Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4r9r-cpgw-cf98

почти 3 года назад

Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r9r-ch6f-vxmx

около 1 года назад

Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile

EPSS: Низкий
github логотип

GHSA-4r9r-4425-74p7

около 2 месяцев назад

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4r9q-wqcj-x85j

больше 4 лет назад

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability.

CVSS3: 7.8
EPSS: Критический
github логотип

GHSA-4r9q-943r-vw7w

больше 4 лет назад

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module when processing metadata in JPEG images. A successful attack can lead to sensitive data exposure.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-4r9q-4cwx-mg9v

больше 4 лет назад

Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-4r9q-49xf-jvj3

около 2 лет назад

The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4r9p-m9h5-r8vm

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.

EPSS: Низкий
github логотип

GHSA-4r9p-cvjh-239m

больше 4 лет назад

The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4r9m-prw4-64m4

больше 4 лет назад

SQL injection vulnerability in the Customer Reference List (ref_list) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4r9m-hpcf-jwxq

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Arigato Autoresponder and Newsletter allows Reflected XSS. This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4r9m-gmj4-v54c

больше 4 лет назад

Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.

EPSS: Низкий
github логотип

GHSA-4r9j-v95c-pgxw

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in odihost Easy 301 Redirects allows Cross Site Request Forgery. This issue affects Easy 301 Redirects: from n/a through 1.33.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4r9h-x77w-mffv

почти 4 года назад

collective.task Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4r9h-gpvv-2xg3

больше 4 лет назад

The /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted 0xc0d8b300 ioctl call.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r9h-gm76-v6c4

больше 4 лет назад

The Facebook Facts (aka com.wFacebookFacts) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4r9g-w48q-8jwm

почти 4 года назад

HyperDown vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4r9g-c2fj-783p

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ice: Block switchdev mode when ADQ is active and vice versa ADQ and switchdev are not supported simultaneously. Enabling both at the same time can result in nullptr dereference. To prevent this, check if ADQ is active when changing devlink mode to switchdev mode, and check if switchdev is active when enabling ADQ.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4r9f-wq7m-x6mw

12 дней назад

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4r9f-9cvp-xjm7

больше 4 лет назад

iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4r9r-cpgw-cf98

Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4r9r-ch6f-vxmx

Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile

около 1 года назад
github логотип
GHSA-4r9r-4425-74p7

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

CVSS3: 8.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-4r9q-wqcj-x85j

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability.

CVSS3: 7.8
99%
Критический
больше 4 лет назад
github логотип
GHSA-4r9q-943r-vw7w

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module when processing metadata in JPEG images. A successful attack can lead to sensitive data exposure.

CVSS3: 6.5
11%
Средний
больше 4 лет назад
github логотип
GHSA-4r9q-4cwx-mg9v

Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system.

CVSS3: 7.2
28%
Средний
больше 4 лет назад
github логотип
GHSA-4r9q-49xf-jvj3

The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-4r9p-m9h5-r8vm

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r9p-cvjh-239m

The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r9m-prw4-64m4

SQL injection vulnerability in the Customer Reference List (ref_list) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r9m-hpcf-jwxq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Arigato Autoresponder and Newsletter allows Reflected XSS. This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.4.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4r9m-gmj4-v54c

Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-4r9j-v95c-pgxw

Cross-Site Request Forgery (CSRF) vulnerability in odihost Easy 301 Redirects allows Cross Site Request Forgery. This issue affects Easy 301 Redirects: from n/a through 1.33.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4r9h-x77w-mffv

collective.task Cross-site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-4r9h-gpvv-2xg3

The /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted 0xc0d8b300 ioctl call.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r9h-gm76-v6c4

The Facebook Facts (aka com.wFacebookFacts) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r9g-w48q-8jwm

HyperDown vulnerable to Cross-site Scripting

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-4r9g-c2fj-783p

In the Linux kernel, the following vulnerability has been resolved: ice: Block switchdev mode when ADQ is active and vice versa ADQ and switchdev are not supported simultaneously. Enabling both at the same time can result in nullptr dereference. To prevent this, check if ADQ is active when changing devlink mode to switchdev mode, and check if switchdev is active when enabling ADQ.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4r9f-wq7m-x6mw

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
12 дней назад
github логотип
GHSA-4r9f-9cvp-xjm7

iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу