Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 556

Количество 324 556

github логотип

GHSA-xrqq-m9vv-pq36

около 2 месяцев назад

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrqq-74w4-x876

5 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver log=(file) construct allows the user to specify an arbitrary file for the JDBC driver to write its log information to.  If an application allows an end user to specify a value for the SpyAttributes connection option then an attacker could cause java script to be written to a log file.  If the log file was in the correct location with the correct extension, an application server could see that log file as a resource to be served.  The attacker could fetch the resource from the server causing the java script to be executed. This issue affects: DataDirect Connect for JDBC for Amazon R...

EPSS: Низкий
github логотип

GHSA-xrqp-jfhx-4wcr

почти 4 года назад

IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 includes a security test that sends session cookies to a specific external server, which allows man-in-the-middle attackers to hijack the test account by capturing these cookies.

EPSS: Низкий
github логотип

GHSA-xrqm-fpgr-6hhx

больше 4 лет назад

Overflow/crash in `tf.range`

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrqm-569v-qj6w

11 месяцев назад

A Stored Cross-Site Scripting (XSS) vulnerability has been found in Koibox for versions prior to e8cbce2. This vulnerability allows an authenticated attacker to upload an image containing malicious JavaScript code as profile picture in the '/es/dashboard/clientes/ficha/' endpoint

EPSS: Низкий
github логотип

GHSA-xrqj-vfc5-wr3x

почти 4 года назад

Buffer overflow in Glider Collect'n kill 1.0.0.0 allows remote attackers to execute arbitrary code via a gl_playerEnter command with a long player name.

EPSS: Средний
github логотип

GHSA-xrqj-45rp-23mg

10 месяцев назад

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

EPSS: Низкий
github логотип

GHSA-xrqh-hpg9-64g6

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Tim Whitlock Loco Translate allows Cross Site Request Forgery.This issue affects Loco Translate: from n/a through 2.6.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrqh-48jh-pjv2

22 дня назад

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrqg-3g47-qq3r

почти 4 года назад

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrqf-x4w2-4h99

почти 4 года назад

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8461.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xrqc-pp54-h37f

почти 4 года назад

SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.

EPSS: Низкий
github логотип

GHSA-xrqc-7xgx-c9vh

4 месяца назад

RCE via ZipSlip and symbolic links in argoproj/argo-workflows

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xrqc-5j6q-6hmg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xrqc-54h4-vmvv

12 месяцев назад

In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrq9-hcpf-597v

почти 4 года назад

Windows Filter Manager Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrq8-vf9x-qh4p

почти 4 года назад

When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xrq8-5w86-wqq2

почти 4 года назад

In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrq7-8rcw-5wqv

почти 4 года назад

The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.

EPSS: Средний
github логотип

GHSA-xrq7-65mq-gcgw

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webriti Busiprof allows Stored XSS.This issue affects Busiprof: from n/a through 2.4.8.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrqq-m9vv-pq36

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xrqq-74w4-x876

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver log=(file) construct allows the user to specify an arbitrary file for the JDBC driver to write its log information to.  If an application allows an end user to specify a value for the SpyAttributes connection option then an attacker could cause java script to be written to a log file.  If the log file was in the correct location with the correct extension, an application server could see that log file as a resource to be served.  The attacker could fetch the resource from the server causing the java script to be executed. This issue affects: DataDirect Connect for JDBC for Amazon R...

0%
Низкий
5 месяцев назад
github логотип
GHSA-xrqp-jfhx-4wcr

IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 includes a security test that sends session cookies to a specific external server, which allows man-in-the-middle attackers to hijack the test account by capturing these cookies.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrqm-fpgr-6hhx

Overflow/crash in `tf.range`

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xrqm-569v-qj6w

A Stored Cross-Site Scripting (XSS) vulnerability has been found in Koibox for versions prior to e8cbce2. This vulnerability allows an authenticated attacker to upload an image containing malicious JavaScript code as profile picture in the '/es/dashboard/clientes/ficha/' endpoint

0%
Низкий
11 месяцев назад
github логотип
GHSA-xrqj-vfc5-wr3x

Buffer overflow in Glider Collect'n kill 1.0.0.0 allows remote attackers to execute arbitrary code via a gl_playerEnter command with a long player name.

12%
Средний
почти 4 года назад
github логотип
GHSA-xrqj-45rp-23mg

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.

0%
Низкий
10 месяцев назад
github логотип
GHSA-xrqh-hpg9-64g6

Cross-Site Request Forgery (CSRF) vulnerability in Tim Whitlock Loco Translate allows Cross Site Request Forgery.This issue affects Loco Translate: from n/a through 2.6.9.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrqh-48jh-pjv2

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.

CVSS3: 7.5
0%
Низкий
22 дня назад
github логотип
GHSA-xrqg-3g47-qq3r

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-xrqf-x4w2-4h99

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8461.

CVSS3: 7.5
23%
Средний
почти 4 года назад
github логотип
GHSA-xrqc-pp54-h37f

SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrqc-7xgx-c9vh

RCE via ZipSlip and symbolic links in argoproj/argo-workflows

CVSS3: 8.1
0%
Низкий
4 месяца назад
github логотип
GHSA-xrqc-5j6q-6hmg

Cross-site scripting (XSS) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrqc-54h4-vmvv

In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875.

CVSS3: 9.8
1%
Низкий
12 месяцев назад
github логотип
GHSA-xrq9-hcpf-597v

Windows Filter Manager Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrq8-vf9x-qh4p

When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrq8-5w86-wqq2

In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrq7-8rcw-5wqv

The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.

58%
Средний
почти 4 года назад
github логотип
GHSA-xrq7-65mq-gcgw

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webriti Busiprof allows Stored XSS.This issue affects Busiprof: from n/a through 2.4.8.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу