Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-35jm-qwg4-c8wj

7 месяцев назад

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35jj-wx47-4w8r

почти 2 года назад

WeasyPrint allows the attachment of arbitrary files and URLs to a PDF

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-35jj-vqcf-f2jf

почти 3 года назад

Hidden fields can be leaked on readable collections in Payload

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-35jj-h5xp-mhvc

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SliceWP allows Reflected XSS.This issue affects SliceWP: from n/a through 1.1.18.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35jj-9635-2vjm

больше 3 лет назад

Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic.

EPSS: Низкий
github логотип

GHSA-35jh-r3h4-6jhm

почти 5 лет назад

Command Injection in lodash

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-35jh-p5wf-6gg4

больше 3 лет назад

Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents.

EPSS: Низкий
github логотип

GHSA-35jh-g8qg-jgf5

почти 4 года назад

Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.

EPSS: Низкий
github логотип

GHSA-35jh-78c5-6rfj

больше 3 лет назад

IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35jh-65jp-wj73

больше 3 лет назад

Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35jh-2r79-5r66

больше 3 лет назад

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-35jg-8pwm-5q3v

больше 3 лет назад

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

EPSS: Низкий
github логотип

GHSA-35jf-jfrv-9p25

больше 3 лет назад

The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35jf-fw8j-m7v3

почти 4 года назад

Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.

EPSS: Низкий
github логотип

GHSA-35jc-cjp6-54c4

больше 3 лет назад

Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35j8-v8xw-wrrr

больше 3 лет назад

Stack-based buffer overflow in the smc program in smcFanControl 2.1.2 allows local users to execute arbitrary code and gain privileges via a long -k option.

EPSS: Низкий
github логотип

GHSA-35j6-m37x-rh4q

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.

EPSS: Низкий
github логотип

GHSA-35j6-7x52-47f7

больше 3 лет назад

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

EPSS: Низкий
github логотип

GHSA-35j6-76jp-jqcj

больше 3 лет назад

An issue was discovered in Sysdig through 0.24.2, as used in Falco through 0.14.0 and other products. A bypass allows local users to run malicious code without being detected because record_event_consumer in driver/main.c in sysdig-probe.ko (and falco-probe.ko) mishandles a free space calculation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35j5-m29r-xfq5

больше 2 лет назад

XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35jm-qwg4-c8wj

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-35jj-wx47-4w8r

WeasyPrint allows the attachment of arbitrary files and URLs to a PDF

CVSS3: 7.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-35jj-vqcf-f2jf

Hidden fields can be leaked on readable collections in Payload

CVSS3: 7.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-35jj-h5xp-mhvc

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SliceWP allows Reflected XSS.This issue affects SliceWP: from n/a through 1.1.18.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-35jj-9635-2vjm

Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-35jh-r3h4-6jhm

Command Injection in lodash

CVSS3: 7.2
1%
Низкий
почти 5 лет назад
github логотип
GHSA-35jh-p5wf-6gg4

Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via vectors involving multiple adoptions and empty documents.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-35jh-g8qg-jgf5

Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.

5%
Низкий
почти 4 года назад
github логотип
GHSA-35jh-78c5-6rfj

IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-35jh-65jp-wj73

Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35jh-2r79-5r66

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

CVSS3: 7.5
94%
Критический
больше 3 лет назад
github логотип
GHSA-35jg-8pwm-5q3v

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-35jf-jfrv-9p25

The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-35jf-fw8j-m7v3

Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.

0%
Низкий
почти 4 года назад
github логотип
GHSA-35jc-cjp6-54c4

Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-35j8-v8xw-wrrr

Stack-based buffer overflow in the smc program in smcFanControl 2.1.2 allows local users to execute arbitrary code and gain privileges via a long -k option.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-35j6-m37x-rh4q

Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.

1%
Низкий
почти 4 года назад
github логотип
GHSA-35j6-7x52-47f7

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-35j6-76jp-jqcj

An issue was discovered in Sysdig through 0.24.2, as used in Falco through 0.14.0 and other products. A bypass allows local users to run malicious code without being detected because record_event_consumer in driver/main.c in sysdig-probe.ko (and falco-probe.ko) mishandles a free space calculation.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-35j5-m29r-xfq5

XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro

CVSS3: 8.8
10%
Низкий
больше 2 лет назад

Уязвимостей на страницу