Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3xc7-xg67-pw99

больше 6 лет назад

Sensitive Data Exposure in sequelize-cli

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3xc7-x46v-p5qp

больше 3 лет назад

The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, including user and data source credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Server: versions up to and including 7.8.1; 7.9.0; 7.10.0; 7.11.0; 7.12.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3xc7-cmq9-9rff

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3xc7-8f3r-h948

больше 3 лет назад

Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 6.5
EPSS: Высокий
github логотип

GHSA-3xc7-4mq4-jmpm

почти 4 года назад

Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_News action.

EPSS: Низкий
github логотип

GHSA-3xc6-7h59-j2x4

почти 2 года назад

Duplicate Advisory: eza Potential Heap Overflow Vulnerability for AArch64

EPSS: Низкий
github логотип

GHSA-3xc5-vgfg-rqw3

почти 4 года назад

IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.

EPSS: Низкий
github логотип

GHSA-3xc4-c3pf-7rjh

больше 3 лет назад

The Anderson Musaamil (aka com.app_andersonmusaamil.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3xc3-wg4j-v425

около 2 месяцев назад

Incorrect Privilege Assignment vulnerability in WPXPO PostX ultimate-post allows Privilege Escalation.This issue affects PostX: from n/a through <= 4.1.35.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3xc3-m57q-hj7g

почти 4 года назад

O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.

EPSS: Низкий
github логотип

GHSA-3xc3-g6fp-66xr

больше 1 года назад

Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xc3-235x-7q23

больше 3 лет назад

HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.

EPSS: Низкий
github логотип

GHSA-3xc2-jvpw-rv79

около 1 года назад

CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x9x-vhqj-cv27

больше 3 лет назад

Magento XML Injection vulnerability in the Widgets Update Layout

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-3x9w-fg96-5j98

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix VP8 stateless decoder smatch warning Fix a smatch static checker warning on vdec_vp8_req_if.c. Which leads to a kernel crash when fb is NULL.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x9v-m7wh-wv6x

больше 3 лет назад

Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference.

EPSS: Низкий
github логотип

GHSA-3x9v-482c-32cf

больше 3 лет назад

In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x9v-3chp-c9cc

3 месяца назад

Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3x9q-xwx4-hhr3

4 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3x9p-x3q5-7j89

больше 3 лет назад

Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3xc7-xg67-pw99

Sensitive Data Exposure in sequelize-cli

CVSS3: 3.5
больше 6 лет назад
github логотип
GHSA-3xc7-x46v-p5qp

The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, including user and data source credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Server: versions up to and including 7.8.1; 7.9.0; 7.10.0; 7.11.0; 7.12.0.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xc7-cmq9-9rff

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3xc7-8f3r-h948

Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 6.5
74%
Высокий
больше 3 лет назад
github логотип
GHSA-3xc7-4mq4-jmpm

Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_News action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3xc6-7h59-j2x4

Duplicate Advisory: eza Potential Heap Overflow Vulnerability for AArch64

почти 2 года назад
github логотип
GHSA-3xc5-vgfg-rqw3

IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3xc4-c3pf-7rjh

The Anderson Musaamil (aka com.app_andersonmusaamil.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xc3-wg4j-v425

Incorrect Privilege Assignment vulnerability in WPXPO PostX ultimate-post allows Privilege Escalation.This issue affects PostX: from n/a through <= 4.1.35.

CVSS3: 7.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3xc3-m57q-hj7g

O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3xc3-g6fp-66xr

Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3xc3-235x-7q23

HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xc2-jvpw-rv79

CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3x9x-vhqj-cv27

Magento XML Injection vulnerability in the Widgets Update Layout

CVSS3: 7.2
11%
Средний
больше 3 лет назад
github логотип
GHSA-3x9w-fg96-5j98

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix VP8 stateless decoder smatch warning Fix a smatch static checker warning on vdec_vp8_req_if.c. Which leads to a kernel crash when fb is NULL.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x9v-m7wh-wv6x

Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9v-482c-32cf

In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9v-3chp-c9cc

Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 3.1
0%
Низкий
3 месяца назад
github логотип
GHSA-3x9q-xwx4-hhr3

Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3x9p-x3q5-7j89

Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу