Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjpj-3mr7-gcpf

5 месяцев назад

Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xjph-r444-9j84

около 2 лет назад

Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xjph-mj93-g3gw

около 4 лет назад

The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line.

EPSS: Низкий
github логотип

GHSA-xjpg-r9jg-hhhf

26 дней назад

In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait Fix two cases where pdsc_devcmd_wait() returns stale success from the completion register instead of an error: 1. FW crash: If firmware stops running, the wait loop breaks early with running=false. The condition "if ((!done || timeout) && running)" is false, so error handling is bypassed and stale status is returned. Check !running first and return -ENXIO. 2. Timeout: If a command times out, err is set to -ETIMEDOUT but then overwritten by pdsc_err_to_errno(status) which reads stale status. Return -ETIMEDOUT immediately after cleaning up. Both errors now propagate to pdsc_devcmd_locked() which queues health_work for recovery.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjpf-mwm5-w4cr

6 месяцев назад

A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjpc-m35x-gfvr

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xjpc-56ff-89r7

больше 4 лет назад

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-xjpc-3v7h-498j

больше 4 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the HDMI video driver function hdmi_edid_sysfs_rda_res_info(), userspace can perform an arbitrary write into kernel memory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjp9-7hx4-8rwc

почти 3 года назад

Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjp8-j4mm-q4h6

24 дня назад

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xjp8-93c2-7gxm

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xjp7-q8q7-c6x4

больше 4 лет назад

PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests.

EPSS: Низкий
github логотип

GHSA-xjp6-jcwj-9qp5

около 4 лет назад

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AD_DDL.

EPSS: Низкий
github логотип

GHSA-xjp5-p9r4-x8c7

12 месяцев назад

A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET request.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xjp5-m6c5-6c7w

больше 3 лет назад

onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xjp5-gg6j-cwrg

больше 4 лет назад

The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.

EPSS: Низкий
github логотип

GHSA-xjp5-5ph6-c66c

почти 4 года назад

Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjp4-wv35-98vj

больше 1 года назад

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.

EPSS: Низкий
github логотип

GHSA-xjp4-hw94-mvp5

больше 2 лет назад

Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjp4-6w75-qrj7

больше 4 лет назад

Remote CLI Command Execution Vulnerability in CodeIgniter4

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjpj-3mr7-gcpf

Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

CVSS3: 8.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-xjph-r444-9j84

Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.

CVSS3: 4.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xjph-mj93-g3gw

The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xjpg-r9jg-hhhf

In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait Fix two cases where pdsc_devcmd_wait() returns stale success from the completion register instead of an error: 1. FW crash: If firmware stops running, the wait loop breaks early with running=false. The condition "if ((!done || timeout) && running)" is false, so error handling is bypassed and stale status is returned. Check !running first and return -ENXIO. 2. Timeout: If a command times out, err is set to -ETIMEDOUT but then overwritten by pdsc_err_to_errno(status) which reads stale status. Return -ETIMEDOUT immediately after cleaning up. Both errors now propagate to pdsc_devcmd_locked() which queues health_work for recovery.

CVSS3: 7.5
0%
Низкий
26 дней назад
github логотип
GHSA-xjpf-mwm5-w4cr

A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xjpc-m35x-gfvr

Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjpc-56ff-89r7

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."

18%
Средний
больше 4 лет назад
github логотип
GHSA-xjpc-3v7h-498j

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the HDMI video driver function hdmi_edid_sysfs_rda_res_info(), userspace can perform an arbitrary write into kernel memory.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xjp9-7hx4-8rwc

Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xjp8-j4mm-q4h6

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.

CVSS3: 7.1
0%
Низкий
24 дня назад
github логотип
GHSA-xjp8-93c2-7gxm

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-xjp7-q8q7-c6x4

PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjp6-jcwj-9qp5

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AD_DDL.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjp5-p9r4-x8c7

A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET request.

CVSS3: 5.3
2%
Низкий
12 месяцев назад
github логотип
GHSA-xjp5-m6c5-6c7w

onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xjp5-gg6j-cwrg

The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjp5-5ph6-c66c

Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xjp4-wv35-98vj

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.

0%
Низкий
больше 1 года назад
github логотип
GHSA-xjp4-hw94-mvp5

Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()

CVSS3: 6.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-xjp4-6w75-qrj7

Remote CLI Command Execution Vulnerability in CodeIgniter4

CVSS3: 9.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу