Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 286 773

Количество 286 773

github логотип

GHSA-23c8-gv7j-76hv

больше 1 года назад

A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23c7-6444-399m

больше 4 лет назад

Improper Input Validation in sopel-plugins.channelmgnt

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-23c6-h4wg-837x

больше 3 лет назад

Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless/WAP). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Field Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Field Service accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-23c5-w3px-wx59

около 3 лет назад

html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via vectors involving file editing.

EPSS: Низкий
github логотип

GHSA-23c5-vp3g-x496

больше 3 лет назад

gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-23c4-jq8q-2m9j

около 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5 before IFIX003; SmartCloud Control Desk (SCCD) 7.5 before 7.5.0.3 IFIX014 and 7.5.0.5 before IFIX003; and Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.1.x through 7.1.1.12, 7.1.2, and 7.2.x through 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-23c4-87c4-jw89

около 3 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23c4-2wcp-ccr7

около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) attacks via the content parameter in a new_simple action to admin.php.

EPSS: Низкий
github логотип

GHSA-23c3-237c-6x4c

больше 3 лет назад

In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as demonstrated by .phtml, .pht, .html, or .svg.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23c2-w636-5rhm

около 3 лет назад

Jenkins SiteMonitor Plugin globally and unconditionally disables SSL/TLS certificate validation

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23c2-hg9m-2pw8

больше 1 года назад

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23c2-gwp5-pxw9

больше 2 лет назад

ReDoS based DoS vulnerability in GlobalID

EPSS: Низкий
github логотип

GHSA-23c2-5fj7-4rv3

больше 3 лет назад

The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second DATA command.

EPSS: Низкий
github логотип

GHSA-239x-qr9g-j39q

почти 3 года назад

This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-239w-f2px-h2wv

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-239w-4f3w-cfcv

около 3 лет назад

Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin Page

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-239v-mcw5-wrfq

больше 3 лет назад

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCtz72946.

EPSS: Низкий
github логотип

GHSA-239v-6rvp-q7p2

больше 3 лет назад

viksoe GMail Drive shell extension allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GMAILFS: [13;a;1] message with a new filename and a file attachment, which injects a new file into the filesystem; (2) a GMAILFS: [13;a;1] message with an existing filename and a file attachment, which overwrites existing file content; and (3) a GMAILFS: [14;a;1] message, which creates a folder.

EPSS: Низкий
github логотип

GHSA-239v-3pc9-55cf

6 месяцев назад

Abacus ERP is versions older than 2024.210.16036, 2023.205.15833, 2022.105.15542 are affected by an authenticated arbitrary file read vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-239r-qg7g-cjfp

около 3 лет назад

Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.

CVSS3: 7.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23c8-gv7j-76hv

A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

CVSS3: 6.5
3%
Низкий
больше 1 года назад
github логотип
GHSA-23c7-6444-399m

Improper Input Validation in sopel-plugins.channelmgnt

CVSS3: 7.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-23c6-h4wg-837x

Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless/WAP). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Field Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Field Service accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS3: 8.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-23c5-w3px-wx59

html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via vectors involving file editing.

1%
Низкий
около 3 лет назад
github логотип
GHSA-23c5-vp3g-x496

gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23c4-jq8q-2m9j

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5 before IFIX003; SmartCloud Control Desk (SCCD) 7.5 before 7.5.0.3 IFIX014 and 7.5.0.5 before IFIX003; and Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.1.x through 7.1.1.12, 7.1.2, and 7.2.x through 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-23c4-87c4-jw89

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-23c4-2wcp-ccr7

Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) attacks via the content parameter in a new_simple action to admin.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-23c3-237c-6x4c

In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as demonstrated by .phtml, .pht, .html, or .svg.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23c2-w636-5rhm

Jenkins SiteMonitor Plugin globally and unconditionally disables SSL/TLS certificate validation

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-23c2-hg9m-2pw8

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-23c2-gwp5-pxw9

ReDoS based DoS vulnerability in GlobalID

1%
Низкий
больше 2 лет назад
github логотип
GHSA-23c2-5fj7-4rv3

The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second DATA command.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-239x-qr9g-j39q

This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 9.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-239w-f2px-h2wv

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-239w-4f3w-cfcv

Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin Page

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-239v-mcw5-wrfq

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCtz72946.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-239v-6rvp-q7p2

viksoe GMail Drive shell extension allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GMAILFS: [13;a;1] message with a new filename and a file attachment, which injects a new file into the filesystem; (2) a GMAILFS: [13;a;1] message with an existing filename and a file attachment, which overwrites existing file content; and (3) a GMAILFS: [14;a;1] message, which creates a folder.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-239v-3pc9-55cf

Abacus ERP is versions older than 2024.210.16036, 2023.205.15833, 2022.105.15542 are affected by an authenticated arbitrary file read vulnerability.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-239r-qg7g-cjfp

Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.

CVSS3: 7.8
15%
Средний
около 3 лет назад

Уязвимостей на страницу