Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 903

Количество 325 903

github логотип

GHSA-xpp7-7rw8-qmff

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpp7-7jm5-hh44

почти 4 года назад

Sunbelt VIPRE 3.1.1832.2 and possibly 3.1.1633.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

EPSS: Низкий
github логотип

GHSA-xpp7-3x3w-4w29

6 месяцев назад

An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-xpp6-cqwc-x7wh

почти 4 года назад

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

EPSS: Низкий
github логотип

GHSA-xpp6-cm2v-hmmg

почти 4 года назад

The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

EPSS: Низкий
github логотип

GHSA-xpp6-8r3j-ww43

почти 2 года назад

Undertow Denial of Service vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpp5-m7fr-wp25

11 месяцев назад

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xpp4-mh2g-6345

11 месяцев назад

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpp4-hqcj-ch86

почти 4 года назад

lastfm 1.5.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

EPSS: Низкий
github логотип

GHSA-xpp4-g7jq-f7cv

почти 4 года назад

SQL injection vulnerability in the CleanDB - DBAL (tmsw_cleandb) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xpp4-g6wp-qmp7

больше 2 лет назад

A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the component Utility Download Handler. The manipulation of the argument lang with the input 1%27"()%26%25<zzz><ScRiPt>alert(document.domain)</ScRiPt> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249759. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpp3-xrff-w6rh

больше 3 лет назад

rocksdb vulnerable to out-of-bounds read

EPSS: Низкий
github логотип

GHSA-xpp2-rw22-gf34

больше 3 лет назад

An issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks check of the return value of kmalloc() and will cause the null pointer dereference.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpp2-c63f-x3v5

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Logan Carlile Easy Page Transition allows Stored XSS. This issue affects Easy Page Transition: from n/a through 1.0.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xpmx-h7xq-xffh

больше 5 лет назад

Potential access control security issue in apollo-adminservice

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xpmv-w84f-hm92

около 3 лет назад

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpmv-q85x-8hh8

почти 4 года назад

On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the IP address belonging to the victim's host, an attacker might be able to take over the administrative session without being prompted for authentication credentials. An attacker can get the victim's and router's IP addresses by simply sniffing the network traffic. Moreover, if the victim has web access enabled on his router and is accessing the web interface from a different network that is behind the NAT/Proxy, an attacker can sniff the network traffic to know the public IP address of the victim's router and take over his session as he won't be prompted for credentials.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpmv-55r3-vww6

почти 4 года назад

frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability.

EPSS: Низкий
github логотип

GHSA-xpmr-c35p-q4rw

больше 1 года назад

home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An arbitrary OS command may be executed with the root privilege by an administrative user.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xpmr-2g2m-g7vw

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix notifier list entry init struct v4l2_async_notifier has several list_head members, but only waiting_list and done_list are initialized. notifier_entry was kept 'zeroed' leading to an uninitialized list_head. This results in a NULL-pointer dereference if csi2_async_register() fails, e.g. node for remote endpoint is disabled, and returns -ENOTCONN. The following calls to v4l2_async_nf_unregister() results in a NULL pointer dereference. Add the missing list head initializer.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpp7-7rw8-qmff

Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpp7-7jm5-hh44

Sunbelt VIPRE 3.1.1832.2 and possibly 3.1.1633.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpp7-3x3w-4w29

An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames.

CVSS3: 6.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-xpp6-cqwc-x7wh

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpp6-cm2v-hmmg

The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xpp6-8r3j-ww43

Undertow Denial of Service vulnerability

CVSS3: 7.5
4%
Низкий
почти 2 года назад
github логотип
GHSA-xpp5-m7fr-wp25

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

CVSS3: 9.1
3%
Низкий
11 месяцев назад
github логотип
GHSA-xpp4-mh2g-6345

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xpp4-hqcj-ch86

lastfm 1.5.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpp4-g7jq-f7cv

SQL injection vulnerability in the CleanDB - DBAL (tmsw_cleandb) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpp4-g6wp-qmp7

A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the component Utility Download Handler. The manipulation of the argument lang with the input 1%27"()%26%25<zzz><ScRiPt>alert(document.domain)</ScRiPt> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249759. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpp3-xrff-w6rh

rocksdb vulnerable to out-of-bounds read

больше 3 лет назад
github логотип
GHSA-xpp2-rw22-gf34

An issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks check of the return value of kmalloc() and will cause the null pointer dereference.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xpp2-c63f-x3v5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Logan Carlile Easy Page Transition allows Stored XSS. This issue affects Easy Page Transition: from n/a through 1.0.1.

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-xpmx-h7xq-xffh

Potential access control security issue in apollo-adminservice

CVSS3: 7
0%
Низкий
больше 5 лет назад
github логотип
GHSA-xpmv-w84f-hm92

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xpmv-q85x-8hh8

On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the IP address belonging to the victim's host, an attacker might be able to take over the administrative session without being prompted for authentication credentials. An attacker can get the victim's and router's IP addresses by simply sniffing the network traffic. Moreover, if the victim has web access enabled on his router and is accessing the web interface from a different network that is behind the NAT/Proxy, an attacker can sniff the network traffic to know the public IP address of the victim's router and take over his session as he won't be prompted for credentials.

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-xpmv-55r3-vww6

frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpmr-c35p-q4rw

home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An arbitrary OS command may be executed with the root privilege by an administrative user.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpmr-2g2m-g7vw

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix notifier list entry init struct v4l2_async_notifier has several list_head members, but only waiting_list and done_list are initialized. notifier_entry was kept 'zeroed' leading to an uninitialized list_head. This results in a NULL-pointer dereference if csi2_async_register() fails, e.g. node for remote endpoint is disabled, and returns -ENOTCONN. The following calls to v4l2_async_nf_unregister() results in a NULL pointer dereference. Add the missing list head initializer.

CVSS3: 5.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу