Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 322 267

Количество 322 267

github логотип

GHSA-22g4-6c36-68p9

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.

EPSS: Средний
github логотип

GHSA-22g3-xr7w-8vqq

почти 4 года назад

A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22g3-53pr-g6hg

12 месяцев назад

Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22g2-gpw7-9pqh

почти 4 года назад

The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parsed, which can cause attacker-controlled files to be written to the infotainment system and executed as root.

EPSS: Низкий
github логотип

GHSA-22g2-cxxf-8f85

почти 4 года назад

Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file.

EPSS: Средний
github логотип

GHSA-22fx-rv4f-228x

почти 2 года назад

Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22fx-6r9m-r8h9

почти 3 года назад

libheif vulnerable to segmentation fault via floating point exception

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22fw-9q6h-9hhc

больше 2 лет назад

The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.90. This is due to missing or incorrect nonce validation on the Save function. This makes it possible for unauthenticated attackers to make changes to invoices via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22fv-xwqp-5qhr

почти 4 года назад

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22fv-h3f5-g95w

11 месяцев назад

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22fv-7p67-g789

почти 4 года назад

SQL injection vulnerability in frontend/models/techfoliodetail.php in Techfolio (com_techfolio) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

EPSS: Низкий
github логотип

GHSA-22fr-qxwq-hh33

почти 4 года назад

Improper buffer restrictions in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.

EPSS: Низкий
github логотип

GHSA-22fr-q9q3-3hpx

почти 4 года назад

Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-22fr-57h7-x2qm

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes allows Cross Site Request Forgery. This issue affects Admin Notes: from n/a through 1.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22fq-gxhw-m8h5

12 месяцев назад

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22fp-mf44-f2mq

11 месяцев назад

youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22fp-492m-4h47

почти 4 года назад

The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-22fm-2rjp-5f34

почти 4 года назад

Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-22fj-xvpx-pqm9

около 2 лет назад

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-22fj-hq2r-qcpq

больше 2 лет назад

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.0.0 and 6.7.0 through 6.7.5 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via crafted API requests.

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22g4-6c36-68p9

Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.

61%
Средний
почти 4 года назад
github логотип
GHSA-22g3-xr7w-8vqq

A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-22g3-53pr-g6hg

Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-22g2-gpw7-9pqh

The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parsed, which can cause attacker-controlled files to be written to the infotainment system and executed as root.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22g2-cxxf-8f85

Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file.

44%
Средний
почти 4 года назад
github логотип
GHSA-22fx-rv4f-228x

Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.

CVSS3: 6.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-22fx-6r9m-r8h9

libheif vulnerable to segmentation fault via floating point exception

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-22fw-9q6h-9hhc

The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.90. This is due to missing or incorrect nonce validation on the Save function. This makes it possible for unauthenticated attackers to make changes to invoices via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22fv-xwqp-5qhr

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-22fv-h3f5-g95w

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 6.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-22fv-7p67-g789

SQL injection vulnerability in frontend/models/techfoliodetail.php in Techfolio (com_techfolio) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22fr-qxwq-hh33

Improper buffer restrictions in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22fr-q9q3-3hpx

Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

68%
Средний
почти 4 года назад
github логотип
GHSA-22fr-57h7-x2qm

Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes allows Cross Site Request Forgery. This issue affects Admin Notes: from n/a through 1.1.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-22fq-gxhw-m8h5

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-22fp-mf44-f2mq

youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization

CVSS3: 7.8
11 месяцев назад
github логотип
GHSA-22fp-492m-4h47

The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22fm-2rjp-5f34

Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 5.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-22fj-xvpx-pqm9

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-22fj-hq2r-qcpq

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.0.0 and 6.7.0 through 6.7.5 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via crafted API requests.

CVSS3: 9.8
76%
Высокий
больше 2 лет назад

Уязвимостей на страницу