Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-29m8-wh9p-5wc4

около 1 года назад

Apache Kylin Code Injection via JDBC Configuration Alteration

EPSS: Низкий
github логотип

GHSA-29m8-q2f8-5742

около 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider allows Blind SQL Injection. This issue affects WP Yelp Review Slider: from n/a through 8.1.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-29m8-hp2v-37qc

больше 3 лет назад

The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-29m8-fq8p-5fcw

больше 3 лет назад

Azure Site Recovery Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35824.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-29m8-88g5-xjpp

29 дней назад

An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specifically crafted SSH config file.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29m8-82c7-qqgx

почти 4 года назад

Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.

EPSS: Низкий
github логотип

GHSA-29m7-frx3-67fg

почти 4 года назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Tomcat configuration file. The issue results from the lack of proper restriction to the Tomcat admin console. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10799.

EPSS: Низкий
github логотип

GHSA-29m7-62mp-2jf6

почти 4 года назад

Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.

EPSS: Низкий
github логотип

GHSA-29m7-5q7x-g3fr

больше 2 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-29m6-68fv-pgx2

почти 4 года назад

Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.

EPSS: Низкий
github логотип

GHSA-29m5-ghm3-6rpq

около 1 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Green Planet green-planet allows PHP Local File Inclusion.This issue affects Green Planet: from n/a through <= 1.1.14.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-29m4-mx89-3mjg

почти 2 года назад

TYPO3 Denial of Service in Online Media Asset Handling

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29m4-8vqj-fpfg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter.

EPSS: Низкий
github логотип

GHSA-29m3-xwpr-p76m

почти 4 года назад

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29m3-gxfx-749g

3 месяца назад

A security flaw has been discovered in yourmaileyes MOOC up to 1.17. This affects the function subreview of the file mooc/controller/MainController.java of the component Submission Handler. Performing manipulation of the argument review results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-29m2-jvgj-wx83

почти 4 года назад

Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-29m2-93j9-hrcp

почти 4 года назад

VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29jx-h9vr-rw83

почти 4 года назад

In createSimSelectNotification of SimSelectNotification.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153556754

EPSS: Низкий
github логотип

GHSA-29jx-3q54-p8gq

3 месяца назад

A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the component GTPv2 Bearer Response Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 98f76e98df35cd6a35e868aa62715db7f8141ac1. A patch should be applied to remediate this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29jw-cm22-w2mv

почти 4 года назад

regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29m8-wh9p-5wc4

Apache Kylin Code Injection via JDBC Configuration Alteration

0%
Низкий
около 1 года назад
github логотип
GHSA-29m8-q2f8-5742

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider allows Blind SQL Injection. This issue affects WP Yelp Review Slider: from n/a through 8.1.

CVSS3: 7.6
0%
Низкий
около 1 года назад
github логотип
GHSA-29m8-hp2v-37qc

The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29m8-fq8p-5fcw

Azure Site Recovery Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35824.

CVSS3: 7.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-29m8-88g5-xjpp

An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specifically crafted SSH config file.

CVSS3: 5.3
0%
Низкий
29 дней назад
github логотип
GHSA-29m8-82c7-qqgx

Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.

1%
Низкий
почти 4 года назад
github логотип
GHSA-29m7-frx3-67fg

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Tomcat configuration file. The issue results from the lack of proper restriction to the Tomcat admin console. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10799.

4%
Низкий
почти 4 года назад
github логотип
GHSA-29m7-62mp-2jf6

Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29m7-5q7x-g3fr

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29m6-68fv-pgx2

Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.

1%
Низкий
почти 4 года назад
github логотип
GHSA-29m5-ghm3-6rpq

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Green Planet green-planet allows PHP Local File Inclusion.This issue affects Green Planet: from n/a through <= 1.1.14.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-29m4-mx89-3mjg

TYPO3 Denial of Service in Online Media Asset Handling

CVSS3: 5.3
почти 2 года назад
github логотип
GHSA-29m4-8vqj-fpfg

Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-29m3-xwpr-p76m

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-29m3-gxfx-749g

A security flaw has been discovered in yourmaileyes MOOC up to 1.17. This affects the function subreview of the file mooc/controller/MainController.java of the component Submission Handler. Performing manipulation of the argument review results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.5
0%
Низкий
3 месяца назад
github логотип
GHSA-29m2-jvgj-wx83

Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.

CVSS3: 9.8
11%
Средний
почти 4 года назад
github логотип
GHSA-29m2-93j9-hrcp

VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-29jx-h9vr-rw83

In createSimSelectNotification of SimSelectNotification.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153556754

0%
Низкий
почти 4 года назад
github логотип
GHSA-29jx-3q54-p8gq

A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the component GTPv2 Bearer Response Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 98f76e98df35cd6a35e868aa62715db7f8141ac1. A patch should be applied to remediate this issue.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-29jw-cm22-w2mv

regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу