Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 672

Количество 315 672

github логотип

GHSA-3832-gg43-7qm4

больше 1 года назад

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3832-cq7m-8xc3

больше 1 года назад

A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument razorpayKeyId leads to information disclosure. The attack can be launched remotely. It is recommended to upgrade the affected component. The identifier VDB-265981 was assigned to this vulnerability.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-3832-9276-x7gf

почти 4 года назад

Improper Certificate Validation in Apache Commons HttpClient

EPSS: Низкий
github логотип

GHSA-382x-f95g-95c7

больше 3 лет назад

The Bunny Run (aka com.stargirlgames.google.bunnyrun) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-382x-6jh5-7rh9

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Get rid of the nfsd4_legacy_tracking_ops->init() call in check_for_legacy_methods(). That will be handled in the caller (nfsd4_client_tracking_init()). Otherwise, we'll wind up calling nfsd4_legacy_tracking_ops->init() twice, and the second time we'll trigger the BUG_ON() in nfsd4_init_recdir().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-382w-xv39-jcj4

почти 4 года назад

Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.

EPSS: Низкий
github логотип

GHSA-382w-v37j-732p

больше 3 лет назад

A vulnerability, which was classified as problematic, has been found in Teleopti WFM up to 7.1.0. Affected by this issue is some unknown functionality of the component Administration. The manipulation as part of JSON leads to information disclosure (Credentials). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-382w-q3v4-xc76

больше 1 года назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted texture may lead to unexpected app termination.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-382w-3hrq-xh95

больше 3 лет назад

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

EPSS: Низкий
github логотип

GHSA-382v-j99g-hw2p

больше 2 лет назад

A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243592.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-382v-gxj9-ffhc

почти 4 года назад

Moodle uses predictable password-recovery tokens

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-382v-cr8r-vrf3

больше 2 лет назад

In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-382v-9f98-h3x7

больше 3 лет назад

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.

EPSS: Низкий
github логотип

GHSA-382v-76mx-pqx3

19 дней назад

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-382v-24ph-q459

почти 3 года назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-382r-w7px-7vf7

больше 3 лет назад

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server, a different vulnerability than CVE-2015-4880.

EPSS: Низкий
github логотип

GHSA-382q-fpqh-29f7

9 дней назад

`polymarket-clients-sdk` was removed from crates.io for malicious code

EPSS: Низкий
github логотип

GHSA-382q-3qj5-29mx

больше 3 лет назад

Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Низкий
github логотип

GHSA-382p-crwp-jf65

больше 3 лет назад

Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-382m-qj75-vx5v

больше 3 лет назад

inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3832-gg43-7qm4

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3832-cq7m-8xc3

A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument razorpayKeyId leads to information disclosure. The attack can be launched remotely. It is recommended to upgrade the affected component. The identifier VDB-265981 was assigned to this vulnerability.

CVSS3: 5.3
36%
Средний
больше 1 года назад
github логотип
GHSA-3832-9276-x7gf

Improper Certificate Validation in Apache Commons HttpClient

1%
Низкий
почти 4 года назад
github логотип
GHSA-382x-f95g-95c7

The Bunny Run (aka com.stargirlgames.google.bunnyrun) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-382x-6jh5-7rh9

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Get rid of the nfsd4_legacy_tracking_ops->init() call in check_for_legacy_methods(). That will be handled in the caller (nfsd4_client_tracking_init()). Otherwise, we'll wind up calling nfsd4_legacy_tracking_ops->init() twice, and the second time we'll trigger the BUG_ON() in nfsd4_init_recdir().

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-382w-xv39-jcj4

Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.

2%
Низкий
почти 4 года назад
github логотип
GHSA-382w-v37j-732p

A vulnerability, which was classified as problematic, has been found in Teleopti WFM up to 7.1.0. Affected by this issue is some unknown functionality of the component Administration. The manipulation as part of JSON leads to information disclosure (Credentials). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-382w-q3v4-xc76

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted texture may lead to unexpected app termination.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-382w-3hrq-xh95

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-382v-j99g-hw2p

A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243592.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-382v-gxj9-ffhc

Moodle uses predictable password-recovery tokens

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-382v-cr8r-vrf3

In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-382v-9f98-h3x7

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-382v-76mx-pqx3

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.

CVSS3: 6.5
0%
Низкий
19 дней назад
github логотип
GHSA-382v-24ph-q459

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-382r-w7px-7vf7

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server, a different vulnerability than CVE-2015-4880.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-382q-fpqh-29f7

`polymarket-clients-sdk` was removed from crates.io for malicious code

9 дней назад
github логотип
GHSA-382q-3qj5-29mx

Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-382p-crwp-jf65

Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-382m-qj75-vx5v

inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу