Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3qhf-m339-9g5v

7 месяцев назад

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

EPSS: Низкий
github логотип

GHSA-3qhf-g8c6-mhph

2 месяца назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qhf-7635-fhw3

больше 3 лет назад

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to the palette box.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3qhc-99ww-4gq4

почти 4 года назад

The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."

EPSS: Низкий
github логотип

GHSA-3qh8-fcm2-qxpv

4 месяца назад

The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qh7-qjj4-qhgh

больше 3 лет назад

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

EPSS: Низкий
github логотип

GHSA-3qh7-pv9c-8cxc

почти 2 года назад

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263499.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3qh7-hqp3-w27g

почти 4 года назад

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

EPSS: Средний
github логотип

GHSA-3qh6-c633-q2hf

больше 3 лет назад

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

EPSS: Низкий
github логотип

GHSA-3qh5-qqj2-c78f

больше 2 лет назад

Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3qh5-grgw-6275

больше 3 лет назад

** DISPUTED ** In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qh5-7pwc-f43p

больше 3 лет назад

Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qh5-7339-m5xf

больше 3 лет назад

UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through the serial interface (UART).

EPSS: Низкий
github логотип

GHSA-3qh4-r86r-grvm

больше 5 лет назад

Arbitrary JavaScript Execution in typed-function

EPSS: Низкий
github логотип

GHSA-3qh4-83p4-2w86

больше 3 лет назад

In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack memory to be written to disk as uninitialized directory entry padding.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qh3-fx4r-gprg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary JavaScript by modifying the history object.

EPSS: Низкий
github логотип

GHSA-3qh3-f456-7963

больше 3 лет назад

Vulnerability in the Oracle Hospitality RES 3700 product of Oracle Food and Beverage Applications (component: CAL). The supported version that is affected is 5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hospitality RES 3700. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality RES 3700 accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

EPSS: Низкий
github логотип

GHSA-3qh3-9c67-f35w

почти 4 года назад

SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.

EPSS: Низкий
github логотип

GHSA-3qh2-mccc-q5m6

больше 3 лет назад

Keycloak Open Redirect

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qh2-c3gj-pjr3

19 дней назад

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qhf-m339-9g5v

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

0%
Низкий
7 месяцев назад
github логотип
GHSA-3qhf-g8c6-mhph

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-3qhf-7635-fhw3

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser, related to the palette box.

CVSS3: 5.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3qhc-99ww-4gq4

The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."

6%
Низкий
почти 4 года назад
github логотип
GHSA-3qh8-fcm2-qxpv

The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3qh7-qjj4-qhgh

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3qh7-pv9c-8cxc

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263499.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3qh7-hqp3-w27g

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

56%
Средний
почти 4 года назад
github логотип
GHSA-3qh6-c633-q2hf

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qh5-qqj2-c78f

Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qh5-grgw-6275

** DISPUTED ** In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3qh5-7pwc-f43p

Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qh5-7339-m5xf

UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through the serial interface (UART).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qh4-r86r-grvm

Arbitrary JavaScript Execution in typed-function

1%
Низкий
больше 5 лет назад
github логотип
GHSA-3qh4-83p4-2w86

In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack memory to be written to disk as uninitialized directory entry padding.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qh3-fx4r-gprg

Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary JavaScript by modifying the history object.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3qh3-f456-7963

Vulnerability in the Oracle Hospitality RES 3700 product of Oracle Food and Beverage Applications (component: CAL). The supported version that is affected is 5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hospitality RES 3700. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality RES 3700 accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qh3-9c67-f35w

SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3qh2-mccc-q5m6

Keycloak Open Redirect

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qh2-c3gj-pjr3

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVSS3: 5.9
0%
Низкий
19 дней назад

Уязвимостей на страницу