Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-29f2-5rg5-fpqh

больше 3 лет назад

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution in a victims browser.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-29cx-mrrh-g7pc

около 3 лет назад

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the EnterpriseServer service. The issue results from the lack of proper locking when performing operations during authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15528.

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-29cv-f9xj-9653

почти 4 года назад

The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.

EPSS: Низкий
github логотип

GHSA-29cr-mj24-pqgh

больше 2 лет назад

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29cr-f47w-93jr

больше 2 лет назад

Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-29cq-5w36-x7w3

9 месяцев назад

Livewire is vulnerable to remote command execution during component property update hydration

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-29cm-m432-745j

больше 1 года назад

SQL Server Native Client Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29cj-vw65-6494

почти 4 года назад

Uncaught exception in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29cj-cxw4-v4j2

7 месяцев назад

YesWiki Cross Site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-29ch-m3px-xxxc

почти 3 года назад

ARC (aka ARC2) through 2011-12-01 allows reflected XSS via the end_point.php query parameter in an output=htmltab action.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29ch-f7xh-hrh2

почти 4 года назад

The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing.

EPSS: Низкий
github логотип

GHSA-29ch-3cxc-63fh

около 4 лет назад

The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

EPSS: Низкий
github логотип

GHSA-29ch-39m4-vcw5

почти 4 года назад

In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article information of their customer tickets.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29ch-37gp-6r87

почти 4 года назад

The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.

EPSS: Низкий
github логотип

GHSA-29ch-225m-h3vc

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard Fast Custom Social Share by CodeBard allows Stored XSS.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-29cf-w3r7-xw8x

около 3 лет назад

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service and data tampering.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-29cf-7968-4gr3

8 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes allows Code Injection. This issue affects Add Custom Codes: from n/a through 4.80.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29cc-vcq3-44cf

почти 4 года назад

A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V4.3.7), RUGGEDCOM ROS M2200 (All versions < V4.3.7), RUGGEDCOM ROS M969 (All versions < V4.3.7), RUGGEDCOM ROS RMC (All versions < V4.3.7), RUGGEDCOM ROS RMC20 (All versions < V4.3.7), RUGGEDCOM ROS RMC30 (All versions < V4.3.7), RUGGEDCOM ROS RMC40 (All versions < V4.3.7), RUGGEDCOM ROS RMC41 (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RP110 (All versions < V4.3.7), RUGGEDCOM ROS RS400 (All versions < V4.3.7), RUGGEDCOM ROS RS401 (All versions < V4.3.7), RUGGEDCOM ROS RS416 (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V5.X (All versions < 5.5.4), RUGGEDCOM ROS RS8000 (All versions < V4.3.7), RUGGEDCOM ROS RS8000A (All versions < V4.3.7), RUGGEDCOM ROS RS8000H (All versions < V4.3.7), RUGGEDCOM ROS RS8000T (All versions < V4.3.7), RUGGEDCOM ROS RS900 (32M) V...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-29cc-hw6r-mr24

4 месяца назад

An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29cc-85vg-q282

около 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound JetWooBuilder allows PHP Local File Inclusion. This issue affects JetWooBuilder: from n/a through 2.1.18.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29f2-5rg5-fpqh

There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution in a victims browser.

CVSS3: 9.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-29cx-mrrh-g7pc

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the EnterpriseServer service. The issue results from the lack of proper locking when performing operations during authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15528.

CVSS3: 8.1
12%
Средний
около 3 лет назад
github логотип
GHSA-29cv-f9xj-9653

The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.

2%
Низкий
почти 4 года назад
github логотип
GHSA-29cr-mj24-pqgh

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-29cr-f47w-93jr

Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29cq-5w36-x7w3

Livewire is vulnerable to remote command execution during component property update hydration

CVSS3: 9.8
58%
Средний
9 месяцев назад
github логотип
GHSA-29cm-m432-745j

SQL Server Native Client Remote Code Execution Vulnerability

CVSS3: 8.8
4%
Низкий
больше 1 года назад
github логотип
GHSA-29cj-vw65-6494

Uncaught exception in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-29cj-cxw4-v4j2

YesWiki Cross Site Scripting vulnerability

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-29ch-m3px-xxxc

ARC (aka ARC2) through 2011-12-01 allows reflected XSS via the end_point.php query parameter in an output=htmltab action.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-29ch-f7xh-hrh2

The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29ch-3cxc-63fh

The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

0%
Низкий
около 4 лет назад
github логотип
GHSA-29ch-39m4-vcw5

In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article information of their customer tickets.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-29ch-37gp-6r87

The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29ch-225m-h3vc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard Fast Custom Social Share by CodeBard allows Stored XSS.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.1.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29cf-w3r7-xw8x

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service and data tampering.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-29cf-7968-4gr3

Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes allows Code Injection. This issue affects Add Custom Codes: from n/a through 4.80.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-29cc-vcq3-44cf

A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V4.3.7), RUGGEDCOM ROS M2200 (All versions < V4.3.7), RUGGEDCOM ROS M969 (All versions < V4.3.7), RUGGEDCOM ROS RMC (All versions < V4.3.7), RUGGEDCOM ROS RMC20 (All versions < V4.3.7), RUGGEDCOM ROS RMC30 (All versions < V4.3.7), RUGGEDCOM ROS RMC40 (All versions < V4.3.7), RUGGEDCOM ROS RMC41 (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RP110 (All versions < V4.3.7), RUGGEDCOM ROS RS400 (All versions < V4.3.7), RUGGEDCOM ROS RS401 (All versions < V4.3.7), RUGGEDCOM ROS RS416 (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V5.X (All versions < 5.5.4), RUGGEDCOM ROS RS8000 (All versions < V4.3.7), RUGGEDCOM ROS RS8000A (All versions < V4.3.7), RUGGEDCOM ROS RS8000H (All versions < V4.3.7), RUGGEDCOM ROS RS8000T (All versions < V4.3.7), RUGGEDCOM ROS RS900 (32M) V...

CVSS3: 8.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-29cc-hw6r-mr24

An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-29cc-85vg-q282

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound JetWooBuilder allows PHP Local File Inclusion. This issue affects JetWooBuilder: from n/a through 2.1.18.

CVSS3: 7.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу