Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3x97-q7pq-fx88

больше 3 лет назад

IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3x97-g7q3-p9h7

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3x96-m42v-hvh5

больше 3 лет назад

Cross-site Scripting in Microweber

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-3x95-65g7-v9h7

около 1 года назад

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3x94-q4r9-gmj8

больше 1 года назад

The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3x94-fv5h-5q2c

больше 5 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMS

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3x94-9qvg-gr4q

больше 3 лет назад

Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafted HTTP request, related to JSON, aka SAP Security Note 2241978.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3x94-5mfw-j4r8

больше 3 лет назад

A potential security vulnerability caused by incomplete obfuscation of application configuration information was discovered in Tommy Hilfiger TH24/7 Android app versions 2.0.0.11, 2.0.1.14, 2.1.0.16, and 2.2.0.19. HP has no access to customer data as a result of this issue.

CVSS3: 2.1
EPSS: Низкий
github логотип

GHSA-3x94-47mg-35rf

больше 1 года назад

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x93-p299-w98q

больше 3 лет назад

All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one value of the field and subsequently the loop to see a modified field value without retesting the condition moved out of the loop. This can lead to a variety of different issues but read out of array bounds is one major consequence of these problems.

EPSS: Низкий
github логотип

GHSA-3x92-jhww-8qj8

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build 1001. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the content parameter provided to the script_test.jsp endpoint. A crafted content request parameter can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code under the context of the web service. Was ZDI-CAN-5080.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x8x-wg7p-5gq4

около 1 года назад

Substance3D - Painter versions 10.1.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x8x-wfc9-4c2q

6 месяцев назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Ventura 13.7.7, macOS Sonoma 14.7.7. An app may be able to modify protected parts of the file system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x8x-qmm7-6f56

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix possible buffer overflow struct hci_dev_info has a fixed size name[8] field so in the event that hdev->name is bigger than that strcpy would attempt to write past its size, so this fixes this problem by switching to use strscpy.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x8x-79m2-3w2w

почти 3 года назад

jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x8w-qfr9-4jmg

около 2 месяцев назад

Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3x8w-p58r-45ff

почти 4 года назад

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.

EPSS: Средний
github логотип

GHSA-3x8v-x6rr-p9g8

7 месяцев назад

Resource leak vulnerability in ASR180x in router allows Resource Leak Exposure. This vulnerability is associated with program files router/sms/sms.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3x8r-xvj6-wr9x

около 3 лет назад

An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3x8r-x6xp-q4vm

около 3 лет назад

Uncontrolled Recursion in Loofah

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x97-q7pq-fx88

IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x97-g7q3-p9h7

An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x96-m42v-hvh5

Cross-site Scripting in Microweber

CVSS3: 6.1
28%
Средний
больше 3 лет назад
github логотип
GHSA-3x95-65g7-v9h7

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3x94-q4r9-gmj8

The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x94-fv5h-5q2c

Exposure of Sensitive Information to an Unauthorized Actor in TYPO3 CMS

CVSS3: 8.1
1%
Низкий
больше 5 лет назад
github логотип
GHSA-3x94-9qvg-gr4q

Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafted HTTP request, related to JSON, aka SAP Security Note 2241978.

CVSS3: 9.8
37%
Средний
больше 3 лет назад
github логотип
GHSA-3x94-5mfw-j4r8

A potential security vulnerability caused by incomplete obfuscation of application configuration information was discovered in Tommy Hilfiger TH24/7 Android app versions 2.0.0.11, 2.0.1.14, 2.1.0.16, and 2.2.0.19. HP has no access to customer data as a result of this issue.

CVSS3: 2.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x94-47mg-35rf

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x93-p299-w98q

All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one value of the field and subsequently the loop to see a modified field value without retesting the condition moved out of the loop. This can lead to a variety of different issues but read out of array bounds is one major consequence of these problems.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3x92-jhww-8qj8

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build 1001. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the content parameter provided to the script_test.jsp endpoint. A crafted content request parameter can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code under the context of the web service. Was ZDI-CAN-5080.

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-3x8x-wg7p-5gq4

Substance3D - Painter versions 10.1.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3x8x-wfc9-4c2q

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Ventura 13.7.7, macOS Sonoma 14.7.7. An app may be able to modify protected parts of the file system.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-3x8x-qmm7-6f56

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix possible buffer overflow struct hci_dev_info has a fixed size name[8] field so in the event that hdev->name is bigger than that strcpy would attempt to write past its size, so this fixes this problem by switching to use strscpy.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3x8x-79m2-3w2w

jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3x8w-qfr9-4jmg

Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3x8w-p58r-45ff

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.

18%
Средний
почти 4 года назад
github логотип
GHSA-3x8v-x6rr-p9g8

Resource leak vulnerability in ASR180x in router allows Resource Leak Exposure. This vulnerability is associated with program files router/sms/sms.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536.

CVSS3: 5.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-3x8r-xvj6-wr9x

An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3x8r-x6xp-q4vm

Uncontrolled Recursion in Loofah

CVSS3: 7.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу