Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-2836-rjcm-28p3

25 дней назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - duplicate-data-source modules) allows Absolute Path Traversal. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2835-wpx9-j9cq

около 3 лет назад

An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.

EPSS: Низкий
github логотип

GHSA-2835-wjwh-6r5g

больше 3 лет назад

SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.

EPSS: Низкий
github логотип

GHSA-2835-h7pr-xpph

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eyouth { rob.panes } Charity-thermometer allows Stored XSS.This issue affects Charity-thermometer: from n/a through 1.1.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2834-vx6f-v89w

больше 3 лет назад

Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."

EPSS: Низкий
github логотип

GHSA-2834-cpjr-ww85

больше 3 лет назад

apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.

EPSS: Низкий
github логотип

GHSA-2834-c875-f7jj

около 3 лет назад

Improper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2834-55v8-f2v4

больше 3 лет назад

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2833-c767-j26x

10 месяцев назад

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2832-r3gh-ghrj

больше 3 лет назад

Use after free in Vulkan in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-282x-mj8h-7q8w

около 3 лет назад

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-282w-q25g-979q

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/meson: encoder_hdmi: Fix refcount leak in meson_encoder_hdmi_init of_graph_get_remote_node() returns remote device nodepointer with refcount incremented, we should use of_node_put() on it when done. Add missing of_node_put() to avoid refcount leak.

EPSS: Низкий
github логотип

GHSA-282w-5q6m-5xx6

больше 3 лет назад

Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0604.

EPSS: Низкий
github логотип

GHSA-282v-8gf3-6m78

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.

EPSS: Низкий
github логотип

GHSA-282v-666c-3fvg

больше 2 лет назад

transformers has Insecure Temporary File

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-282v-3f28-8726

больше 3 лет назад

Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-282r-w9m2-4r2w

2 месяца назад

Path Traversal vulnerability in Mikado-Themes Grill and Chow allows PHP Local File Inclusion. This issue affects Grill and Chow: from n/a through 1.6.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-282q-x2f9-j9j7

около 3 лет назад

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to crash or to trigger a device reboot.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-282p-qvpm-4cp8

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Phi Phan Meta Field Block allows Stored XSS.This issue affects Meta Field Block: from n/a through 1.2.13.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-282p-5qxv-x526

больше 3 лет назад

An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2836-rjcm-28p3

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - duplicate-data-source modules) allows Absolute Path Traversal. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.

CVSS3: 8.5
0%
Низкий
25 дней назад
github логотип
GHSA-2835-wpx9-j9cq

An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2835-wjwh-6r5g

SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2835-h7pr-xpph

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eyouth { rob.panes } Charity-thermometer allows Stored XSS.This issue affects Charity-thermometer: from n/a through 1.1.2.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2834-vx6f-v89w

Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2834-cpjr-ww85

apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2834-c875-f7jj

Improper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2834-55v8-f2v4

A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages

CVSS3: 2.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2833-c767-j26x

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2832-r3gh-ghrj

Use after free in Vulkan in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-282x-mj8h-7q8w

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

CVSS3: 7.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-282w-q25g-979q

In the Linux kernel, the following vulnerability has been resolved: drm/meson: encoder_hdmi: Fix refcount leak in meson_encoder_hdmi_init of_graph_get_remote_node() returns remote device nodepointer with refcount incremented, we should use of_node_put() on it when done. Add missing of_node_put() to avoid refcount leak.

0%
Низкий
2 месяца назад
github логотип
GHSA-282w-5q6m-5xx6

Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0604.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-282v-8gf3-6m78

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-282v-666c-3fvg

transformers has Insecure Temporary File

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-282v-3f28-8726

Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-282r-w9m2-4r2w

Path Traversal vulnerability in Mikado-Themes Grill and Chow allows PHP Local File Inclusion. This issue affects Grill and Chow: from n/a through 1.6.

CVSS3: 8.1
0%
Низкий
2 месяца назад
github логотип
GHSA-282q-x2f9-j9j7

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to crash or to trigger a device reboot.

CVSS3: 4.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-282p-qvpm-4cp8

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Phi Phan Meta Field Block allows Stored XSS.This issue affects Meta Field Block: from n/a through 1.2.13.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-282p-5qxv-x526

An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу