Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 571

Количество 323 571

github логотип

GHSA-xq2m-jgm3-gpjw

почти 4 года назад

Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

EPSS: Средний
github логотип

GHSA-xq2m-h4jc-ghmf

2 месяца назад

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq2m-9f8c-rr6w

почти 4 года назад

LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.

EPSS: Низкий
github логотип

GHSA-xq2j-fg32-wv9c

почти 4 года назад

A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq2j-2jwj-gfcq

около 1 года назад

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq2h-vm9v-fgph

около 2 лет назад

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xq2h-p299-vjwv

около 1 месяца назад

Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade

EPSS: Низкий
github логотип

GHSA-xq2h-7fp3-456v

около 1 года назад

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xq2h-74x7-89f4

почти 4 года назад

Windows DNS Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq2g-qh2c-29p8

5 месяцев назад

Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xq2g-73fq-x4mq

7 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS. This issue affects Purge Varnish Cache: from n/a through 2.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xq2f-wc3r-4q96

почти 4 года назад

Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.

EPSS: Низкий
github логотип

GHSA-xq2f-h2vw-352p

почти 4 года назад

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq2f-f4gq-58p8

10 месяцев назад

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xq2c-xc9f-44f4

почти 4 года назад

SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

EPSS: Низкий
github логотип

GHSA-xq29-jcj7-xg86

почти 4 года назад

Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands

EPSS: Низкий
github логотип

GHSA-xq29-76j5-j268

8 месяцев назад

A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipulation of the argument emailid leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xq29-5vxx-327w

почти 4 года назад

The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a vulnerability that theoretically enables a user to spoof their account to look like a different user in the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xq28-w75v-29rr

почти 4 года назад

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1024.

EPSS: Средний
github логотип

GHSA-xq28-26p4-h63h

больше 2 лет назад

In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq2m-jgm3-gpjw

Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

54%
Средний
почти 4 года назад
github логотип
GHSA-xq2m-h4jc-ghmf

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xq2m-9f8c-rr6w

LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq2j-fg32-wv9c

A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xq2j-2jwj-gfcq

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.

CVSS3: 9.8
2%
Низкий
около 1 года назад
github логотип
GHSA-xq2h-vm9v-fgph

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xq2h-p299-vjwv

Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade

0%
Низкий
около 1 месяца назад
github логотип
GHSA-xq2h-7fp3-456v

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xq2h-74x7-89f4

Windows DNS Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq2g-qh2c-29p8

Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 3.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xq2g-73fq-x4mq

Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS. This issue affects Purge Varnish Cache: from n/a through 2.6.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-xq2f-wc3r-4q96

Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xq2f-h2vw-352p

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq2f-f4gq-58p8

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-xq2c-xc9f-44f4

SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq29-jcj7-xg86

Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands

1%
Низкий
почти 4 года назад
github логотип
GHSA-xq29-76j5-j268

A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipulation of the argument emailid leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xq29-5vxx-327w

The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a vulnerability that theoretically enables a user to spoof their account to look like a different user in the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq28-w75v-29rr

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1024.

46%
Средний
почти 4 года назад
github логотип
GHSA-xq28-26p4-h63h

In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу