Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 308

Количество 288 308

github логотип

GHSA-24rg-9rhw-m9gh

около 3 лет назад

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-24rf-wvhf-33v8

больше 1 года назад

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20926.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-24rf-59x9-98x7

около 3 лет назад

A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a privilege level of a guest user. The vulnerability is due to an incorrect networking configuration at the administrative shell CLI. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a set of crafted, malicious commands at the administrative shell. An exploit could allow the attacker to gain root access on the device. Cisco Bug IDs: CSCvb34303, CSCvb35726.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24r9-p447-gxg2

около 3 лет назад

SQL injection vulnerability in admin.php in E-topbiz Domain Shop 2 allows remote attackers to execute arbitrary SQL commands via the passfromform parameter.

EPSS: Низкий
github логотип

GHSA-24r9-8wx9-6g9f

около 1 года назад

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-24r8-jmfh-r268

больше 2 лет назад

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24r8-fm9r-cpj2

больше 5 лет назад

Low severity vulnerability that affects com.linecorp.armeria:armeria

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-24r7-x8mx-hc2h

больше 3 лет назад

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-24r7-c5r6-xxmj

около 3 лет назад

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Средний
github логотип

GHSA-24r6-29j2-hrjv

больше 3 лет назад

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

EPSS: Низкий
github логотип

GHSA-24r5-xw2j-9h9x

больше 1 года назад

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24r3-rx3r-wgvw

около 1 года назад

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-24r3-qrv6-6jx6

около 3 лет назад

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-24r2-2rf2-whfq

3 месяца назад

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24qx-986r-jvf4

около 3 лет назад

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24qw-g5w5-55fm

около 3 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-24qw-797r-8hmj

около 3 лет назад

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24qv-pghr-gg8x

больше 3 лет назад

PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

EPSS: Низкий
github логотип

GHSA-24qv-j57w-wmcf

13 дней назад

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-24qv-68gq-r7hr

больше 3 лет назад

The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24rg-9rhw-m9gh

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.

CVSS3: 8.8
28%
Средний
около 3 лет назад
github логотип
GHSA-24rf-wvhf-33v8

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20926.

CVSS3: 3.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-24rf-59x9-98x7

A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a privilege level of a guest user. The vulnerability is due to an incorrect networking configuration at the administrative shell CLI. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a set of crafted, malicious commands at the administrative shell. An exploit could allow the attacker to gain root access on the device. Cisco Bug IDs: CSCvb34303, CSCvb35726.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-24r9-p447-gxg2

SQL injection vulnerability in admin.php in E-topbiz Domain Shop 2 allows remote attackers to execute arbitrary SQL commands via the passfromform parameter.

0%
Низкий
около 3 лет назад
github логотип
GHSA-24r9-8wx9-6g9f

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

CVSS3: 9.8
64%
Средний
около 1 года назад
github логотип
GHSA-24r8-jmfh-r268

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24r8-fm9r-cpj2

Low severity vulnerability that affects com.linecorp.armeria:armeria

CVSS3: 4.8
0%
Низкий
больше 5 лет назад
github логотип
GHSA-24r7-x8mx-hc2h

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CVSS3: 9.8
27%
Средний
больше 3 лет назад
github логотип
GHSA-24r7-c5r6-xxmj

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

13%
Средний
около 3 лет назад
github логотип
GHSA-24r6-29j2-hrjv

WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

4%
Низкий
больше 3 лет назад
github логотип
GHSA-24r5-xw2j-9h9x

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-24r3-rx3r-wgvw

A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with tutor privileges to inject arbitrary web script or HTML via XML file upload.

CVSS3: 4.7
0%
Низкий
около 1 года назад
github логотип
GHSA-24r3-qrv6-6jx6

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via unspecified vectors.

29%
Средний
около 3 лет назад
github логотип
GHSA-24r2-2rf2-whfq

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-24qx-986r-jvf4

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-24qw-g5w5-55fm

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS3: 7.5
21%
Средний
около 3 лет назад
github логотип
GHSA-24qw-797r-8hmj

Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-24qv-pghr-gg8x

PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-24qv-j57w-wmcf

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
13 дней назад
github логотип
GHSA-24qv-68gq-r7hr

The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу