Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 903

Количество 325 903

github логотип

GHSA-2fh5-8393-p7m3

почти 4 года назад

Buffer overflow in PTW-WMS1 firmware version 2.000.012 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fh5-2q69-8g9v

почти 4 года назад

Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fh4-p8g3-4vjj

почти 4 года назад

Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter.

EPSS: Низкий
github логотип

GHSA-2fh4-gpch-vqv4

около 1 года назад

Duplicate Advisory: Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch

EPSS: Низкий
github логотип

GHSA-2fh4-cpv8-68hg

почти 4 года назад

** DISPUTED ** Race condition in Online Solutions Security Suite 1.5.14905.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.

EPSS: Низкий
github логотип

GHSA-2fh4-99wm-m59g

больше 1 года назад

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-2fh4-45ph-7q27

больше 2 лет назад

The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fh3-xg72-f7vx

почти 4 года назад

FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.

EPSS: Критический
github логотип

GHSA-2fh3-rm73-hjxf

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.6.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fh2-r4pq-hx4f

почти 2 года назад

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2fgx-cg4f-9pgq

почти 4 года назад

The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2fgw-qh65-pxv5

11 месяцев назад

The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fgw-hpx5-xjx3

почти 2 года назад

A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History parameter.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2fgw-ch33-hpgq

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2fgw-2v2m-w7mc

почти 4 года назад

useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.

EPSS: Низкий
github логотип

GHSA-2fgv-c9q9-5wwh

почти 4 года назад

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.

EPSS: Средний
github логотип

GHSA-2fgr-v6mx-rmch

7 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows SQL Injection. This issue affects Perfect Brands for WooCommerce: from n/a through 3.6.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2fgr-mc24-75x3

13 дней назад

iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized value to the -k/--key parameter. Attackers can craft a malicious argument containing a NOP sled, shellcode, and return address to overflow a 1024-byte stack buffer and gain code execution with user privileges.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2fgq-wq42-4xxq

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Search.php in DiMeMa CONTENTdm (CDM) allows remote attackers to inject arbitrary web script or HTML via a search, probably related to the CISOBOX1 parameter to results.php in CDM 4.2.

EPSS: Низкий
github логотип

GHSA-2fgq-8wh7-jwc9

14 дней назад

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Inventory System 1.0 in the view_sales.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fh5-8393-p7m3

Buffer overflow in PTW-WMS1 firmware version 2.000.012 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2fh5-2q69-8g9v

Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2fh4-p8g3-4vjj

Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fh4-gpch-vqv4

Duplicate Advisory: Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch

около 1 года назад
github логотип
GHSA-2fh4-cpv8-68hg

** DISPUTED ** Race condition in Online Solutions Security Suite 1.5.14905.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fh4-99wm-m59g

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fh4-45ph-7q27

The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fh3-xg72-f7vx

FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.

93%
Критический
почти 4 года назад
github логотип
GHSA-2fh3-rm73-hjxf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.6.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fh2-r4pq-hx4f

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.

CVSS3: 8.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2fgx-cg4f-9pgq

The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fgw-qh65-pxv5

The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain elevated privileges.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2fgw-hpx5-xjx3

A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History parameter.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2fgw-ch33-hpgq

Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fgw-2v2m-w7mc

useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fgv-c9q9-5wwh

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.

24%
Средний
почти 4 года назад
github логотип
GHSA-2fgr-v6mx-rmch

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows SQL Injection. This issue affects Perfect Brands for WooCommerce: from n/a through 3.6.0.

CVSS3: 8.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2fgr-mc24-75x3

iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized value to the -k/--key parameter. Attackers can craft a malicious argument containing a NOP sled, shellcode, and return address to overflow a 1024-byte stack buffer and gain code execution with user privileges.

CVSS3: 8.4
0%
Низкий
13 дней назад
github логотип
GHSA-2fgq-wq42-4xxq

Cross-site scripting (XSS) vulnerability in Search.php in DiMeMa CONTENTdm (CDM) allows remote attackers to inject arbitrary web script or HTML via a search, probably related to the CISOBOX1 parameter to results.php in CDM 4.2.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fgq-8wh7-jwc9

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Inventory System 1.0 in the view_sales.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 6.1
0%
Низкий
14 дней назад

Уязвимостей на страницу