Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 287 888

Количество 287 888

github логотип

GHSA-xxp2-cp36-7xm7

около 3 лет назад

Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.

EPSS: Низкий
github логотип

GHSA-xxp2-9c9g-7wmj

больше 1 года назад

XWiki Platform: Remote code execution from edit in multilingual wikis via translations

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-xxmw-m6v2-9h47

больше 1 года назад

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxmv-v72m-r6w4

больше 3 лет назад

The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.

EPSS: Низкий
github логотип

GHSA-xxmv-mjx9-wg53

около 3 лет назад

Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.

EPSS: Низкий
github логотип

GHSA-xxmr-5pw7-p42v

больше 3 лет назад

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.

EPSS: Низкий
github логотип

GHSA-xxmr-593v-8f45

больше 2 лет назад

In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxmq-q3f3-wvpg

около 3 лет назад

A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product.

EPSS: Низкий
github логотип

GHSA-xxmq-pq4f-q6mv

около 3 лет назад

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a file. An attacker can leverage this vulnerability to expose sensitive information. Was ZDI-CAN-4750.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxmq-p542-3257

около 3 лет назад

Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xxmq-4vph-956w

больше 2 лет назад

Comrak vulnerable to production of excessive output when parsing Markdown (GHSL-2023-048)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxmp-4c36-6f47

около 3 лет назад

Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5398.

EPSS: Низкий
github логотип

GHSA-xxmm-cxv2-23w9

больше 3 лет назад

Memory leak in Juniper JUNOS Packet Forwarding Engine (PFE) allows remote attackers to cause a denial of service (memory exhaustion and device reboot) via certain IPv6 packets.

EPSS: Низкий
github логотип

GHSA-xxmm-334r-gmx7

около 3 лет назад

Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5.50.10 before 10.5-52.11, 10.1.122.17 before 10.1-129.11, and 10.1-120.1316.e before 10.1-129.1105.e, when using unspecified configurations, allows remote authenticated users to access "network resources" of other users via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xxmj-xf3c-rjq4

около 3 лет назад

An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query. This can be exploited by malicious users to, e.g., read sensitive data from the database through in-band SQL Injection attacks. Successful exploitation of this vulnerability requires the Live Chat plugin to be enabled.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxmj-r9ph-qg7w

около 3 лет назад

Cross-site scripting (XSS) vulnerability in guide-park.com BBS X102 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xxmj-qmq4-g4j9

11 месяцев назад

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iprofileidx parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxmj-j4pj-fx22

почти 3 года назад

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxmj-hwq5-5h3j

около 3 лет назад

Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxmj-957m-hg64

больше 3 лет назад

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not check the Fully Qualified Domain Name (FQDN) during a "Validate Repository SSL Certificate" scan, which has unknown impact and attack vectors, possibly related to spoofed certificates.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxp2-cp36-7xm7

Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxp2-9c9g-7wmj

XWiki Platform: Remote code execution from edit in multilingual wikis via translations

CVSS3: 9.9
30%
Средний
больше 1 года назад
github логотип
GHSA-xxmw-m6v2-9h47

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxmv-v72m-r6w4

The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xxmv-mjx9-wg53

Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxmr-5pw7-p42v

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxmr-593v-8f45

In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxmq-q3f3-wvpg

A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxmq-pq4f-q6mv

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a file. An attacker can leverage this vulnerability to expose sensitive information. Was ZDI-CAN-4750.

CVSS3: 7.5
5%
Низкий
около 3 лет назад
github логотип
GHSA-xxmq-p542-3257

Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.

1%
Низкий
около 3 лет назад
github логотип
GHSA-xxmq-4vph-956w

Comrak vulnerable to production of excessive output when parsing Markdown (GHSL-2023-048)

CVSS3: 5.3
больше 2 лет назад
github логотип
GHSA-xxmp-4c36-6f47

Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5398.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxmm-cxv2-23w9

Memory leak in Juniper JUNOS Packet Forwarding Engine (PFE) allows remote attackers to cause a denial of service (memory exhaustion and device reboot) via certain IPv6 packets.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxmm-334r-gmx7

Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5.50.10 before 10.5-52.11, 10.1.122.17 before 10.1-129.11, and 10.1-120.1316.e before 10.1-129.1105.e, when using unspecified configurations, allows remote authenticated users to access "network resources" of other users via unknown vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxmj-xf3c-rjq4

An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query. This can be exploited by malicious users to, e.g., read sensitive data from the database through in-band SQL Injection attacks. Successful exploitation of this vulnerability requires the Live Chat plugin to be enabled.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxmj-r9ph-qg7w

Cross-site scripting (XSS) vulnerability in guide-park.com BBS X102 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxmj-qmq4-g4j9

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iprofileidx parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxmj-j4pj-fx22

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxmj-hwq5-5h3j

Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxmj-957m-hg64

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not check the Fully Qualified Domain Name (FQDN) during a "Validate Repository SSL Certificate" scan, which has unknown impact and attack vectors, possibly related to spoofed certificates.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу