Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v27-f65g-fr6x

6 месяцев назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v27-cw49-q24f

больше 4 лет назад

List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.

EPSS: Низкий
github логотип

GHSA-4v26-v6cg-g6f9

6 месяцев назад

xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4v26-47w8-q4gm

около 1 года назад

A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided by OMRON SOCIAL SOLUTIONS Co., Ltd., where the executable file paths of Windows services are not enclosed in quotation marks. If the installation folder path of this product contains spaces, there is a possibility that unauthorized files may be executed under the service privileges by using paths containing spaces.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4v26-3qrx-r7mq

около 4 лет назад

A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4v25-p375-pcjc

больше 2 лет назад

XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4v24-mjr7-pmr3

14 дней назад

Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v24-3w3q-g36w

12 месяцев назад

Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4v22-j8v6-qgvh

3 месяца назад

Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity headers allowing the attacker to get unauthorized access the protected resources. This issue affects Apache APISIX: from 2.3 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4rxx-6c3r-g2p4

больше 4 лет назад

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-4rxw-r623-vp2w

почти 3 года назад

Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4rxv-m7gf-r8rf

больше 3 лет назад

A vulnerability was found in juju2143 WalrusIRC 0.0.2. It has been rated as problematic. This issue affects the function parseLinks of the file public/parser.js. The manipulation of the argument text leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 0.0.3 is able to address this issue. The name of the patch is 45fd885895ae13e8d9b3a71e89d59768914f60af. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220751.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4rxv-8f9g-9h5w

5 дней назад

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rxr-g7cg-rwg8

больше 2 лет назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

CVSS3: 10
EPSS: Высокий
github логотип

GHSA-4rxr-9956-j9gp

больше 4 лет назад

AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon mobile and snapdragon wear in versions MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 835, SD 845, SD 850

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rxr-8xrx-9rf3

больше 2 лет назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, tvOS 17.4. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4rxr-6q7p-q23g

больше 4 лет назад

The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.

EPSS: Средний
github логотип

GHSA-4rxr-27mm-mxq9

почти 4 года назад

Upstash Adapter missing token verification

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4rxq-xcjw-9ww8

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rxq-j825-6wv8

больше 4 лет назад

Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v27-f65g-fr6x

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-4v27-cw49-q24f

List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v26-v6cg-g6f9

xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption

CVSS3: 8.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-4v26-47w8-q4gm

A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided by OMRON SOCIAL SOLUTIONS Co., Ltd., where the executable file paths of Windows services are not enclosed in quotation marks. If the installation folder path of this product contains spaces, there is a possibility that unauthorized files may be executed under the service privileges by using paths containing spaces.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-4v26-3qrx-r7mq

A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-4v25-p375-pcjc

XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4v24-mjr7-pmr3

Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.

CVSS3: 7.5
0%
Низкий
14 дней назад
github логотип
GHSA-4v24-3w3q-g36w

Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.

CVSS3: 4.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-4v22-j8v6-qgvh

Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity headers allowing the attacker to get unauthorized access the protected resources. This issue affects Apache APISIX: from 2.3 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 9.1
0%
Низкий
3 месяца назад
github логотип
GHSA-4rxx-6c3r-g2p4

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
87%
Высокий
больше 4 лет назад
github логотип
GHSA-4rxw-r623-vp2w

Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-4rxv-m7gf-r8rf

A vulnerability was found in juju2143 WalrusIRC 0.0.2. It has been rated as problematic. This issue affects the function parseLinks of the file public/parser.js. The manipulation of the argument text leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 0.0.3 is able to address this issue. The name of the patch is 45fd885895ae13e8d9b3a71e89d59768914f60af. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220751.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4rxv-8f9g-9h5w

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.

CVSS3: 9.8
0%
Низкий
5 дней назад
github логотип
GHSA-4rxr-g7cg-rwg8

Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

CVSS3: 10
88%
Высокий
больше 2 лет назад
github логотип
GHSA-4rxr-9956-j9gp

AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon mobile and snapdragon wear in versions MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 835, SD 845, SD 850

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rxr-8xrx-9rf3

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, tvOS 17.4. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4rxr-6q7p-q23g

The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.

11%
Средний
больше 4 лет назад
github логотип
GHSA-4rxr-27mm-mxq9

Upstash Adapter missing token verification

CVSS3: 6.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-4rxq-xcjw-9ww8

Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-4rxq-j825-6wv8

Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад

Уязвимостей на страницу