Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2994-cf23-4hmp

около 4 лет назад

Mingw-w64 version 5.0.3 and earlier, 5.0.4, 6.0.0 and 7.0.0 contains an Improper Null Termination (CWE-170) vulnerability in mingw-w64-crt (libc)->(v)snprintf that can result in The bug may be used to corrupt subsequent string functions. This attack appear to be exploitable via Depending on the usage, worst case: network.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2993-5qvm-pg7x

около 4 лет назад

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2992-vffv-8399

около 4 лет назад

The Inmobi library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2992-6547-hhfp

около 4 лет назад

In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.

EPSS: Низкий
github логотип

GHSA-2992-3j6w-22hh

почти 3 года назад

Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-298w-pg84-p7jw

больше 1 года назад

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to leverage them to perform unauthorized actions.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-298v-qmqm-hfrx

6 месяцев назад

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of github-kanban-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the create_issue parameter. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-27784.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-298v-7gc3-86vj

около 4 лет назад

UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-298r-5c48-7q2r

больше 3 лет назад

Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-298q-wv2h-v5vw

около 4 лет назад

Magento 2 Community Edition XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-298q-w9qh-3r99

больше 2 лет назад

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-298q-cxp8-5c9m

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-298p-q946-hhq4

больше 4 лет назад

Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.

EPSS: Низкий
github логотип

GHSA-298p-mmc8-j4x9

почти 2 года назад

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-298m-hvgh-x9cw

около 3 лет назад

Alluxio Cross Site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-298j-vh9r-mc78

около 1 месяца назад

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-298j-cm7q-56g9

около 4 лет назад

An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-298j-9q4w-6rm4

около 4 лет назад

Agent-to-controller security bypass in Jenkins xUnit Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-298h-vfc8-fcfc

больше 1 года назад

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-298h-373h-w6rq

больше 3 лет назад

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mighty Digital Nooz plugin <= 1.6.0 versions.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2994-cf23-4hmp

Mingw-w64 version 5.0.3 and earlier, 5.0.4, 6.0.0 and 7.0.0 contains an Improper Null Termination (CWE-170) vulnerability in mingw-w64-crt (libc)->(v)snprintf that can result in The bug may be used to corrupt subsequent string functions. This attack appear to be exploitable via Depending on the usage, worst case: network.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2993-5qvm-pg7x

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2992-vffv-8399

The Inmobi library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2992-6547-hhfp

In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2992-3j6w-22hh

Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-298w-pg84-p7jw

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to leverage them to perform unauthorized actions.

CVSS3: 9.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-298v-qmqm-hfrx

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of github-kanban-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the create_issue parameter. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-27784.

CVSS3: 9.8
2%
Низкий
6 месяцев назад
github логотип
GHSA-298v-7gc3-86vj

UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-298r-5c48-7q2r

Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion

CVSS3: 8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-298q-wv2h-v5vw

Magento 2 Community Edition XSS Vulnerability

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-298q-w9qh-3r99

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-298q-cxp8-5c9m

Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-298p-q946-hhq4

Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-298p-mmc8-j4x9

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.1
6%
Низкий
почти 2 года назад
github логотип
GHSA-298m-hvgh-x9cw

Alluxio Cross Site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-298j-vh9r-mc78

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-298j-cm7q-56g9

An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-298j-9q4w-6rm4

Agent-to-controller security bypass in Jenkins xUnit Plugin

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-298h-vfc8-fcfc

IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-298h-373h-w6rq

Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mighty Digital Nooz plugin <= 1.6.0 versions.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу