Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 419

Количество 323 419

github логотип

GHSA-25fv-6fhv-mjcq

почти 4 года назад

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

EPSS: Низкий
github логотип

GHSA-25fv-45mr-wm5r

12 месяцев назад

A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless range can resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages. This allows spoofed commands to be injected without authentication, triggering false alerts and misleading the user through notifications in the mobile application used to monitor the network.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-25fr-wqcg-x83x

почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentication of administrators and users for requests that change passwords.

EPSS: Низкий
github логотип

GHSA-25fr-px8w-jvcm

больше 1 года назад

Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-25fr-pq5j-rg59

больше 1 года назад

This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending a specially crafted input to the vulnerable parameter to perform reflected Cross Site Scripting (XSS) attacks on the targeted system.

EPSS: Низкий
github логотип

GHSA-25fr-p9c4-3h4q

почти 4 года назад

The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25fr-9mxc-qjvr

около 1 года назад

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-25fq-6qgg-qpj8

около 2 месяцев назад

SCEditor has DOM XSS via emoticon URL/HTML injection

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-25fp-8w8p-mx36

около 2 месяцев назад

OpenSTAManager has an OS Command Injection in P7M File Processing

EPSS: Низкий
github логотип

GHSA-25fm-hfr5-5989

почти 4 года назад

Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40474, CVE-2021-40479, CVE-2021-40485.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25fm-h323-2298

почти 4 года назад

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-25fm-gvgp-hcrp

почти 4 года назад

IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino does not properly handle URLs that request images, which allows remote authenticated users to cause a denial of service (daemon crash) via a request to resources.nsf, aka SPR XFXF7JDBCX.

EPSS: Низкий
github логотип

GHSA-25fm-5c3h-wg69

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) msg_result and (2) rep_titre parameters in (a) read.php; and the (3) id and (4) parent parameters and (5) CSForum_nom, (6) CSForum_mail, and (7) CSForum_url cookie parameters in (b) ajouter.php.

EPSS: Низкий
github логотип

GHSA-25fj-gxq4-4fv9

почти 4 года назад

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

EPSS: Низкий
github логотип

GHSA-25fh-x6gg-93xg

7 месяцев назад

The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_custom_fields function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change plugin custom fields.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25fh-g53r-vqxf

почти 4 года назад

Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

EPSS: Низкий
github логотип

GHSA-25fh-5c58-j8q5

4 месяца назад

Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25fh-589c-4pcj

около 1 года назад

The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25fg-pjf6-wj33

почти 4 года назад

Unspecified vulnerability in the Application Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Patch Administrator.

EPSS: Низкий
github логотип

GHSA-25fg-m85m-j989

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the registration form in Casinosoft Casino Script (Masvet) 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) surname field.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25fv-6fhv-mjcq

WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

1%
Низкий
почти 4 года назад
github логотип
GHSA-25fv-45mr-wm5r

A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless range can resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages. This allows spoofed commands to be injected without authentication, triggering false alerts and misleading the user through notifications in the mobile application used to monitor the network.

CVSS3: 9.1
1%
Низкий
12 месяцев назад
github логотип
GHSA-25fr-wqcg-x83x

Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentication of administrators and users for requests that change passwords.

0%
Низкий
почти 4 года назад
github логотип
GHSA-25fr-px8w-jvcm

Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-25fr-pq5j-rg59

This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending a specially crafted input to the vulnerable parameter to perform reflected Cross Site Scripting (XSS) attacks on the targeted system.

1%
Низкий
больше 1 года назад
github логотип
GHSA-25fr-p9c4-3h4q

The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-25fr-9mxc-qjvr

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

CVSS3: 5
0%
Низкий
около 1 года назад
github логотип
GHSA-25fq-6qgg-qpj8

SCEditor has DOM XSS via emoticon URL/HTML injection

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-25fp-8w8p-mx36

OpenSTAManager has an OS Command Injection in P7M File Processing

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-25fm-hfr5-5989

Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40474, CVE-2021-40479, CVE-2021-40485.

CVSS3: 7.8
5%
Низкий
почти 4 года назад
github логотип
GHSA-25fm-h323-2298

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-25fm-gvgp-hcrp

IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino does not properly handle URLs that request images, which allows remote authenticated users to cause a denial of service (daemon crash) via a request to resources.nsf, aka SPR XFXF7JDBCX.

0%
Низкий
почти 4 года назад
github логотип
GHSA-25fm-5c3h-wg69

Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) msg_result and (2) rep_titre parameters in (a) read.php; and the (3) id and (4) parent parameters and (5) CSForum_nom, (6) CSForum_mail, and (7) CSForum_url cookie parameters in (b) ajouter.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-25fj-gxq4-4fv9

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

1%
Низкий
почти 4 года назад
github логотип
GHSA-25fh-x6gg-93xg

The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_custom_fields function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change plugin custom fields.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-25fh-g53r-vqxf

Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-25fh-5c58-j8q5

Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-25fh-589c-4pcj

The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.

CVSS3: 9.8
3%
Низкий
около 1 года назад
github логотип
GHSA-25fg-pjf6-wj33

Unspecified vulnerability in the Application Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Patch Administrator.

0%
Низкий
почти 4 года назад
github логотип
GHSA-25fg-m85m-j989

Multiple cross-site scripting (XSS) vulnerabilities in the registration form in Casinosoft Casino Script (Masvet) 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) surname field.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу