Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 360

Количество 324 360

github логотип

GHSA-xv65-m527-x787

около 2 лет назад

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xv64-wpfr-x2m3

почти 4 года назад

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xv64-q73j-cvqp

больше 1 года назад

Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22272.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv64-jjpm-mgjv

почти 4 года назад

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

EPSS: Низкий
github логотип

GHSA-xv64-cc6j-5cjp

почти 4 года назад

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.

EPSS: Низкий
github логотип

GHSA-xv64-8p4r-94gq

почти 2 года назад

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xv63-cpgc-6g6c

почти 4 года назад

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1306, CVE-2020-1334.

EPSS: Средний
github логотип

GHSA-xv63-838w-fgf7

почти 4 года назад

ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv63-73qr-p568

почти 4 года назад

In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.

EPSS: Низкий
github логотип

GHSA-xv5x-v758-wfgm

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.18.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv5x-m38x-3h28

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv5x-6w3r-qqm9

почти 4 года назад

Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.

EPSS: Низкий
github логотип

GHSA-xv5w-q9qp-mpg2

3 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-xv5w-q5wq-r3c3

4 месяца назад

Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv5v-c2mf-pc43

больше 2 лет назад

A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv5v-4g23-pxj9

почти 4 года назад

Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.

EPSS: Низкий
github логотип

GHSA-xv5r-jf97-8xjm

больше 4 лет назад

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

EPSS: Низкий
github логотип

GHSA-xv5r-44m2-6q3g

почти 2 года назад

An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted malicious links to the EDR XConsole end user.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-xv5q-xvvq-gvcm

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xv5q-r8xx-69mw

почти 4 года назад

Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv65-m527-x787

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.

CVSS3: 8.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-xv64-wpfr-x2m3

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

CVSS3: 8.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xv64-q73j-cvqp

Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22272.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xv64-jjpm-mgjv

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv64-cc6j-5cjp

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv64-8p4r-94gq

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

CVSS3: 7.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv63-cpgc-6g6c

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1306, CVE-2020-1334.

12%
Средний
почти 4 года назад
github логотип
GHSA-xv63-838w-fgf7

ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xv63-73qr-p568

In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv5x-v758-wfgm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.18.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-xv5x-m38x-3h28

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv5x-6w3r-qqm9

Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xv5w-q9qp-mpg2

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

3 месяца назад
github логотип
GHSA-xv5w-q5wq-r3c3

Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xv5v-c2mf-pc43

A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv5v-4g23-pxj9

Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.

6%
Низкий
почти 4 года назад
github логотип
GHSA-xv5r-jf97-8xjm

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xv5r-44m2-6q3g

An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted malicious links to the EDR XConsole end user.

CVSS3: 4.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv5q-xvvq-gvcm

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv5q-r8xx-69mw

Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.

CVSS3: 9.8
4%
Низкий
почти 4 года назад

Уязвимостей на страницу