Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 632

Количество 325 632

github логотип

GHSA-xq2q-96g9-r4pc

почти 4 года назад

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xq2q-8hxc-7jr2

почти 4 года назад

XXE vulnerability in Jenkins Valgrind Plugin

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xq2p-cgwj-87m3

почти 4 года назад

Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.

EPSS: Низкий
github логотип

GHSA-xq2p-83g5-rqxp

2 месяца назад

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq2m-jgm3-gpjw

почти 4 года назад

Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

EPSS: Средний
github логотип

GHSA-xq2m-h4jc-ghmf

2 месяца назад

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq2m-9f8c-rr6w

почти 4 года назад

LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.

EPSS: Низкий
github логотип

GHSA-xq2j-fg32-wv9c

почти 4 года назад

A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq2j-2jwj-gfcq

около 1 года назад

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq2h-vm9v-fgph

около 2 лет назад

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xq2h-p299-vjwv

около 1 месяца назад

Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade

EPSS: Низкий
github логотип

GHSA-xq2h-7fp3-456v

около 1 года назад

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xq2h-74x7-89f4

почти 4 года назад

Windows DNS Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq2g-qh2c-29p8

5 месяцев назад

Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xq2g-73fq-x4mq

7 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS. This issue affects Purge Varnish Cache: from n/a through 2.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xq2f-wc3r-4q96

почти 4 года назад

Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.

EPSS: Низкий
github логотип

GHSA-xq2f-h2vw-352p

почти 4 года назад

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq2f-f4gq-58p8

10 месяцев назад

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xq2c-xc9f-44f4

почти 4 года назад

SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

EPSS: Низкий
github логотип

GHSA-xq29-jcj7-xg86

почти 4 года назад

Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq2q-96g9-r4pc

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.

CVSS3: 9.8
20%
Средний
почти 4 года назад
github логотип
GHSA-xq2q-8hxc-7jr2

XXE vulnerability in Jenkins Valgrind Plugin

CVSS3: 7.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq2p-cgwj-87m3

Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.

10%
Низкий
почти 4 года назад
github логотип
GHSA-xq2p-83g5-rqxp

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.

CVSS3: 9.8
0%
Низкий
2 месяца назад
github логотип
GHSA-xq2m-jgm3-gpjw

Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

54%
Средний
почти 4 года назад
github логотип
GHSA-xq2m-h4jc-ghmf

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xq2m-9f8c-rr6w

LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq2j-fg32-wv9c

A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xq2j-2jwj-gfcq

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.

CVSS3: 9.8
2%
Низкий
около 1 года назад
github логотип
GHSA-xq2h-vm9v-fgph

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xq2h-p299-vjwv

Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade

0%
Низкий
около 1 месяца назад
github логотип
GHSA-xq2h-7fp3-456v

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xq2h-74x7-89f4

Windows DNS Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq2g-qh2c-29p8

Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 3.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xq2g-73fq-x4mq

Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS. This issue affects Purge Varnish Cache: from n/a through 2.6.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-xq2f-wc3r-4q96

Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xq2f-h2vw-352p

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq2f-f4gq-58p8

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-xq2c-xc9f-44f4

SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq29-jcj7-xg86

Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands

1%
Низкий
почти 4 года назад

Уязвимостей на страницу