Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2p66-jqj6-xc58

около 1 месяца назад

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2p66-4rg2-ppg3

больше 4 лет назад

Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2p66-4gvq-xrrq

больше 4 лет назад

Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long IRC message.

EPSS: Низкий
github логотип

GHSA-2p66-2g75-qw5g

больше 2 лет назад

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_uri_editor' function in all versions up to, and including, 2.4.3.1. This makes it possible for unauthenticated attackers to view the permalinks of all posts.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2p65-4wj7-rfxw

7 месяцев назад

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

EPSS: Низкий
github логотип

GHSA-2p64-mr93-v76g

больше 4 лет назад

Dino's Webserver 1.2 allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via several large HTTP requests within a short time.

EPSS: Низкий
github логотип

GHSA-2p64-hc8v-gh2f

больше 4 лет назад

Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash) via a long URI value (aka url) in the Cascading Style Sheets (CSS) background property.

EPSS: Низкий
github логотип

GHSA-2p63-m9x5-p5cm

почти 4 года назад

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2p63-m843-cvx8

около 4 лет назад

IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172707.

EPSS: Низкий
github логотип

GHSA-2p62-w27q-9g83

около 4 лет назад

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to create a GitHub App on the instance and have a user authorize the application through the web authentication flow. All permissions being granted would properly be shown during the first authorization, but in certain circumstances, if the user revisits the authorization flow after the GitHub App has configured additional user-level permissions, those additional permissions may not be shown, leading to more permissions being granted than the user potentially intended. This vulnerability affected GitHub Enterprise Server 3.0.x prior to 3.0.7 and 2.22.x prior to 2.22.13. It was fixed in versions 3.0.7 and 2.22.13. This vulnerability was reported via the GitHub Bug Bounty program.

EPSS: Низкий
github логотип

GHSA-2p62-g69r-34gr

больше 2 лет назад

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2p62-c4rm-mr72

почти 6 лет назад

Malicious Package in another-date-picker

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2p5x-6x62-jgxf

около 4 лет назад

The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2p5x-4jr6-x5jg

21 день назад

FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2p5w-vr7w-w9xh

больше 4 лет назад

PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang parameter.

EPSS: Высокий
github логотип

GHSA-2p5w-f38x-fgff

около 2 месяцев назад

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2p5w-cvg5-gc5c

6 месяцев назад

Hibernate vulnerable to SQL Injection

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2p5v-xc8c-c7f4

около 4 лет назад

Directory traversal vulnerability in the PXE Mtftp service in Hitachi JP1/ServerConductor/DeploymentManager before 08-55 Japanese and before 08-51 English allows remote attackers to read arbitrary files via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2p5v-p767-wqv5

8 месяцев назад

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2p5v-755j-54f5

больше 1 года назад

Windows Telephony Service Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2p66-jqj6-xc58

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2p66-4rg2-ppg3

Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2p66-4gvq-xrrq

Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long IRC message.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2p66-2g75-qw5g

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_uri_editor' function in all versions up to, and including, 2.4.3.1. This makes it possible for unauthenticated attackers to view the permalinks of all posts.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2p65-4wj7-rfxw

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

7 месяцев назад
github логотип
GHSA-2p64-mr93-v76g

Dino's Webserver 1.2 allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via several large HTTP requests within a short time.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2p64-hc8v-gh2f

Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash) via a long URI value (aka url) in the Cascading Style Sheets (CSS) background property.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-2p63-m9x5-p5cm

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2p63-m843-cvx8

IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172707.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2p62-w27q-9g83

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to create a GitHub App on the instance and have a user authorize the application through the web authentication flow. All permissions being granted would properly be shown during the first authorization, but in certain circumstances, if the user revisits the authorization flow after the GitHub App has configured additional user-level permissions, those additional permissions may not be shown, leading to more permissions being granted than the user potentially intended. This vulnerability affected GitHub Enterprise Server 3.0.x prior to 3.0.7 and 2.22.x prior to 2.22.13. It was fixed in versions 3.0.7 and 2.22.13. This vulnerability was reported via the GitHub Bug Bounty program.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2p62-g69r-34gr

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2p62-c4rm-mr72

Malicious Package in another-date-picker

CVSS3: 9.8
почти 6 лет назад
github логотип
GHSA-2p5x-6x62-jgxf

The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2p5x-4jr6-x5jg

FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export

CVSS3: 8
21 день назад
github логотип
GHSA-2p5w-vr7w-w9xh

PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_lang parameter.

71%
Высокий
больше 4 лет назад
github логотип
GHSA-2p5w-f38x-fgff

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-2p5w-cvg5-gc5c

Hibernate vulnerable to SQL Injection

CVSS3: 8.3
1%
Низкий
6 месяцев назад
github логотип
GHSA-2p5v-xc8c-c7f4

Directory traversal vulnerability in the PXE Mtftp service in Hitachi JP1/ServerConductor/DeploymentManager before 08-55 Japanese and before 08-51 English allows remote attackers to read arbitrary files via unknown vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2p5v-p767-wqv5

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.

CVSS3: 6.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-2p5v-755j-54f5

Windows Telephony Service Remote Code Execution Vulnerability

CVSS3: 8.8
1%
Низкий
больше 1 года назад

Уязвимостей на страницу