Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3p76-4rrp-wwv9

9 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3p75-q5cc-qmj7

около 2 лет назад

Duplicate Advisory: Keycloak Open Redirect vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-3p74-pwfx-pcgr

почти 4 года назад

The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.

EPSS: Низкий
github логотип

GHSA-3p74-fjhf-m5jm

6 месяцев назад

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3p73-mm7v-4f6m

около 3 лет назад

DoS vulnerability in MaliciousCode filter

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3p73-75xq-v9wv

почти 2 года назад

An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3p72-rmv7-7jc9

больше 3 лет назад

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

EPSS: Низкий
github логотип

GHSA-3p72-mm77-r69w

почти 4 года назад

Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.

EPSS: Низкий
github логотип

GHSA-3p6x-mw8p-qjh9

почти 4 года назад

An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3p6x-7vmm-w6rr

больше 3 лет назад

The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3p6w-gv5g-xjw9

4 месяца назад

MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3p6w-82x2-65rf

больше 3 лет назад

An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files, aka 'Microsoft Office Click-to-Run Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16934, CVE-2020-16955.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3p6v-qx4g-mwhp

больше 3 лет назад

A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p6v-hrg8-8qj7

11 месяцев назад

@mozilla/readability Denial of Service through Regex

EPSS: Низкий
github логотип

GHSA-3p6v-922c-mrw6

11 месяцев назад

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3p6r-56fp-3cwc

больше 3 лет назад

Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p6r-3579-wxm9

5 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in aakash1911 WP likes allows Reflected XSS. This issue affects WP likes: from n/a through 3.1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3p6q-h5pg-fcv3

около 1 месяца назад

Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p6p-pp2j-3qr6

больше 3 лет назад

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm field that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

EPSS: Средний
github логотип

GHSA-3p6p-6hwj-52g9

5 месяцев назад

A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p76-4rrp-wwv9

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

9 месяцев назад
github логотип
GHSA-3p75-q5cc-qmj7

Duplicate Advisory: Keycloak Open Redirect vulnerability

CVSS3: 4.6
около 2 лет назад
github логотип
GHSA-3p74-pwfx-pcgr

The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3p74-fjhf-m5jm

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3p73-mm7v-4f6m

DoS vulnerability in MaliciousCode filter

CVSS3: 4.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-3p73-75xq-v9wv

An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

CVSS3: 7.4
1%
Низкий
почти 2 года назад
github логотип
GHSA-3p72-rmv7-7jc9

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p72-mm77-r69w

Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3p6x-mw8p-qjh9

An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.

CVSS3: 4.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-3p6x-7vmm-w6rr

The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p6w-gv5g-xjw9

MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string

CVSS3: 8
0%
Низкий
4 месяца назад
github логотип
GHSA-3p6w-82x2-65rf

An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files, aka 'Microsoft Office Click-to-Run Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16934, CVE-2020-16955.

CVSS3: 7.8
11%
Средний
больше 3 лет назад
github логотип
GHSA-3p6v-qx4g-mwhp

A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p6v-hrg8-8qj7

@mozilla/readability Denial of Service through Regex

11 месяцев назад
github логотип
GHSA-3p6v-922c-mrw6

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later

CVSS3: 7.2
0%
Низкий
11 месяцев назад
github логотип
GHSA-3p6r-56fp-3cwc

Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p6r-3579-wxm9

Cross-Site Request Forgery (CSRF) vulnerability in aakash1911 WP likes allows Reflected XSS. This issue affects WP likes: from n/a through 3.1.1.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-3p6q-h5pg-fcv3

Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3p6p-pp2j-3qr6

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForm field that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

21%
Средний
больше 3 лет назад
github логотип
GHSA-3p6p-6hwj-52g9

A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser.

CVSS3: 6.1
0%
Низкий
5 месяцев назад

Уязвимостей на страницу