Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 805

Количество 323 805

github логотип

GHSA-26wh-hvvw-2vc6

почти 4 года назад

Unspecified vulnerability in the Oracle Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to DMSYS.DBMS_DM_EXP_INTERNAL.

EPSS: Низкий
github логотип

GHSA-26wh-cc3r-w6pj

12 месяцев назад

canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-26wh-22xw-qfqx

почти 4 года назад

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-26wg-qj4f-57xc

почти 4 года назад

SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a different module than CVE-2007-4956.2.

EPSS: Низкий
github логотип

GHSA-26wg-3w7j-96gj

около 3 лет назад

Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to a stack-based buffer overflow which may allow an attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26wf-xmmh-wwqr

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3 allows remote attackers to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library.

EPSS: Низкий
github логотип

GHSA-26wf-vqvv-w3p8

почти 4 года назад

VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26wc-mjpc-3f8m

больше 1 года назад

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26wc-fvf8-2rgq

почти 4 года назад

arch/i386/kernel/sysenter.c in the Virtual Dynamic Shared Objects (vDSO) implementation in the Linux kernel before 2.6.21 does not properly check boundaries, which allows local users to gain privileges or cause a denial of service via unspecified vectors, related to the install_special_mapping, syscall, and syscall32_nopage functions.

EPSS: Низкий
github логотип

GHSA-26wc-3wqp-g3rp

почти 4 года назад

Deserialization of Untrusted Data in Jenkins

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-26wc-246g-r3wf

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: xsk: Fix xsk_diag use-after-free error during socket cleanup Fix a use-after-free error that is possible if the xsk_diag interface is used after the socket has been unbound from the device. This can happen either due to the socket being closed or the device disappearing. In the early days of AF_XDP, the way we tested that a socket was not bound to a device was to simply check if the netdevice pointer in the xsk socket structure was NULL. Later, a better system was introduced by having an explicit state variable in the xsk socket struct. For example, the state of a socket that is on the way to being closed and has been unbound from the device is XSK_UNBOUND. The commit in the Fixes tag below deleted the old way of signalling that a socket is unbound, setting dev to NULL. This in the belief that all code using the old way had been exterminated. That was unfortunately not true as the xsk diagnostics code was still u...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26w9-85c6-ccr8

почти 4 года назад

An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters.

EPSS: Средний
github логотип

GHSA-26w9-58jr-4jc3

почти 4 года назад

After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.

EPSS: Низкий
github логотип

GHSA-26w9-32mp-48g9

почти 2 года назад

Brocade SANnav before Brocade SANnav v2.3.1 lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated, remote attacker to reach Kafka APIs and send malicious data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26w7-fjp2-3w5x

около 4 лет назад

A vulnerability classified as problematic has been found in Kiddoware Kids Place. This affects the Home Button Protection. A repeated pressing of the button causes a local denial of service. It is recommended to upgrade the affected component.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26w6-gvvp-6v5v

больше 4 лет назад

An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.

EPSS: Низкий
github логотип

GHSA-26w5-7j2r-m53c

7 месяцев назад

A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-26w4-3wx5-pc45

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-26w3-q4j8-4xjp

около 2 лет назад

1Panel open source panel project has an unauthorized vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-26w2-6853-mrpc

больше 2 лет назад

A vulnerability was found in Campcodes Beauty Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235238 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26wh-hvvw-2vc6

Unspecified vulnerability in the Oracle Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to DMSYS.DBMS_DM_EXP_INTERNAL.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26wh-cc3r-w6pj

canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output

CVSS3: 8.2
0%
Низкий
12 месяцев назад
github логотип
GHSA-26wh-22xw-qfqx

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

CVSS3: 8.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-26wg-qj4f-57xc

SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a different module than CVE-2007-4956.2.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26wg-3w7j-96gj

Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to a stack-based buffer overflow which may allow an attacker to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-26wf-xmmh-wwqr

Cross-site scripting (XSS) vulnerability in Zenphoto before 1.4.3 allows remote attackers to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26wf-vqvv-w3p8

VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-26wc-mjpc-3f8m

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-26wc-fvf8-2rgq

arch/i386/kernel/sysenter.c in the Virtual Dynamic Shared Objects (vDSO) implementation in the Linux kernel before 2.6.21 does not properly check boundaries, which allows local users to gain privileges or cause a denial of service via unspecified vectors, related to the install_special_mapping, syscall, and syscall32_nopage functions.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26wc-3wqp-g3rp

Deserialization of Untrusted Data in Jenkins

CVSS3: 9.8
94%
Критический
почти 4 года назад
github логотип
GHSA-26wc-246g-r3wf

In the Linux kernel, the following vulnerability has been resolved: xsk: Fix xsk_diag use-after-free error during socket cleanup Fix a use-after-free error that is possible if the xsk_diag interface is used after the socket has been unbound from the device. This can happen either due to the socket being closed or the device disappearing. In the early days of AF_XDP, the way we tested that a socket was not bound to a device was to simply check if the netdevice pointer in the xsk socket structure was NULL. Later, a better system was introduced by having an explicit state variable in the xsk socket struct. For example, the state of a socket that is on the way to being closed and has been unbound from the device is XSK_UNBOUND. The commit in the Fixes tag below deleted the old way of signalling that a socket is unbound, setting dev to NULL. This in the belief that all code using the old way had been exterminated. That was unfortunately not true as the xsk diagnostics code was still u...

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-26w9-85c6-ccr8

An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters.

31%
Средний
почти 4 года назад
github логотип
GHSA-26w9-58jr-4jc3

After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.

1%
Низкий
почти 4 года назад
github логотип
GHSA-26w9-32mp-48g9

Brocade SANnav before Brocade SANnav v2.3.1 lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthenticated, remote attacker to reach Kafka APIs and send malicious data.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-26w7-fjp2-3w5x

A vulnerability classified as problematic has been found in Kiddoware Kids Place. This affects the Home Button Protection. A repeated pressing of the button causes a local denial of service. It is recommended to upgrade the affected component.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-26w6-gvvp-6v5v

An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-26w5-7j2r-m53c

A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-26w4-3wx5-pc45

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integration, leading (for example) to disclosure of a GCP service token.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-26w3-q4j8-4xjp

1Panel open source panel project has an unauthorized vulnerability.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-26w2-6853-mrpc

A vulnerability was found in Campcodes Beauty Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235238 is the identifier assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу