Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 528

Количество 373 528

github логотип

GHSA-xxxf-qw8j-6rfv

больше 4 лет назад

Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxxf-8fjp-59qv

больше 4 лет назад

An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.

EPSS: Низкий
github логотип

GHSA-xxxc-p928-96mq

10 месяцев назад

Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 2.2
EPSS: Низкий
github логотип

GHSA-xxxc-2fjg-mprw

больше 1 года назад

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxx9-8q88-3qrf

почти 3 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: from n/a through 3.1.40.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxx9-446j-m3xj

больше 4 лет назад

Unspecified vulnerability in Kismet before 2005-08-R1 allows remote attackers to have an unknown impact via unprintable characters in the SSID.

EPSS: Низкий
github логотип

GHSA-xxx9-3xcr-gjj3

больше 4 лет назад

XML Injection in Xerces Java affects Nokogiri

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxx8-w7mj-hmgq

больше 4 лет назад

hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxx7-j74c-5xrg

6 месяцев назад

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxx6-g6jv-xq96

3 месяца назад

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may result in the disclosure of process memory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxx6-f4cg-v662

почти 4 года назад

Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxx5-wj7r-x3hv

больше 4 лет назад

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xxx5-7c7q-rc45

почти 3 года назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxx4-cx36-38r5

больше 4 лет назад

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxx4-63qf-8v87

около 4 лет назад

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xxx4-4fcv-w56c

больше 4 лет назад

The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) via a crafted application, aka a "semaphore deadlock issue."

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxx3-q2f4-59h7

больше 4 лет назад

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

EPSS: Низкий
github логотип

GHSA-xxx3-p74m-7mjp

11 месяцев назад

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxx3-74w7-m595

9 дней назад

Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxx2-77cj-f65h

больше 4 лет назад

Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxxf-qw8j-6rfv

Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxxf-8fjp-59qv

An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xxxc-p928-96mq

Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 2.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-xxxc-2fjg-mprw

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxx9-8q88-3qrf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: from n/a through 3.1.40.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxx9-446j-m3xj

Unspecified vulnerability in Kismet before 2005-08-R1 allows remote attackers to have an unknown impact via unprintable characters in the SSID.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xxx9-3xcr-gjj3

XML Injection in Xerces Java affects Nokogiri

CVSS3: 6.5
больше 4 лет назад
github логотип
GHSA-xxx8-w7mj-hmgq

hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxx7-j74c-5xrg

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xxx6-g6jv-xq96

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may result in the disclosure of process memory.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xxx6-f4cg-v662

Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxx5-wj7r-x3hv

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
56%
Средний
больше 4 лет назад
github логотип
GHSA-xxx5-7c7q-rc45

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-xxx4-cx36-38r5

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxx4-63qf-8v87

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxx4-4fcv-w56c

The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) via a crafted application, aka a "semaphore deadlock issue."

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxx3-q2f4-59h7

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxx3-p74m-7mjp

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxx3-74w7-m595

Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
9 дней назад
github логотип
GHSA-xxx2-77cj-f65h

Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу