Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-2987-rjmh-cpp7

18 дней назад

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2987-5c42-f4x4

почти 4 года назад

The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2987-2gpf-qmqg

почти 4 года назад

Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2986-vwq2-p2w6

почти 4 года назад

A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2986-hg3w-pgmr

около 14 часов назад

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2986-9f3x-j93c

больше 2 лет назад

Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2986-5hvv-7665

почти 4 года назад

The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.

EPSS: Средний
github логотип

GHSA-2986-5hcf-cm8g

около 4 лет назад

When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image

EPSS: Низкий
github логотип

GHSA-2984-fgj8-4x8h

почти 4 года назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

EPSS: Низкий
github логотип

GHSA-2984-652w-j78c

2 месяца назад

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a Web Server.This issue affects Miion: from n/a through <= 1.2.7.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2983-rc95-vrc7

почти 2 года назад

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture Firmware allows a local non-privileged user to make improper GPU processing operations to access a limited amount outside of buffer bounds. If the operations are carefully prepared, then this in turn could give them access to all system memory. This issue affects Valhall GPU Firmware: from r29p0 through r46p0; Arm 5th Gen GPU Architecture Firmware: from r41p0 through r46p0.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2983-hvjm-2229

8 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin WooCommerce Point Of Sale (POS) allows SQL Injection. This issue affects WooCommerce Point Of Sale (POS): from n/a through 1.4.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2982-34wj-7m53

11 месяцев назад

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1. This is due to missing or incorrect nonce validation on the dismiss() function. This makes it possible for unauthenticated attackers to set arbitrary user meta values to `1` which can be leveraged to lock and administrator out of their site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2982-268x-jwcx

почти 4 года назад

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the error handling functionality of web pages.

EPSS: Низкий
github логотип

GHSA-297x-j9pm-xjgg

почти 2 года назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-297x-8xj4-vcxv

почти 4 года назад

Improper Control of Generation of Code in doT

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-297x-2qf3-jrj3

около 2 лет назад

Unsafe yaml deserialization in llama-hub

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-297w-r8j3-c69q

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup allows DOM-Based XSS. This issue affects EZ InLinkz linkup: from n/a through 0.18.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-297w-mgxc-v84x

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-297w-79rr-rq4p

больше 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MultiVendorX Product Stock Manager & Notifier for WooCommerce.This issue affects Product Stock Manager & Notifier for WooCommerce: from n/a through 2.0.1.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2987-rjmh-cpp7

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

CVSS3: 9.8
0%
Низкий
18 дней назад
github логотип
GHSA-2987-5c42-f4x4

The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.

CVSS3: 3.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2987-2gpf-qmqg

Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.

CVSS3: 7.5
13%
Средний
почти 4 года назад
github логотип
GHSA-2986-vwq2-p2w6

A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2986-hg3w-pgmr

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

CVSS3: 8.8
около 14 часов назад
github логотип
GHSA-2986-9f3x-j93c

Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.

CVSS3: 6.1
5%
Низкий
больше 2 лет назад
github логотип
GHSA-2986-5hvv-7665

The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.

26%
Средний
почти 4 года назад
github логотип
GHSA-2986-5hcf-cm8g

When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image

0%
Низкий
около 4 лет назад
github логотип
GHSA-2984-fgj8-4x8h

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2984-652w-j78c

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a Web Server.This issue affects Miion: from n/a through <= 1.2.7.

CVSS3: 9.9
0%
Низкий
2 месяца назад
github логотип
GHSA-2983-rc95-vrc7

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture Firmware allows a local non-privileged user to make improper GPU processing operations to access a limited amount outside of buffer bounds. If the operations are carefully prepared, then this in turn could give them access to all system memory. This issue affects Valhall GPU Firmware: from r29p0 through r46p0; Arm 5th Gen GPU Architecture Firmware: from r41p0 through r46p0.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2983-hvjm-2229

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin WooCommerce Point Of Sale (POS) allows SQL Injection. This issue affects WooCommerce Point Of Sale (POS): from n/a through 1.4.

CVSS3: 8.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2982-34wj-7m53

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1. This is due to missing or incorrect nonce validation on the dismiss() function. This makes it possible for unauthenticated attackers to set arbitrary user meta values to `1` which can be leveraged to lock and administrator out of their site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2982-268x-jwcx

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the error handling functionality of web pages.

0%
Низкий
почти 4 года назад
github логотип
GHSA-297x-j9pm-xjgg

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
94%
Критический
почти 2 года назад
github логотип
GHSA-297x-8xj4-vcxv

Improper Control of Generation of Code in doT

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-297x-2qf3-jrj3

Unsafe yaml deserialization in llama-hub

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-297w-r8j3-c69q

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup allows DOM-Based XSS. This issue affects EZ InLinkz linkup: from n/a through 0.18.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-297w-mgxc-v84x

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-297w-79rr-rq4p

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MultiVendorX Product Stock Manager & Notifier for WooCommerce.This issue affects Product Stock Manager & Notifier for WooCommerce: from n/a through 2.0.1.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу