Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4c89-hmqm-65h7

около 3 лет назад

Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4c89-7wj7-fm5r

больше 4 лет назад

The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

EPSS: Низкий
github логотип

GHSA-4c88-vc7v-vjc9

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Web component in IBM Cognos TM1 before 9.5.2 FP3 and 10.1 before 10.1 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4c88-v3q4-r75x

больше 4 лет назад

Anviz access control devices allow remote attackers to issue commands without a password.

EPSS: Низкий
github логотип

GHSA-4c88-rc57-94rf

больше 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4c88-c5vh-m8mh

29 дней назад

In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx: Fix i.MX8MP VC8000E power up sequence Per errata[1]: ERR050531: VPU_NOC power down handshake may hang during VC8000E/VPUMIX power up/down cycling. Description: VC8000E reset de-assertion edge and AXI clock may have a timing issue. Workaround: Set bit2 (vc8000e_clk_en) of BLK_CLK_EN_CSR to 0 to gate off both AXI clock and VC8000E clock sent to VC8000E and AXI clock sent to VPU_NOC m_v_2 interface during VC8000E power up(VC8000E reset is de-asserted by HW) Add a bool variable is_errata_err050531 in 'struct imx8m_blk_ctrl_domain_data' to represent whether the workaround is needed. If is_errata_err050531 is true, first clear the clk before powering up gpc, then enable the clk after powering up gpc. [1] https://www.nxp.com/webapp/Download?colCode=IMX8MP_1P33A

EPSS: Низкий
github логотип

GHSA-4c88-2h2m-gjmm

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix smatch static checker warning adev->gfx.imu.funcs could be NULL

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4c87-xqpv-r7h5

почти 3 года назад

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4c87-gg2q-fc6m

около 6 лет назад

Malicious Package in rc-calendar-jhorst

EPSS: Низкий
github логотип

GHSA-4c87-9xq5-5c35

больше 4 лет назад

Content-Security-Policy protection for user content disabled by Jenkins ZAP Pipeline Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4c87-7rj9-cwg4

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalprocessing Nomupay Payment Processing Gateway allows Reflected XSS. This issue affects Nomupay Payment Processing Gateway: from n/a through 7.1.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4c85-w99g-9v4w

около 1 года назад

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4c85-h2g3-r272

больше 4 лет назад

Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u file.

EPSS: Низкий
github логотип

GHSA-4c84-c2x6-wwjv

больше 2 лет назад

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring GeoJSON settings. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.8.17, 3.9.12, 3.10.9, 3.11.7, and 3.12.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4c84-63pp-c7rv

6 месяцев назад

Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. Attackers can craft a username with a payload containing 4059 bytes of padding followed by a nseh value and seh pointer to trigger the overflow when adding a new user account.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4c83-m6v2-mvrm

больше 4 лет назад

Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4c82-32w7-vxc8

17 дней назад

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-4c7x-8f5j-c5c8

больше 4 лет назад

An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-4c7w-p94r-xj6r

больше 4 лет назад

SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of service via 100% CPU utilization. Restart of the application is required.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4c7w-4j3f-pff5

больше 4 лет назад

Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4c89-hmqm-65h7

Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.

CVSS3: 6.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-4c89-7wj7-fm5r

The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c88-vc7v-vjc9

Cross-site scripting (XSS) vulnerability in the Web component in IBM Cognos TM1 before 9.5.2 FP3 and 10.1 before 10.1 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c88-v3q4-r75x

Anviz access control devices allow remote attackers to issue commands without a password.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c88-rc57-94rf

Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4c88-c5vh-m8mh

In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx: Fix i.MX8MP VC8000E power up sequence Per errata[1]: ERR050531: VPU_NOC power down handshake may hang during VC8000E/VPUMIX power up/down cycling. Description: VC8000E reset de-assertion edge and AXI clock may have a timing issue. Workaround: Set bit2 (vc8000e_clk_en) of BLK_CLK_EN_CSR to 0 to gate off both AXI clock and VC8000E clock sent to VC8000E and AXI clock sent to VPU_NOC m_v_2 interface during VC8000E power up(VC8000E reset is de-asserted by HW) Add a bool variable is_errata_err050531 in 'struct imx8m_blk_ctrl_domain_data' to represent whether the workaround is needed. If is_errata_err050531 is true, first clear the clk before powering up gpc, then enable the clk after powering up gpc. [1] https://www.nxp.com/webapp/Download?colCode=IMX8MP_1P33A

0%
Низкий
29 дней назад
github логотип
GHSA-4c88-2h2m-gjmm

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix smatch static checker warning adev->gfx.imu.funcs could be NULL

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4c87-xqpv-r7h5

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-4c87-gg2q-fc6m

Malicious Package in rc-calendar-jhorst

около 6 лет назад
github логотип
GHSA-4c87-9xq5-5c35

Content-Security-Policy protection for user content disabled by Jenkins ZAP Pipeline Plugin

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c87-7rj9-cwg4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalprocessing Nomupay Payment Processing Gateway allows Reflected XSS. This issue affects Nomupay Payment Processing Gateway: from n/a through 7.1.6.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4c85-w99g-9v4w

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-4c85-h2g3-r272

Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4c84-c2x6-wwjv

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring GeoJSON settings. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in versions 3.8.17, 3.9.12, 3.10.9, 3.11.7, and 3.12.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 9.1
2%
Низкий
больше 2 лет назад
github логотип
GHSA-4c84-63pp-c7rv

Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. Attackers can craft a username with a payload containing 4059 bytes of padding followed by a nseh value and seh pointer to trigger the overflow when adding a new user account.

CVSS3: 8.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-4c83-m6v2-mvrm

Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c82-32w7-vxc8

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

CVSS3: 9
0%
Низкий
17 дней назад
github логотип
GHSA-4c7x-8f5j-c5c8

An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7w-p94r-xj6r

SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of service via 100% CPU utilization. Restart of the application is required.

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7w-4j3f-pff5

Vulnerability in the Java SE product of Oracle Java SE (component: JavaFX). The supported version that is affected is Java SE: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVSS3: 5.9
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу