Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-xp29-pwxq-2c4v

почти 4 года назад

The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh) package before 3.3.3, stores the history database password in cleartext, which allows local users to obtain sensitive information by reading an unspecified file.

EPSS: Низкий
github логотип

GHSA-xp29-g429-j593

почти 4 года назад

Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.

EPSS: Низкий
github логотип

GHSA-xp29-43pm-7r9g

около 2 месяцев назад

The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue arbitrary commands to devices.

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-xp28-88f3-2f49

больше 1 года назад

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp28-3fv9-33c6

около 2 лет назад

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp27-mhxx-q8mf

почти 4 года назад

A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13; PAN-OS 9.0 versions earlier than PAN-OS 9.0.7.

EPSS: Низкий
github логотип

GHSA-xp27-gwqx-8qx4

больше 2 лет назад

Auth. (contributo+) Stored Cross-Site Scripting (XSS) vulnerability in Cytech BuddyMeet plugin <= 2.2.0 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp27-8r9x-g424

больше 1 года назад

ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xp27-622h-2g9p

больше 3 лет назад

In DreamServices, there is a possible way to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-189574230

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp26-p53h-6h2p

почти 4 года назад

Improper Neutralization of Input During Web Page Generation in LXML

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp26-jqrv-cc5r

почти 4 года назад

Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xp26-fwf6-j3gx

почти 4 года назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp23-pr4w-q7fx

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themeqx LetterPress plugin <= 1.1.2 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xp23-94cq-8m5g

11 месяцев назад

A vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications contain an out of bounds read past the end of an allocated buffer while checking the integrity of incoming packets. This could allow an unauthenticated remote attacker to create a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp23-4cw6-346h

почти 4 года назад

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0767, CVE-2019-0782.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xp22-xvph-8m82

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in AcmeeDesign WPShapere Lite allows Stored XSS. This issue affects WPShapere Lite: from n/a through 1.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xmxx-m7q8-x9xj

почти 4 года назад

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.

EPSS: Низкий
github логотип

GHSA-xmxx-8mch-q276

почти 4 года назад

The mintToken function of a smart contract implementation for Bitstarti, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmxx-577p-gqgc

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing mutex lock around get meter levels As scarlett2_meter_ctl_get() uses meter_level_map[], the data_mutex should be locked while accessing it.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xmxw-rhxj-cxcc

почти 4 года назад

The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30259955.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp29-pwxq-2c4v

The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh) package before 3.3.3, stores the history database password in cleartext, which allows local users to obtain sensitive information by reading an unspecified file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp29-g429-j593

Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp29-43pm-7r9g

The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue arbitrary commands to devices.

CVSS3: 9.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xp28-88f3-2f49

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp28-3fv9-33c6

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-xp27-mhxx-q8mf

A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbitrary code with root privileges. This issue affects: All versions of PAN-OS 7.1 and PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.13; PAN-OS 9.0 versions earlier than PAN-OS 9.0.7.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xp27-gwqx-8qx4

Auth. (contributo+) Stored Cross-Site Scripting (XSS) vulnerability in Cytech BuddyMeet plugin <= 2.2.0 versions.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xp27-8r9x-g424

ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp27-622h-2g9p

In DreamServices, there is a possible way to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-189574230

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xp26-p53h-6h2p

Improper Neutralization of Input During Web Page Generation in LXML

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xp26-jqrv-cc5r

Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.

CVSS3: 7.2
2%
Низкий
почти 4 года назад
github логотип
GHSA-xp26-fwf6-j3gx

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xp23-pr4w-q7fx

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themeqx LetterPress plugin <= 1.1.2 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xp23-94cq-8m5g

A vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications contain an out of bounds read past the end of an allocated buffer while checking the integrity of incoming packets. This could allow an unauthenticated remote attacker to create a denial of service condition.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xp23-4cw6-346h

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0767, CVE-2019-0782.

CVSS3: 4.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp22-xvph-8m82

Cross-Site Request Forgery (CSRF) vulnerability in AcmeeDesign WPShapere Lite allows Stored XSS. This issue affects WPShapere Lite: from n/a through 1.4.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-xmxx-m7q8-x9xj

btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xmxx-8mch-q276

The mintToken function of a smart contract implementation for Bitstarti, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xmxx-577p-gqgc

In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing mutex lock around get meter levels As scarlett2_meter_ctl_get() uses meter_level_map[], the data_mutex should be locked while accessing it.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xmxw-rhxj-cxcc

The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30259955.

CVSS3: 5.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу