Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 081

Количество 324 081

github логотип

GHSA-279v-q4q9-mx7j

больше 2 лет назад

Improper Initialization in firmware for some Intel(R) Optane(TM) SSD products may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-279v-98r6-v7g8

почти 4 года назад

Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack on hash values in the database, aka ZEN-15413.

EPSS: Низкий
github логотип

GHSA-279r-fmjg-85qx

почти 4 года назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-12936.

EPSS: Средний
github логотип

GHSA-279q-vh9q-c9w4

больше 2 лет назад

The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-279q-m5wr-9ff4

почти 3 года назад

Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-279q-3xp7-xvgp

больше 3 лет назад

CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-279p-xgvm-r6g6

почти 4 года назад

DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a symlink attack on the temporary file.

EPSS: Низкий
github логотип

GHSA-279p-pc38-xx4p

почти 4 года назад

JFinal file validation vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-279p-8h87-pr33

около 3 лет назад

platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-279p-29gw-62v2

почти 4 года назад

PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter.

EPSS: Низкий
github логотип

GHSA-279m-c6v8-cm85

почти 4 года назад

The Diabetes Forum (aka com.tapatalk.diabetescoukdiabetesforum) application 3.9.30 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-279j-x4gx-hfrh

больше 1 года назад

Gradio uses insecure communication between the FRP client and server

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-279h-w9gh-fpvc

почти 4 года назад

In Youngzsoft CCFile (aka CC File Transfer) 3.6, by sending a crafted HTTP request, it is possible for a malicious user to remotely crash the affected software. No authentication is required. An example payload is a malformed request header with many '|' characters. NOTE: some sources use this ID for a NoviWare issue, but the correct ID for that issue is CVE-2017-12787.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-279h-9ccj-88q7

почти 4 года назад

The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-279h-8hwx-39m5

около 2 лет назад

The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by tricking a logged in admin into submitting a form.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-279h-83gv-45m4

почти 4 года назад

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175410.

EPSS: Низкий
github логотип

GHSA-279g-qmgj-gvvw

почти 4 года назад

Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPhone 1.1.1 allows user-assisted remote attackers to cause a denial of service (application crash), and enable filesystem browsing by the local user, via a certain TIFF file.

EPSS: Низкий
github логотип

GHSA-279g-54q8-w7ww

почти 4 года назад

A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

EPSS: Низкий
github логотип

GHSA-279f-qwgh-h5mp

больше 2 лет назад

Jenkins does not exclude sensitive build variables from search

CVSS3: 4.3
EPSS: Средний
github логотип

GHSA-279f-qp3q-j675

около 1 года назад

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-279v-q4q9-mx7j

Improper Initialization in firmware for some Intel(R) Optane(TM) SSD products may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-279v-98r6-v7g8

Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack on hash values in the database, aka ZEN-15413.

0%
Низкий
почти 4 года назад
github логотип
GHSA-279r-fmjg-85qx

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-12936.

16%
Средний
почти 4 года назад
github логотип
GHSA-279q-vh9q-c9w4

The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-279q-m5wr-9ff4

Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-279q-3xp7-xvgp

CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-279p-xgvm-r6g6

DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a symlink attack on the temporary file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-279p-pc38-xx4p

JFinal file validation vulnerability

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-279p-8h87-pr33

platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-279p-29gw-62v2

PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter.

4%
Низкий
почти 4 года назад
github логотип
GHSA-279m-c6v8-cm85

The Diabetes Forum (aka com.tapatalk.diabetescoukdiabetesforum) application 3.9.30 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-279j-x4gx-hfrh

Gradio uses insecure communication between the FRP client and server

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-279h-w9gh-fpvc

In Youngzsoft CCFile (aka CC File Transfer) 3.6, by sending a crafted HTTP request, it is possible for a malicious user to remotely crash the affected software. No authentication is required. An example payload is a malformed request header with many '|' characters. NOTE: some sources use this ID for a NoviWare issue, but the correct ID for that issue is CVE-2017-12787.

CVSS3: 7.5
2%
Низкий
почти 4 года назад
github логотип
GHSA-279h-9ccj-88q7

The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS3: 7.5
7%
Низкий
почти 4 года назад
github логотип
GHSA-279h-8hwx-39m5

The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by tricking a logged in admin into submitting a form.

CVSS3: 8.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-279h-83gv-45m4

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175410.

0%
Низкий
почти 4 года назад
github логотип
GHSA-279g-qmgj-gvvw

Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPhone 1.1.1 allows user-assisted remote attackers to cause a denial of service (application crash), and enable filesystem browsing by the local user, via a certain TIFF file.

3%
Низкий
почти 4 года назад
github логотип
GHSA-279g-54q8-w7ww

A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

0%
Низкий
почти 4 года назад
github логотип
GHSA-279f-qwgh-h5mp

Jenkins does not exclude sensitive build variables from search

CVSS3: 4.3
51%
Средний
больше 2 лет назад
github логотип
GHSA-279f-qp3q-j675

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.

CVSS3: 6.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу