Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-43cp-6p3q-2pc4

больше 2 лет назад

HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43cm-g4rg-jr2r

почти 2 года назад

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43cm-73px-5v4m

больше 3 лет назад

OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors

EPSS: Низкий
github логотип

GHSA-43cj-rvm4-7798

почти 4 года назад

SMC Networks Barricade Wireless Cable/DSL Broadband Router SMC7004VWBR allows remote attackers to cause a denial of service via certain packets to PPTP port 1723 on the internal interface.

EPSS: Низкий
github логотип

GHSA-43cj-cr8f-9vfw

больше 3 лет назад

A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.

EPSS: Низкий
github логотип

GHSA-43ch-53q4-hc3r

больше 3 лет назад

The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43ch-2h55-2vj7

почти 5 лет назад

Server-Side Request Forgery in private-ip

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43cg-vjjq-q598

больше 3 лет назад

Vulnerability in the Oracle Security Service component of Oracle Fusion Middleware (subcomponent: C Oracle SSL API). Supported versions that are affected are FMW: 11.1.1.9.0 and 12.1.3.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Security Service. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Security Service accessible data. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-43cg-qpw3-5c5w

больше 3 лет назад

Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded keys and log in to such a device through SSH.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43cg-c28c-82hq

больше 3 лет назад

IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43cf-7f3h-38rg

больше 1 года назад

Privilege Escalation in TYPO3 Neos

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-43cc-x849-58fv

больше 3 лет назад

Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2603, CVE-2015-2604, CVE-2015-2605, CVE-2015-2606, and CVE-2015-4745.

EPSS: Низкий
github логотип

GHSA-43c9-q639-gwmv

почти 4 года назад

Multiple buffer overflows in acgm.dll in the Corel / Micrografx ActiveCGM Browser ActiveX control before 7.1.4.19 allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-43c9-gw4x-pcx6

около 1 года назад

Authenticated arbitrary file deletion in YesWiki

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43c9-25jg-rxm4

больше 1 года назад

The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43c8-fr4h-pfw6

больше 3 лет назад

STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to a "Possible Stack Corruption starting at Unknown Symbol @ 0x00000000038f2fbf called from image00000000_00400000+0x0000000000240065."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-43c8-2xf3-9353

2 месяца назад

Missing Authorization vulnerability in berthaai BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BERTHA AI: from n/a through <= 1.13.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43c7-728f-g6cx

больше 3 лет назад

Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43c7-2hjm-369m

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in signup.php in Article Dashboard allow remote attackers to inject arbitrary web script or HTML via the (1) f_emailaddress, (2) f_reemailaddress, and other unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-43c6-phh4-mmp3

больше 3 лет назад

An issue was discovered in ACDSee Photo Studio Standard 22.1 Build 1159. There is a User Mode Write AV starting at IDE_ACDStd!IEP_ShowPlugInDialog+0x000000000023d060.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43cp-6p3q-2pc4

HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-43cm-g4rg-jr2r

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-43cm-73px-5v4m

OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43cj-rvm4-7798

SMC Networks Barricade Wireless Cable/DSL Broadband Router SMC7004VWBR allows remote attackers to cause a denial of service via certain packets to PPTP port 1723 on the internal interface.

1%
Низкий
почти 4 года назад
github логотип
GHSA-43cj-cr8f-9vfw

A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-43ch-53q4-hc3r

The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43ch-2h55-2vj7

Server-Side Request Forgery in private-ip

CVSS3: 9.8
2%
Низкий
почти 5 лет назад
github логотип
GHSA-43cg-vjjq-q598

Vulnerability in the Oracle Security Service component of Oracle Fusion Middleware (subcomponent: C Oracle SSL API). Supported versions that are affected are FMW: 11.1.1.9.0 and 12.1.3.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Security Service. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Security Service accessible data. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVSS3: 3.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43cg-qpw3-5c5w

Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticate different nodes of the devices. An attacker may obtain the hardcoded keys and log in to such a device through SSH.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43cg-c28c-82hq

IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43cf-7f3h-38rg

Privilege Escalation in TYPO3 Neos

CVSS3: 4.2
больше 1 года назад
github логотип
GHSA-43cc-x849-58fv

Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2603, CVE-2015-2604, CVE-2015-2605, CVE-2015-2606, and CVE-2015-4745.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-43c9-q639-gwmv

Multiple buffer overflows in acgm.dll in the Corel / Micrografx ActiveCGM Browser ActiveX control before 7.1.4.19 allow remote attackers to execute arbitrary code via unspecified vectors.

9%
Низкий
почти 4 года назад
github логотип
GHSA-43c9-gw4x-pcx6

Authenticated arbitrary file deletion in YesWiki

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-43c9-25jg-rxm4

The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

CVSS3: 8.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-43c8-fr4h-pfw6

STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to a "Possible Stack Corruption starting at Unknown Symbol @ 0x00000000038f2fbf called from image00000000_00400000+0x0000000000240065."

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43c8-2xf3-9353

Missing Authorization vulnerability in berthaai BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BERTHA AI: from n/a through <= 1.13.

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-43c7-728f-g6cx

Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43c7-2hjm-369m

Multiple cross-site scripting (XSS) vulnerabilities in signup.php in Article Dashboard allow remote attackers to inject arbitrary web script or HTML via the (1) f_emailaddress, (2) f_reemailaddress, and other unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-43c6-phh4-mmp3

An issue was discovered in ACDSee Photo Studio Standard 22.1 Build 1159. There is a User Mode Write AV starting at IDE_ACDStd!IEP_ShowPlugInDialog+0x000000000023d060.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу