Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 099

Количество 288 099

github логотип

GHSA-22v8-m2j9-v5f6

больше 3 лет назад

Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22v7-w6c5-v4rr

около 3 лет назад

Apache Ranger Access Restriction Bypass

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22v7-v3mj-pm8r

больше 1 года назад

Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-22v6-vh64-279g

около 3 лет назад

There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22v6-4f2p-rcq7

около 3 лет назад

Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS v3.0 Base Score 4.7 (Integrity impacts).

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-22v5-q59j-h85m

около 2 месяцев назад

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22v5-h5m8-j4hf

больше 3 лет назад

ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-22v5-644q-6x94

около 1 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita allows PHP Local File Inclusion. This issue affects Zita: from n/a through 1.6.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-22v4-7fpv-5gx7

больше 3 лет назад

XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22v4-3qpp-69q8

6 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-22v3-6xfr-m72g

около 3 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1752.

EPSS: Средний
github логотип

GHSA-22v3-6wxv-73wp

около 1 года назад

Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-22rx-rqrm-w97p

больше 3 лет назад

Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.

EPSS: Низкий
github логотип

GHSA-22rx-pp25-m56g

около 3 лет назад

The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22rx-gchv-6fvx

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

EPSS: Низкий
github логотип

GHSA-22rx-39m3-hr5w

около 3 лет назад

bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22rr-f3p8-5gf8

почти 2 года назад

Directus affected by VM2 sandbox escape vulnerability

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-22rr-c324-2vj7

6 месяцев назад

A vulnerability, which was classified as problematic, has been found in Discord up to 1.0.9177 on Windows. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to untrusted search path. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-22rr-8c54-p9rr

около 3 лет назад

The zroadster.com (aka com.tapatalk.zroadstercomforum) application 2.4.13.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-22rq-cmx2-gvr4

11 месяцев назад

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to overwrite arbitrary files.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22v8-m2j9-v5f6

Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22v7-w6c5-v4rr

Apache Ranger Access Restriction Bypass

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-22v7-v3mj-pm8r

Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability

CVSS3: 8.8
74%
Высокий
больше 1 года назад
github логотип
GHSA-22v6-vh64-279g

There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-22v6-4f2p-rcq7

Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS v3.0 Base Score 4.7 (Integrity impacts).

CVSS3: 4.7
1%
Низкий
около 3 лет назад
github логотип
GHSA-22v5-q59j-h85m

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-22v5-h5m8-j4hf

ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22v5-644q-6x94

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita allows PHP Local File Inclusion. This issue affects Zita: from n/a through 1.6.5.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-22v4-7fpv-5gx7

XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22v4-3qpp-69q8

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

6 месяцев назад
github логотип
GHSA-22v3-6xfr-m72g

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1752.

24%
Средний
около 3 лет назад
github логотип
GHSA-22v3-6wxv-73wp

Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-22rx-rqrm-w97p

Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-22rx-pp25-m56g

The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-22rx-gchv-6fvx

Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22rx-39m3-hr5w

bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar file.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-22rr-f3p8-5gf8

Directus affected by VM2 sandbox escape vulnerability

CVSS3: 7.6
почти 2 года назад
github логотип
GHSA-22rr-c324-2vj7

A vulnerability, which was classified as problematic, has been found in Discord up to 1.0.9177 on Windows. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to untrusted search path. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-22rr-8c54-p9rr

The zroadster.com (aka com.tapatalk.zroadstercomforum) application 2.4.13.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 3 лет назад
github логотип
GHSA-22rq-cmx2-gvr4

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to overwrite arbitrary files.

CVSS3: 8.1
0%
Низкий
11 месяцев назад

Уязвимостей на страницу