Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 805

Количество 323 805

github логотип

GHSA-26w2-2f8h-v6xj

почти 4 года назад

Premium Antispam in Symantec Mail Security for Domino Server 5.1.x before 5.1.2.28 does not filter certain SMTP address formats, which allows remote attackers to use the product as a spam relay.

EPSS: Низкий
github логотип

GHSA-26vv-h7j3-gv3q

9 месяцев назад

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-26vv-46rq-5vmv

почти 4 года назад

Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a "Receive data file" LPD command. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-26vr-h5vf-58cq

около 2 месяцев назад

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-26vr-8j45-3r4w

почти 5 лет назад

Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-26vr-8g66-chcv

около 3 лет назад

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-26vr-2vpv-r92q

почти 3 года назад

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-26vq-hm3j-jx75

больше 1 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: from n/a through 1.0.33.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26vq-f7w9-38r3

почти 4 года назад

SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.

EPSS: Низкий
github логотип

GHSA-26vp-298r-fj8f

почти 4 года назад

In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185193932

EPSS: Низкий
github логотип

GHSA-26vj-q53w-3g76

11 месяцев назад

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-26vj-jqr4-v7fv

больше 2 лет назад

Dynamics 365 Finance Spoofing Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26vh-pr9j-whxx

почти 4 года назад

Unspecified vulnerability in the wpprop code for Project EROS bbsengine before 20060622-0315 has unknown impact and remote attack vectors via [img] tags, possibly cross-site scripting (XSS).

EPSS: Низкий
github логотип

GHSA-26vh-hjq5-fv9v

больше 1 года назад

Missing Authorization vulnerability in wppal Easy Captcha allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Captcha: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26vg-2p3j-9wv3

почти 4 года назад

A vulnerability in TCP port management in Cisco ONS 15454 Series Multiservice Provisioning Platforms could allow an unauthenticated, remote attacker to cause the controller card to unexpectedly reload. More Information: CSCuw26032. Known Affected Releases: 10.51.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26vc-chp7-cj4q

почти 4 года назад

u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Voice & Music in Bitra, Nicobar, Saipan, SM6150, SM8150, SM8250, SXR2130

EPSS: Низкий
github логотип

GHSA-26vc-7jr9-jq6g

почти 4 года назад

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.

EPSS: Низкий
github логотип

GHSA-26v9-qvmq-8frg

почти 4 года назад

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

EPSS: Низкий
github логотип

GHSA-26v8-q35j-h6q9

больше 3 лет назад

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26v8-ffh8-7vqg

почти 4 года назад

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26w2-2f8h-v6xj

Premium Antispam in Symantec Mail Security for Domino Server 5.1.x before 5.1.2.28 does not filter certain SMTP address formats, which allows remote attackers to use the product as a spam relay.

1%
Низкий
почти 4 года назад
github логотип
GHSA-26vv-h7j3-gv3q

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVSS3: 9.8
83%
Высокий
9 месяцев назад
github логотип
GHSA-26vv-46rq-5vmv

Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a "Receive data file" LPD command. NOTE: some of these details are obtained from third party information.

12%
Средний
почти 4 года назад
github логотип
GHSA-26vr-h5vf-58cq

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

CVSS3: 4.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-26vr-8j45-3r4w

Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources

CVSS3: 7.5
12%
Средний
почти 5 лет назад
github логотип
GHSA-26vr-8g66-chcv

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-26vr-2vpv-r92q

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.

CVSS3: 7.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-26vq-hm3j-jx75

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: from n/a through 1.0.33.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-26vq-f7w9-38r3

SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26vp-298r-fj8f

In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185193932

0%
Низкий
почти 4 года назад
github логотип
GHSA-26vj-q53w-3g76

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-26vj-jqr4-v7fv

Dynamics 365 Finance Spoofing Vulnerability

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26vh-pr9j-whxx

Unspecified vulnerability in the wpprop code for Project EROS bbsengine before 20060622-0315 has unknown impact and remote attack vectors via [img] tags, possibly cross-site scripting (XSS).

0%
Низкий
почти 4 года назад
github логотип
GHSA-26vh-hjq5-fv9v

Missing Authorization vulnerability in wppal Easy Captcha allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Captcha: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-26vg-2p3j-9wv3

A vulnerability in TCP port management in Cisco ONS 15454 Series Multiservice Provisioning Platforms could allow an unauthenticated, remote attacker to cause the controller card to unexpectedly reload. More Information: CSCuw26032. Known Affected Releases: 10.51.

CVSS3: 7.5
2%
Низкий
почти 4 года назад
github логотип
GHSA-26vc-chp7-cj4q

u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Voice & Music in Bitra, Nicobar, Saipan, SM6150, SM8150, SM8250, SXR2130

0%
Низкий
почти 4 года назад
github логотип
GHSA-26vc-7jr9-jq6g

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26v9-qvmq-8frg

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26v8-q35j-h6q9

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26v8-ffh8-7vqg

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
94%
Критический
почти 4 года назад

Уязвимостей на страницу