Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 632

Количество 325 632

github логотип

GHSA-2f58-x9v2-9x28

5 месяцев назад

A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2f58-vf6g-6p8x

почти 4 года назад

MediaWiki Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2f58-rpx7-23m7

около 3 лет назад

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_sonos, at 0x9d01c3a0, the value for the `s_state` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2f58-m324-22jj

почти 4 года назад

Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain.

EPSS: Низкий
github логотип

GHSA-2f58-3p8j-4mx4

почти 4 года назад

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2f55-ch9h-2gfp

почти 3 года назад

Uncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2f54-rmw2-852f

почти 4 года назад

A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user?s browser session.

EPSS: Низкий
github логотип

GHSA-2f54-q22v-4g5r

почти 4 года назад

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypass vulnerability when manipulating Forms Data Format (FDF).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2f53-hr63-f79f

почти 4 года назад

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack the authentication of administrators via destructive controller actions, a different vulnerability than CVE-2010-5087.

EPSS: Низкий
github логотип

GHSA-2f52-v87j-7ppj

больше 3 лет назад

Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code. Successful exploitation allows an attacker to login using only a username and password and successfully bypass MFA requirements in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2f52-79rv-444c

2 месяца назад

Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files ldebug.C. This issue affects WickedEngine: before 0.71.705.

EPSS: Низкий
github логотип

GHSA-2f4x-p9hx-9v3c

почти 4 года назад

SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter.

EPSS: Низкий
github логотип

GHSA-2f4x-947v-p53c

почти 4 года назад

IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2f4w-6mc7-4w78

около 1 года назад

LibreNMS Display Name 2 Stored Cross-site Scripting vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2f4w-2x4q-hpgg

почти 4 года назад

Unspecified vulnerability in AdAstrA TRACE MODE Data Center allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by the GLEG Agora SCADA+ Exploit Pack for Immunity CANVAS.

EPSS: Низкий
github логотип

GHSA-2f4v-85x8-m662

почти 2 года назад

Windows Deployment Services Information Disclosure Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2f4v-4h68-m25j

больше 1 года назад

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2f4r-pfx3-8hjj

почти 4 года назад

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerability to execute code on the hypervisor from a virtual machine. Additional conditions beyond the attacker's control must be present for exploitation to be possible.

EPSS: Низкий
github логотип

GHSA-2f4r-9w89-phg8

около 4 лет назад

Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2f4r-6wjq-849q

12 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers allows Cross Site Request Forgery. This issue affects CM Answers: from n/a through 3.3.3.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2f58-x9v2-9x28

A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.

CVSS3: 6.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-2f58-vf6g-6p8x

MediaWiki Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2f58-rpx7-23m7

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_sonos, at 0x9d01c3a0, the value for the `s_state` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-2f58-m324-22jj

Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2f58-3p8j-4mx4

Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2f55-ch9h-2gfp

Uncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2f54-rmw2-852f

A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user?s browser session.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2f54-q22v-4g5r

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypass vulnerability when manipulating Forms Data Format (FDF).

CVSS3: 8.8
6%
Низкий
почти 4 года назад
github логотип
GHSA-2f53-hr63-f79f

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack the authentication of administrators via destructive controller actions, a different vulnerability than CVE-2010-5087.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2f52-v87j-7ppj

Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code. Successful exploitation allows an attacker to login using only a username and password and successfully bypass MFA requirements in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2f52-79rv-444c

Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files ldebug.C. This issue affects WickedEngine: before 0.71.705.

0%
Низкий
2 месяца назад
github логотип
GHSA-2f4x-p9hx-9v3c

SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2f4x-947v-p53c

IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.

CVSS3: 8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2f4w-6mc7-4w78

LibreNMS Display Name 2 Stored Cross-site Scripting vulnerability

CVSS3: 4.6
0%
Низкий
около 1 года назад
github логотип
GHSA-2f4w-2x4q-hpgg

Unspecified vulnerability in AdAstrA TRACE MODE Data Center allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by the GLEG Agora SCADA+ Exploit Pack for Immunity CANVAS.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2f4v-85x8-m662

Windows Deployment Services Information Disclosure Vulnerability

CVSS3: 6.5
7%
Низкий
почти 2 года назад
github логотип
GHSA-2f4v-4h68-m25j

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2f4r-pfx3-8hjj

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue in the USB 2.0 controller (EHCI). A malicious actor with local access to a virtual machine may be able to exploit this vulnerability to execute code on the hypervisor from a virtual machine. Additional conditions beyond the attacker's control must be present for exploitation to be possible.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2f4r-9w89-phg8

Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication

CVSS3: 4.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-2f4r-6wjq-849q

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers allows Cross Site Request Forgery. This issue affects CM Answers: from n/a through 3.3.3.

CVSS3: 4.3
0%
Низкий
12 месяцев назад

Уязвимостей на страницу