Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-36p7-pvq8-jjmx

6 месяцев назад

Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight allows Object Injection. This issue affects Employee Spotlight: from n/a through 5.1.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-36p7-jqv6-r5mj

больше 3 лет назад

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36p7-fgf7-w6rh

больше 3 лет назад

Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Banking Payments accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36p6-h78p-cx2w

1 день назад

Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memory integrity

EPSS: Низкий
github логотип

GHSA-36p4-cjjg-rccj

почти 2 года назад

In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36p3-wjmg-h94x

почти 4 года назад

Remote Code Execution in Spring Framework

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-36p3-j543-mpj6

почти 4 года назад

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36p3-3fj3-g9p5

больше 1 года назад

SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36p2-p85p-3g3q

почти 4 года назад

onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.

EPSS: Низкий
github логотип

GHSA-36p2-cfmm-wp8w

28 дней назад

The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36p2-8879-3c27

почти 4 года назад

A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36p2-8566-7frq

больше 2 лет назад

The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36p2-3xmm-mxrv

около 3 лет назад

WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36mx-gp2g-xh52

больше 3 лет назад

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the internal representation of raster data. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36mw-gq75-9mwg

больше 3 лет назад

IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36mv-7364-j7gh

6 месяцев назад

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36mr-q5jp-rfp3

больше 3 лет назад

A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long` as well as a shift exponent that is too large for 64-bit type. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-36mr-3fcp-m422

почти 2 года назад

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-36mq-qwm2-6rpp

больше 3 лет назад

Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet.

EPSS: Низкий
github логотип

GHSA-36mq-q7hj-fg2m

больше 3 лет назад

Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36p7-pvq8-jjmx

Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight allows Object Injection. This issue affects Employee Spotlight: from n/a through 5.1.1.

CVSS3: 8.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-36p7-jqv6-r5mj

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restrictions when using a deploy token

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36p7-fgf7-w6rh

Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Banking Payments accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-36p6-h78p-cx2w

Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memory integrity

0%
Низкий
1 день назад
github логотип
GHSA-36p4-cjjg-rccj

In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-36p3-wjmg-h94x

Remote Code Execution in Spring Framework

CVSS3: 9.8
94%
Критический
почти 4 года назад
github логотип
GHSA-36p3-j543-mpj6

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-36p3-3fj3-g9p5

SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting attacks.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-36p2-p85p-3g3q

onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-36p2-cfmm-wp8w

The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 8.8
0%
Низкий
28 дней назад
github логотип
GHSA-36p2-8879-3c27

A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-36p2-8566-7frq

The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36p2-3xmm-mxrv

WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-36mx-gp2g-xh52

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the internal representation of raster data. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-36mw-gq75-9mwg

IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36mv-7364-j7gh

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-36mr-q5jp-rfp3

A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long` as well as a shift exponent that is too large for 64-bit type. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36mr-3fcp-m422

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

CVSS3: 6.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-36mq-qwm2-6rpp

Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-36mq-q7hj-fg2m

Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу