Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 290 064

Количество 290 064

github логотип

GHSA-2cjm-j72p-vj2q

почти 2 года назад

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cjm-cj9v-8j23

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.

EPSS: Низкий
github логотип

GHSA-2cjm-39g8-5fv8

больше 3 лет назад

In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cjj-vh62-f62h

больше 3 лет назад

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2cjj-7rx5-5hhq

больше 3 лет назад

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Control Flow starting at Unknown Symbol @ 0x0000000003aa7cef called from Unknown Symbol @ 0x0000000004aa024d."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cjh-75gp-34gc

больше 1 года назад

livewire Cross-Site Request Forgery vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2cjg-pfcc-g8hr

больше 3 лет назад

In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cjg-6xm9-4wh6

больше 3 лет назад

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2cjf-w7c4-fhf6

больше 3 лет назад

Cross-site Scripting in Beanstalk console

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2cjf-q722-7gc5

больше 3 лет назад

SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

EPSS: Низкий
github логотип

GHSA-2cjf-4qjm-hh7v

больше 2 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2cjc-rgmp-x649

больше 3 лет назад

Traefik Missing Authentication

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2cjc-6xrh-7w5q

8 месяцев назад

Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through 2.1.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2cjc-543p-gpj8

больше 3 лет назад

admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2cj9-wjmr-5w57

больше 1 года назад

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cj9-r6h5-6jwg

больше 3 лет назад

ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2cj8-f8jw-33qq

больше 3 лет назад

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2cj8-cg4w-q64p

около 3 лет назад

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cj8-639j-6rq5

4 месяца назад

A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. The manipulation of the argument content leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2cj7-q7vw-gwx8

6 месяцев назад

There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2cjm-j72p-vj2q

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2cjm-cj9v-8j23

Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjm-39g8-5fv8

In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.

CVSS3: 7.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjj-vh62-f62h

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjj-7rx5-5hhq

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Control Flow starting at Unknown Symbol @ 0x0000000003aa7cef called from Unknown Symbol @ 0x0000000004aa024d."

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjh-75gp-34gc

livewire Cross-Site Request Forgery vulnerability

CVSS3: 8.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-2cjg-pfcc-g8hr

In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjg-6xm9-4wh6

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjf-w7c4-fhf6

Cross-site Scripting in Beanstalk console

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjf-q722-7gc5

SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjf-4qjm-hh7v

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2cjc-rgmp-x649

Traefik Missing Authentication

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjc-6xrh-7w5q

Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through 2.1.1.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2cjc-543p-gpj8

admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cj9-wjmr-5w57

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2cj9-r6h5-6jwg

ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cj8-f8jw-33qq

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

CVSS3: 6.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2cj8-cg4w-q64p

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
6%
Низкий
около 3 лет назад
github логотип
GHSA-2cj8-639j-6rq5

A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. The manipulation of the argument content leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2cj7-q7vw-gwx8

There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.

CVSS3: 4.9
0%
Низкий
6 месяцев назад

Уязвимостей на страницу