Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-xqw7-j7p9-vrvw

почти 4 года назад

Unspecified vulnerability in AgileWiki before 0.10.1 has unknown impact and attack vectors related to passwords.

EPSS: Низкий
github логотип

GHSA-xqw7-36rc-3p43

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: ipv4: check for NULL idev in ip_route_use_hint() syzbot was able to trigger a NULL deref in fib_validate_source() in an old tree [1]. It appears the bug exists in latest trees. All calls to __in_dev_get_rcu() must be checked for a NULL result. [1] general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 2 PID: 3257 Comm: syz-executor.3 Not tainted 5.10.0-syzkaller #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:fib_validate_source+0xbf/0x15a0 net/ipv4/fib_frontend.c:425 Code: 18 f2 f2 f2 f2 42 c7 44 20 23 f3 f3 f3 f3 48 89 44 24 78 42 c6 44 20 27 f3 e8 5d 88 48 fc 4c 89 e8 48 c1 e8 03 48 89 44 24 18 <42> 80 3c 20 00 74 08 4c 89 ef e8 d2 15 98 fc 48 89 5c 24 10 41 bf RSP: 0018:ffffc900015fee40 EFLAGS: 00010246 RAX: 000000000000000...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqw6-m98x-r88x

почти 4 года назад

The IP ingress packet handler on Cisco Aironet 1800 devices with software 8.1(112.3) and 8.1(112.4) allows remote attackers to cause a denial of service via a crafted header in an IP packet, aka Bug ID CSCuv63138.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqw6-9936-vppq

почти 4 года назад

Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.

EPSS: Низкий
github логотип

GHSA-xqw6-233f-6mq4

почти 4 года назад

Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability. Successful exploitation could lead to a security bypass.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqw5-p932-5jgr

больше 2 лет назад

A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. The manipulation of the argument c leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-241255.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xqw5-f5f6-22vf

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already has a bounds check on the array size but does not account for cache levels with separate data/instructions cache. Fix this by incrementing the index for any populated leaf (instead of any populated level).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqw4-p5gv-vxf6

около 3 лет назад

H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may allow a malicious actor to gain system privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqw4-hgfp-f28v

почти 4 года назад

Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.

EPSS: Низкий
github логотип

GHSA-xqw2-xw3g-cpj5

почти 3 года назад

Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqw2-jp6f-x74j

19 дней назад

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqw2-8hr2-gw5r

около 1 года назад

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive)

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xqw2-5rg4-323p

почти 4 года назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.

EPSS: Низкий
github логотип

GHSA-xqvx-2258-gfp2

больше 2 лет назад

Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-xqvw-x6gg-wh6x

почти 3 года назад

Incorrect access control in Videogo v6.8.1 allows attackers to bind shared devices after the connection has been ended.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xqvw-p594-3pxq

почти 4 года назад

An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitrary code execution via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function. IBM X-Force ID: 152079.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqvw-jp2q-crr2

почти 4 года назад

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-xqvw-7hh9-jm8v

больше 1 года назад

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqvw-6qp4-5g2p

5 месяцев назад

The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'saveSettings' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify plugin settings that control role capabilities, and subsequently exploit the misconfigured capabilities to duplicate and view password-protected posts containing sensitive information.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xqvv-gw6g-p8gh

почти 4 года назад

PHP remote file inclusion vulnerability in strload.php in Dayana Networks phpOnline (aka PHP-Online) 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the LangFile parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqw7-j7p9-vrvw

Unspecified vulnerability in AgileWiki before 0.10.1 has unknown impact and attack vectors related to passwords.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqw7-36rc-3p43

In the Linux kernel, the following vulnerability has been resolved: ipv4: check for NULL idev in ip_route_use_hint() syzbot was able to trigger a NULL deref in fib_validate_source() in an old tree [1]. It appears the bug exists in latest trees. All calls to __in_dev_get_rcu() must be checked for a NULL result. [1] general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 2 PID: 3257 Comm: syz-executor.3 Not tainted 5.10.0-syzkaller #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:fib_validate_source+0xbf/0x15a0 net/ipv4/fib_frontend.c:425 Code: 18 f2 f2 f2 f2 42 c7 44 20 23 f3 f3 f3 f3 48 89 44 24 78 42 c6 44 20 27 f3 e8 5d 88 48 fc 4c 89 e8 48 c1 e8 03 48 89 44 24 18 <42> 80 3c 20 00 74 08 4c 89 ef e8 d2 15 98 fc 48 89 5c 24 10 41 bf RSP: 0018:ffffc900015fee40 EFLAGS: 00010246 RAX: 000000000000000...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xqw6-m98x-r88x

The IP ingress packet handler on Cisco Aironet 1800 devices with software 8.1(112.3) and 8.1(112.4) allows remote attackers to cause a denial of service via a crafted header in an IP packet, aka Bug ID CSCuv63138.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqw6-9936-vppq

Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqw6-233f-6mq4

Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability. Successful exploitation could lead to a security bypass.

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-xqw5-p932-5jgr

A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. The manipulation of the argument c leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-241255.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqw5-f5f6-22vf

In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already has a bounds check on the array size but does not account for cache levels with separate data/instructions cache. Fix this by incrementing the index for any populated leaf (instead of any populated level).

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xqw4-p5gv-vxf6

H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may allow a malicious actor to gain system privileges.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xqw4-hgfp-f28v

Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqw2-xw3g-cpj5

Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xqw2-jp6f-x74j

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
19 дней назад
github логотип
GHSA-xqw2-8hr2-gw5r

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive)

CVSS3: 8.4
0%
Низкий
около 1 года назад
github логотип
GHSA-xqw2-5rg4-323p

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqvx-2258-gfp2

Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.

CVSS3: 4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqvw-x6gg-wh6x

Incorrect access control in Videogo v6.8.1 allows attackers to bind shared devices after the connection has been ended.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xqvw-p594-3pxq

An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitrary code execution via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function. IBM X-Force ID: 152079.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqvw-jp2q-crr2

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

CVSS3: 5.5
20%
Средний
почти 4 года назад
github логотип
GHSA-xqvw-7hh9-jm8v

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqvw-6qp4-5g2p

The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'saveSettings' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify plugin settings that control role capabilities, and subsequently exploit the misconfigured capabilities to duplicate and view password-protected posts containing sensitive information.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xqvv-gw6g-p8gh

PHP remote file inclusion vulnerability in strload.php in Dayana Networks phpOnline (aka PHP-Online) 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the LangFile parameter.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу