Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-xqfj-35wv-m3cr

почти 5 лет назад

Null pointer dereference in `StringNGrams`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-xqfh-gx6q-m574

около 2 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xqfg-p7f2-6w5f

больше 2 лет назад

An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqff-x4hf-x674

почти 4 года назад

Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.

EPSS: Низкий
github логотип

GHSA-xqff-gxc3-2x4v

около 2 лет назад

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xqfc-fqm7-gx4x

почти 4 года назад

A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqfc-cx8v-9v3h

почти 4 года назад

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0675.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-xqfc-ch67-qwvg

больше 2 лет назад

In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqf9-v7ff-rf4x

почти 4 года назад

Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.

EPSS: Низкий
github логотип

GHSA-xqf9-qrgq-fxfv

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still process packets without rfc1042 headers.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xqf9-q644-qr8q

почти 4 года назад

HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.

EPSS: Низкий
github логотип

GHSA-xqf7-wh6f-f6jh

больше 1 года назад

The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xqf7-frvw-5523

больше 3 лет назад

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqf6-p37p-9cxg

почти 4 года назад

A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqf6-m6vx-v7jx

почти 4 года назад

Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqf6-9hf7-323f

5 месяцев назад

An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful exploitation may result in account takeover via password reset or other authentication bypass methods.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqf6-5grh-6223

почти 4 года назад

Passwords transmitted in plain text by Jenkins Artifactory Plugin

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xqf5-6fm4-qwhv

почти 4 года назад

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.

EPSS: Низкий
github логотип

GHSA-xqf3-q69c-jc7c

больше 1 года назад

Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xqf3-q2jh-qp3h

около 3 лет назад

Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqfj-35wv-m3cr

Null pointer dereference in `StringNGrams`

CVSS3: 2.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-xqfh-gx6q-m574

Rejected reason: Not used

около 2 месяцев назад
github логотип
GHSA-xqfg-p7f2-6w5f

An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqff-x4hf-x674

Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqff-gxc3-2x4v

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xqfc-fqm7-gx4x

A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqfc-cx8v-9v3h

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0671, CVE-2019-0672, CVE-2019-0673, CVE-2019-0675.

CVSS3: 7.8
30%
Средний
почти 4 года назад
github логотип
GHSA-xqfc-ch67-qwvg

In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqf9-v7ff-rf4x

Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqf9-qrgq-fxfv

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to access the rfc1042 headers when the buffer is too small, so the driver can still process packets without rfc1042 headers.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xqf9-q644-qr8q

HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqf7-wh6f-f6jh

The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqf7-frvw-5523

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xqf6-p37p-9cxg

A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqf6-m6vx-v7jx

Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqf6-9hf7-323f

An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful exploitation may result in account takeover via password reset or other authentication bypass methods.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xqf6-5grh-6223

Passwords transmitted in plain text by Jenkins Artifactory Plugin

CVSS3: 3.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqf5-6fm4-qwhv

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqf3-q69c-jc7c

Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqf3-q2jh-qp3h

Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу