Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 360

Количество 324 360

github логотип

GHSA-xrw3-prcw-c39g

5 месяцев назад

Rejected reason: Duplicate of CVE-2023-52441.

EPSS: Низкий
github логотип

GHSA-xrw3-jj6f-ghmf

около 1 года назад

Rejected reason: This CVE ID is Rejected because the issue was not a vulnerability. The data field reported is not attacker controlled.

EPSS: Низкий
github логотип

GHSA-xrw3-8mcq-hpx7

8 месяцев назад

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrw3-7gpj-88wx

почти 4 года назад

IRC client irssi in irssi-text before 0.8.4 allows remote attackers to cause a denial of service (crash) via an IRC channel that has a long topic followed by a certain string, possibly triggering a buffer overflow.

EPSS: Низкий
github логотип

GHSA-xrw2-79w2-6fm9

почти 4 года назад

Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported version that is affected is Prior to 11.1.2.4.046. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Essbase Administration Services. While the vulnerability is in Essbase Administration Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Essbase Administration Services accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-xrvx-fq8v-qp5f

почти 4 года назад

An issue was discovered in DESTOON B2B 7.0. admin\setting.inc.php has XSS via the first text box to the admin.php URI.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xrvw-f7p8-2hqm

почти 4 года назад

CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.

EPSS: Средний
github логотип

GHSA-xrvv-5xmr-3grf

почти 4 года назад

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.

EPSS: Низкий
github логотип

GHSA-xrvr-m2pw-2qj4

почти 4 года назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xrvr-j7mc-4r64

12 месяцев назад

Missing Authorization vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.4.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrvr-gp95-q8q5

6 месяцев назад

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xrvq-v6gg-4qrq

почти 4 года назад

An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31799972.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xrvp-gx9p-8ch2

больше 1 года назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to access the internet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrvp-842j-3375

больше 3 лет назад

jizhicms v2.3.1 has SQL injection in the background.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrvp-6c6f-cv37

около 4 лет назад

A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrvp-4p2v-gq5h

почти 4 года назад

Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allow remote attackers to cause a denial of service (process crash) via a crafted Real-Time Transport Control Protocol (RTCP) UDP packet, aka Bug ID CSCth60993.

EPSS: Низкий
github логотип

GHSA-xrvm-qcmp-42vc

около 3 лет назад

An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xrvm-7f7g-5v3x

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from n/a through 3.4.23.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrvj-pv83-89qp

почти 4 года назад

In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144767096

EPSS: Низкий
github логотип

GHSA-xrvj-hr46-wm97

больше 1 года назад

A vulnerability, which was classified as critical, has been found in Codezips Online Institute Management System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrw3-prcw-c39g

Rejected reason: Duplicate of CVE-2023-52441.

5 месяцев назад
github логотип
GHSA-xrw3-jj6f-ghmf

Rejected reason: This CVE ID is Rejected because the issue was not a vulnerability. The data field reported is not attacker controlled.

около 1 года назад
github логотип
GHSA-xrw3-8mcq-hpx7

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xrw3-7gpj-88wx

IRC client irssi in irssi-text before 0.8.4 allows remote attackers to cause a denial of service (crash) via an IRC channel that has a long topic followed by a certain string, possibly triggering a buffer overflow.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xrw2-79w2-6fm9

Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported version that is affected is Prior to 11.1.2.4.046. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Essbase Administration Services. While the vulnerability is in Essbase Administration Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Essbase Administration Services accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

CVSS3: 7.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrvx-fq8v-qp5f

An issue was discovered in DESTOON B2B 7.0. admin\setting.inc.php has XSS via the first text box to the admin.php URI.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrvw-f7p8-2hqm

CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.

62%
Средний
почти 4 года назад
github логотип
GHSA-xrvv-5xmr-3grf

Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xrvr-m2pw-2qj4

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xrvr-j7mc-4r64

Missing Authorization vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.4.

CVSS3: 5.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-xrvr-gp95-q8q5

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative access to supply a crafted string which would execute arbitrary JavaScript code in the browser.

CVSS3: 4.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xrvq-v6gg-4qrq

An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31799972.

CVSS3: 4.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrvp-gx9p-8ch2

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to access the internet.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrvp-842j-3375

jizhicms v2.3.1 has SQL injection in the background.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrvp-6c6f-cv37

A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xrvp-4p2v-gq5h

Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allow remote attackers to cause a denial of service (process crash) via a crafted Real-Time Transport Control Protocol (RTCP) UDP packet, aka Bug ID CSCth60993.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xrvm-qcmp-42vc

An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service.

CVSS3: 4.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-xrvm-7f7g-5v3x

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from n/a through 3.4.23.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xrvj-pv83-89qp

In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144767096

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrvj-hr46-wm97

A vulnerability, which was classified as critical, has been found in Codezips Online Institute Management System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу