Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-234j-gj4m-9pxf

почти 4 года назад

IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-234j-9vr7-j7mx

почти 4 года назад

An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to overwrite cookies via a crafted web site.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-234j-6f32-pqmg

почти 4 года назад

In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-234g-273x-9qxr

4 месяца назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-234f-wm58-6qqv

почти 4 года назад

Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based upon an initial disclosure. Details will be updated after the grace period has ended. This issue is different from CVE-2006-4133 and CVE-2006-4134.

EPSS: Низкий
github логотип

GHSA-234f-f38v-vqmg

18 дней назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Roisin roisin allows PHP Local File Inclusion.This issue affects Roisin: from n/a through <= 1.2.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-234c-whv9-v8j6

почти 4 года назад

dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.

EPSS: Низкий
github логотип

GHSA-234c-568r-p7m4

почти 4 года назад

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2349-9g3v-jxmj

около 4 лет назад

A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2348-qg6m-wv4j

4 месяца назад

A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp.app. Such manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2348-p6m3-vqc4

около 2 лет назад

A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been rated as critical. Affected by this issue is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252260. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2348-ccqj-8p27

почти 4 года назад

Jenkins RQM Plugin allows enumerating credentials IDs due to missing permission check

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2347-hhxr-8hg9

около 3 лет назад

NETGEAR Nighthawk R6220 v1.1.0.112_1.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2347-fp75-m9xc

почти 4 года назад

An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate web request issued by the application itself. This can be abused to conduct SSRF attacks against otherwise unreachable Acronis services that are bound to localhost such as the NotificationService on 127.0.0.1:30572.

EPSS: Средний
github логотип

GHSA-2347-6p44-pr5m

больше 2 лет назад

Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_db_info request, a related issue to CVE-2023-42387.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2347-3mgh-xw2g

почти 2 года назад

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2346-xh2v-3jjh

10 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fastw3b LLC FW Gallery allows PHP Local File Inclusion. This issue affects FW Gallery: from n/a through 8.0.0.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2346-h487-gw9h

почти 4 года назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.

EPSS: Низкий
github логотип

GHSA-2346-8v69-w74p

больше 3 лет назад

In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441630; Issue ID: ALPS07441630.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2346-6pqf-j299

больше 3 лет назад

Windows Group Policy Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37992.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-234j-gj4m-9pxf

IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 159944.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-234j-9vr7-j7mx

An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to overwrite cookies via a crafted web site.

CVSS3: 4.3
5%
Низкий
почти 4 года назад
github логотип
GHSA-234j-6f32-pqmg

In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).

CVSS3: 2.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-234g-273x-9qxr

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-234f-wm58-6qqv

Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based upon an initial disclosure. Details will be updated after the grace period has ended. This issue is different from CVE-2006-4133 and CVE-2006-4134.

1%
Низкий
почти 4 года назад
github логотип
GHSA-234f-f38v-vqmg

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Roisin roisin allows PHP Local File Inclusion.This issue affects Roisin: from n/a through <= 1.2.1.

CVSS3: 8.1
0%
Низкий
18 дней назад
github логотип
GHSA-234c-whv9-v8j6

dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.

0%
Низкий
почти 4 года назад
github логотип
GHSA-234c-568r-p7m4

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

CVSS3: 8.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-2349-9g3v-jxmj

A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 7.5
29%
Средний
около 4 лет назад
github логотип
GHSA-2348-qg6m-wv4j

A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp.app. Such manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2348-p6m3-vqc4

A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been rated as critical. Affected by this issue is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252260. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-2348-ccqj-8p27

Jenkins RQM Plugin allows enumerating credentials IDs due to missing permission check

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-2347-hhxr-8hg9

NETGEAR Nighthawk R6220 v1.1.0.112_1.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-2347-fp75-m9xc

An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate web request issued by the application itself. This can be abused to conduct SSRF attacks against otherwise unreachable Acronis services that are bound to localhost such as the NotificationService on 127.0.0.1:30572.

11%
Средний
почти 4 года назад
github логотип
GHSA-2347-6p44-pr5m

Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_db_info request, a related issue to CVE-2023-42387.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2347-3mgh-xw2g

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-2346-xh2v-3jjh

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fastw3b LLC FW Gallery allows PHP Local File Inclusion. This issue affects FW Gallery: from n/a through 8.0.0.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-2346-h487-gw9h

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2346-8v69-w74p

In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441630; Issue ID: ALPS07441630.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2346-6pqf-j299

Windows Group Policy Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37992.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу