Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3cg7-x7vx-225c

11 месяцев назад

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cg7-p7mp-2hcx

больше 3 лет назад

Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cg6-xv3h-2wj2

больше 1 года назад

An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3cg5-88qj-6x5f

почти 4 года назад

Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cg5-6rj7-9c9c

около 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cg4-vq2p-w876

почти 4 года назад

CRLF injection vulnerability in help.php in Russcom Network Loginphp allows remote attackers to spoof e-mails and inject MIME headers via CRLF sequences in the email address.

EPSS: Низкий
github логотип

GHSA-3cg4-jf33-6fwh

10 месяцев назад

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 8
EPSS: Средний
github логотип

GHSA-3cg3-wjrx-v9jw

больше 3 лет назад

Multiple format string vulnerabilities in White_Dune before 0.29beta851 have unspecified impact and attack vectors, a different vulnerability than CVE-2008-0101.

EPSS: Низкий
github логотип

GHSA-3cg3-w3v4-rw4g

почти 4 года назад

The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel's return from (1) an interrupt, (2) a trap, or (3) a system call.

EPSS: Низкий
github логотип

GHSA-3cg3-vqjf-x53x

больше 3 лет назад

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-3cg3-jw2v-vmvx

4 месяца назад

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deference. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3cg3-3mmr-w8hj

6 месяцев назад

Mattermost Confluence Plugin has Improper Validation of Specified Type of Input

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3cg2-pp2v-hxh3

почти 4 года назад

SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter.

EPSS: Низкий
github логотип

GHSA-3cfx-qf53-8h6m

больше 3 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cfx-pw87-g2gg

почти 4 года назад

Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."

EPSS: Низкий
github логотип

GHSA-3cfw-j97c-6cfv

почти 4 года назад

Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to execute arbitrary code via a long Computer value in an .ipj project file.

EPSS: Средний
github логотип

GHSA-3cfw-2rv8-9rx3

больше 3 лет назад

An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3cfv-7x3j-7m2c

больше 2 лет назад

Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3cfv-64r8-pvrv

почти 4 года назад

Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code using buffer overflows via unknown vectors that cause (1) qmaster or (2) execd to terminate.

EPSS: Низкий
github логотип

GHSA-3cfr-rpp6-j86f

больше 3 лет назад

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3cg7-x7vx-225c

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3cg7-p7mp-2hcx

Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cg6-xv3h-2wj2

An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

CVSS3: 7.1
2%
Низкий
больше 1 года назад
github логотип
GHSA-3cg5-88qj-6x5f

Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-3cg5-6rj7-9c9c

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.1.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3cg4-vq2p-w876

CRLF injection vulnerability in help.php in Russcom Network Loginphp allows remote attackers to spoof e-mails and inject MIME headers via CRLF sequences in the email address.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cg4-jf33-6fwh

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 8
24%
Средний
10 месяцев назад
github логотип
GHSA-3cg3-wjrx-v9jw

Multiple format string vulnerabilities in White_Dune before 0.29beta851 have unspecified impact and attack vectors, a different vulnerability than CVE-2008-0101.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cg3-w3v4-rw4g

The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel's return from (1) an interrupt, (2) a trap, or (3) a system call.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cg3-vqjf-x53x

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.

CVSS3: 9.1
11%
Средний
больше 3 лет назад
github логотип
GHSA-3cg3-jw2v-vmvx

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deference. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5
0%
Низкий
4 месяца назад
github логотип
GHSA-3cg3-3mmr-w8hj

Mattermost Confluence Plugin has Improper Validation of Specified Type of Input

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3cg2-pp2v-hxh3

SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cfx-qf53-8h6m

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cfx-pw87-g2gg

Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cfw-j97c-6cfv

Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to execute arbitrary code via a long Computer value in an .ipj project file.

67%
Средний
почти 4 года назад
github логотип
GHSA-3cfw-2rv8-9rx3

An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3cfv-7x3j-7m2c

Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cfv-64r8-pvrv

Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code using buffer overflows via unknown vectors that cause (1) qmaster or (2) execd to terminate.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3cfr-rpp6-j86f

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.

CVSS3: 7.5
11%
Средний
больше 3 лет назад

Уязвимостей на страницу