Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 279

Количество 323 279

github логотип

GHSA-xx2v-j2rm-5c42

больше 2 лет назад

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx2r-xrgj-fm3f

около 2 лет назад

The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx2r-x7vm-xjjj

почти 4 года назад

A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx2r-f4xg-6rg7

почти 3 года назад

Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx2r-34w4-h84r

почти 4 года назад

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."

EPSS: Средний
github логотип

GHSA-xx2r-2w7h-qwpc

почти 2 года назад

Microsoft Defender for IoT Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xx2q-wc64-gcw2

12 месяцев назад

Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts allows Upload a Web Shell to a Web Server. This issue affects Sync Posts: from n/a through 1.0.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xx2q-9jcq-97m8

почти 4 года назад

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

EPSS: Низкий
github логотип

GHSA-xx2q-9cgc-6xvc

почти 4 года назад

The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xx2q-52g7-vmx5

почти 4 года назад

Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xx2p-7x2v-j239

почти 4 года назад

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xx2p-5w38-cw49

почти 4 года назад

The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.

EPSS: Низкий
github логотип

GHSA-xx2p-3xq8-p2xm

почти 4 года назад

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.

EPSS: Низкий
github логотип

GHSA-xx2h-vg66-mpr3

почти 4 года назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901, CVE-2019-0902.

EPSS: Средний
github логотип

GHSA-xx2h-qwcv-vv5w

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: arm64/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array was used outside of its scope.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx2h-39g7-5x2c

почти 4 года назад

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

EPSS: Средний
github логотип

GHSA-xx2h-2hf5-v7vv

почти 4 года назад

Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xx2g-w5xg-2w3f

больше 3 лет назад

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-xx2g-p975-mwgc

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IRQ worker is running, unplugging the device would cause a crash. The sealevel hardware this driver was written for was not hotpluggable, so I never realized it. This change uses a spinlock to protect a list of workers, which it tears down on disconnect.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx2f-m35m-cqwx

почти 4 года назад

In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9Android ID: A-172322502

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx2v-j2rm-5c42

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx2r-xrgj-fm3f

The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xx2r-x7vm-xjjj

A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xx2r-f4xg-6rg7

Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.

CVSS3: 7.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xx2r-34w4-h84r

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."

11%
Средний
почти 4 года назад
github логотип
GHSA-xx2r-2w7h-qwpc

Microsoft Defender for IoT Remote Code Execution Vulnerability

CVSS3: 8.8
10%
Средний
почти 2 года назад
github логотип
GHSA-xx2q-wc64-gcw2

Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts allows Upload a Web Shell to a Web Server. This issue affects Sync Posts: from n/a through 1.0.

CVSS3: 9.9
0%
Низкий
12 месяцев назад
github логотип
GHSA-xx2q-9jcq-97m8

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xx2q-9cgc-6xvc

The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.

CVSS3: 6
0%
Низкий
почти 4 года назад
github логотип
GHSA-xx2q-52g7-vmx5

Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx2p-7x2v-j239

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.

10%
Низкий
почти 4 года назад
github логотип
GHSA-xx2p-5w38-cw49

The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx2p-3xq8-p2xm

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.

9%
Низкий
почти 4 года назад
github логотип
GHSA-xx2h-vg66-mpr3

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901, CVE-2019-0902.

28%
Средний
почти 4 года назад
github логотип
GHSA-xx2h-qwcv-vv5w

In the Linux kernel, the following vulnerability has been resolved: arm64/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array was used outside of its scope.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xx2h-39g7-5x2c

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

35%
Средний
почти 4 года назад
github логотип
GHSA-xx2h-2hf5-v7vv

Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password

CVSS3: 5.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-xx2g-w5xg-2w3f

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

CVSS3: 6.1
48%
Средний
больше 3 лет назад
github логотип
GHSA-xx2g-p975-mwgc

In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IRQ worker is running, unplugging the device would cause a crash. The sealevel hardware this driver was written for was not hotpluggable, so I never realized it. This change uses a spinlock to protect a list of workers, which it tears down on disconnect.

CVSS3: 5.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xx2f-m35m-cqwx

In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9Android ID: A-172322502

CVSS3: 7.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу