Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-452g-gx43-7wv5

больше 1 года назад

This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to capture a few seconds of audio before the microphone indicator is activated.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-452g-f7fp-9jf7

больше 4 лет назад

Type confusion during tensor casts lead to dereferencing null pointers

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-452f-rx2g-gx8c

больше 3 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.50.11 through 8.50.15 and 8.51GA through 8.51.05 allows remote attackers to affect confidentiality, integrity, and availability, related to PIA Core Technology.

EPSS: Низкий
github логотип

GHSA-452f-fqfm-q3xf

около 2 лет назад

In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388762; Issue ID: ALPS07388762.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-452f-c962-qphr

больше 3 лет назад

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

EPSS: Низкий
github логотип

GHSA-452f-9hr7-jmxv

почти 4 года назад

An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-452f-6cjx-8x7j

почти 4 года назад

The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.

EPSS: Низкий
github логотип

GHSA-452c-qvj7-x6xq

почти 4 года назад

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-452c-mgc8-crh5

больше 3 лет назад

A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4529-7wqq-6324

почти 4 года назад

Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.

EPSS: Высокий
github логотип

GHSA-4528-vmxj-v97w

около 3 лет назад

Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4528-h42g-x3c7

10 месяцев назад

Vulnerability in Hewlett Packard Enterprise HPE Performance Cluster Manager (HPCM).This issue affects HPE Performance Cluster Manager (HPCM): through 1.12.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4527-g864-c7mh

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Sahifa sahifa allows DOM-Based XSS.This issue affects Sahifa: from n/a through < 5.8.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4527-385c-q8r6

около 1 года назад

IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4526-r3g2-c73j

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4526-q5cq-pcrg

2 месяца назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4526-pqcm-97mm

почти 4 года назад

Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, unexpected behavior, or potentially unauthorized code execution via knowledge of the internal trust mechanism.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4526-ppgm-5hff

почти 4 года назад

Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.

EPSS: Низкий
github логотип

GHSA-4526-48hj-jf4q

почти 4 года назад

Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request. NOTE: this might be the same issue as CVE-2004-2463.

EPSS: Низкий
github логотип

GHSA-4525-wg6p-34mx

больше 2 лет назад

Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could potentially allow attackers unauthorized access to the device through the open ports.

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-452g-gx43-7wv5

This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to capture a few seconds of audio before the microphone indicator is activated.

CVSS3: 4.3
7%
Низкий
больше 1 года назад
github логотип
GHSA-452g-f7fp-9jf7

Type confusion during tensor casts lead to dereferencing null pointers

CVSS3: 2.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-452f-rx2g-gx8c

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.50.11 through 8.50.15 and 8.51GA through 8.51.05 allows remote attackers to affect confidentiality, integrity, and availability, related to PIA Core Technology.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-452f-fqfm-q3xf

In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388762; Issue ID: ALPS07388762.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-452f-c962-qphr

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-452f-9hr7-jmxv

An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-452f-6cjx-8x7j

The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.

1%
Низкий
почти 4 года назад
github логотип
GHSA-452c-qvj7-x6xq

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.

CVSS3: 7.8
47%
Средний
почти 4 года назад
github логотип
GHSA-452c-mgc8-crh5

A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4529-7wqq-6324

Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.

76%
Высокий
почти 4 года назад
github логотип
GHSA-4528-vmxj-v97w

Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-4528-h42g-x3c7

Vulnerability in Hewlett Packard Enterprise HPE Performance Cluster Manager (HPCM).This issue affects HPE Performance Cluster Manager (HPCM): through 1.12.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-4527-g864-c7mh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Sahifa sahifa allows DOM-Based XSS.This issue affects Sahifa: from n/a through < 5.8.6.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4527-385c-q8r6

IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-4526-r3g2-c73j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-4526-q5cq-pcrg

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
2 месяца назад
github логотип
GHSA-4526-pqcm-97mm

Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, unexpected behavior, or potentially unauthorized code execution via knowledge of the internal trust mechanism.

CVSS3: 7
0%
Низкий
почти 4 года назад
github логотип
GHSA-4526-ppgm-5hff

Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4526-48hj-jf4q

Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request. NOTE: this might be the same issue as CVE-2004-2463.

10%
Низкий
почти 4 года назад
github логотип
GHSA-4525-wg6p-34mx

Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could potentially allow attackers unauthorized access to the device through the open ports.

CVSS3: 9.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу