

github логотип

GHSA-2fhv-6v4j-h4qx

2 месяца назад

A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the argument text leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2fhr-f6q6-c4p2

почти 4 года назад

Magento 2 Community Edition Access Control Bypass

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fhr-9w58-p9x4

почти 4 года назад

Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2fhr-94vx-gjwj

почти 2 года назад

A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-262307.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fhr-8r8r-qp56

почти 2 года назад

ZendFramework Information Disclosure and Insufficient Entropy vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2fhq-mmhr-8hcv

около 1 месяца назад

A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2fhq-375j-g3px

почти 4 года назад

Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php.

EPSS: Низкий
github логотип

GHSA-2fhp-w5w8-fmw9

больше 1 года назад

The Simple Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2fhp-73jw-g5hv

почти 4 года назад

GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attacker to remotely execute arbitrary code or cause a denial-of-service condition.

EPSS: Низкий
github логотип

GHSA-2fhp-49gm-838v

почти 2 года назад

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the MENU parameter under the Menu module.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2fhm-pcv6-vcx9

9 месяцев назад

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fhj-34vp-w6xg

почти 4 года назад

Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows have unspecified remote attack vectors and impact. NOTE: this issue contains no actionable information, but it was released by a reliable researcher.

EPSS: Низкий
github логотип

GHSA-2fhg-rq88-fxhg

почти 3 года назад

Azure Arc Jumpstart Information Disclosure Vulnerability

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2fhg-mfw9-px88

20 дней назад

Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2fhc-wxpq-2mf3

больше 1 года назад

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2fhc-6x45-rh5v

больше 2 лет назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fh8-pjc2-m3v7

почти 4 года назад

The default Access Control Lists (ACLs) of the administration database for ZMerge 4.x and 5.x provides arbitrary users (including anonymous users) with Manager level access, which allows the users to read or modify import/export scripts.

EPSS: Низкий
github логотип

GHSA-2fh8-hvqx-49wh

почти 4 года назад

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66.

EPSS: Низкий
github логотип

GHSA-2fh7-g5h4-3598

5 месяцев назад

In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01672601; Issue ID: MSV-4623.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fh5-h7qq-56m4

больше 2 лет назад

In IntentResolver, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fhv-6v4j-h4qx

A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the argument text leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 6.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2fhr-f6q6-c4p2

Magento 2 Community Edition Access Control Bypass

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fhr-9w58-p9x4

Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fhr-94vx-gjwj

A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-262307.

CVSS3: 9.8
3%
Низкий
почти 2 года назад
github логотип
GHSA-2fhr-8r8r-qp56

ZendFramework Information Disclosure and Insufficient Entropy vulnerability

CVSS3: 5.3
почти 2 года назад
github логотип
GHSA-2fhq-mmhr-8hcv

A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

CVSS3: 7.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2fhq-375j-g3px

Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fhp-w5w8-fmw9

The Simple Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fhp-73jw-g5hv

GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attacker to remotely execute arbitrary code or cause a denial-of-service condition.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fhp-49gm-838v

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the MENU parameter under the Menu module.

CVSS3: 4.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-2fhm-pcv6-vcx9

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2fhj-34vp-w6xg

Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows have unspecified remote attack vectors and impact. NOTE: this issue contains no actionable information, but it was released by a reliable researcher.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fhg-rq88-fxhg

Azure Arc Jumpstart Information Disclosure Vulnerability

CVSS3: 3.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-2fhg-mfw9-px88

Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.

CVSS3: 6.2
0%
Низкий
20 дней назад
github логотип
GHSA-2fhc-wxpq-2mf3

A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fhc-6x45-rh5v

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fh8-pjc2-m3v7

The default Access Control Lists (ACLs) of the administration database for ZMerge 4.x and 5.x provides arbitrary users (including anonymous users) with Manager level access, which allows the users to read or modify import/export scripts.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fh8-hvqx-49wh

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fh7-g5h4-3598

In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01672601; Issue ID: MSV-4623.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2fh5-h7qq-56m4

In IntentResolver, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу