Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-32h6-xpp4-6279

больше 3 лет назад

DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user defined buffer size. If the size of the buffer is less than 512 bytes, then the driver will overwrite the next pool header if there is one next to the user buffer's pool.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32h6-6w8m-mc99

2 месяца назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-32h6-678g-3xvh

больше 3 лет назад

Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-32h5-mfcc-v69p

больше 3 лет назад

Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622.

EPSS: Средний
github логотип

GHSA-32h4-r3wm-53g5

больше 2 лет назад

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-32h3-3qq6-92x8

почти 4 года назад

Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.

EPSS: Низкий
github логотип

GHSA-32h2-wrvr-hg99

больше 3 лет назад

Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allow attackers to bypass intended access restrictions and execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-32h2-7245-4mh4

около 2 лет назад

Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-32h2-5pxq-28cx

больше 3 лет назад

Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-32gx-rhqv-h4gm

5 месяцев назад

Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scripting (XSS). The vulnerability exists in the /ip.php endpoint, which processes and displays the X-Forwarded-For HTTP header without proper sanitization or output encoding. This allows an attacker to inject malicious JavaScript code that will execute in visitor browsers.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-32gw-rm39-g9p5

больше 3 лет назад

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle CRM Technical Foundation. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-32gw-r878-mrx5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action.

EPSS: Низкий
github логотип

GHSA-32gw-7vj2-p573

больше 3 лет назад

VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of service (VMX process disruption) by using an invalid port.

EPSS: Низкий
github логотип

GHSA-32gv-r223-hpr7

6 месяцев назад

A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload a crafted HTML file containing malicious content, such as a fake login form for credential harvesting or scripts for Cross-Site Scripting (XSS) attacks. Since the content is served from a trusted domain, it significantly increases the likelihood of successful phishing or script execution against other users.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-32gv-f76r-vj5h

больше 3 лет назад

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2389 and CVE-2015-2411.

EPSS: Средний
github логотип

GHSA-32gv-6cf3-wcmq

почти 4 года назад

HTTP/2 DoS Attacks: Ping, Reset, and Settings Floods

EPSS: Низкий
github логотип

GHSA-32gv-685r-xv99

больше 3 лет назад

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32gr-x76g-267w

почти 3 года назад

SQL injection in webbuilders-group silverstripe-kapost-bridge

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-32gr-j934-98f7

почти 3 года назад

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-32gr-4cq6-5w5q

почти 3 года назад

rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32h6-xpp4-6279

DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user defined buffer size. If the size of the buffer is less than 512 bytes, then the driver will overwrite the next pool header if there is one next to the user buffer's pool.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32h6-6w8m-mc99

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
2 месяца назад
github логотип
GHSA-32h6-678g-3xvh

Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.

CVSS3: 9.8
18%
Средний
больше 3 лет назад
github логотип
GHSA-32h5-mfcc-v69p

Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622.

38%
Средний
больше 3 лет назад
github логотип
GHSA-32h4-r3wm-53g5

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVSS3: 5.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32h3-3qq6-92x8

Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32h2-wrvr-hg99

Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allow attackers to bypass intended access restrictions and execute arbitrary code via unspecified vectors.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-32h2-7245-4mh4

Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

CVSS3: 6.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-32h2-5pxq-28cx

Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-32gx-rhqv-h4gm

Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scripting (XSS). The vulnerability exists in the /ip.php endpoint, which processes and displays the X-Forwarded-For HTTP header without proper sanitization or output encoding. This allows an attacker to inject malicious JavaScript code that will execute in visitor browsers.

CVSS3: 6.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-32gw-rm39-g9p5

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle CRM Technical Foundation. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
больше 3 лет назад
github логотип
GHSA-32gw-r878-mrx5

Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in an addcat action.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-32gw-7vj2-p573

VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of service (VMX process disruption) by using an invalid port.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32gv-r223-hpr7

A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload a crafted HTML file containing malicious content, such as a fake login form for credential harvesting or scripts for Cross-Site Scripting (XSS) attacks. Since the content is served from a trusted domain, it significantly increases the likelihood of successful phishing or script execution against other users.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-32gv-f76r-vj5h

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2389 and CVE-2015-2411.

28%
Средний
больше 3 лет назад
github логотип
GHSA-32gv-6cf3-wcmq

HTTP/2 DoS Attacks: Ping, Reset, and Settings Floods

почти 4 года назад
github логотип
GHSA-32gv-685r-xv99

An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32gr-x76g-267w

SQL injection in webbuilders-group silverstripe-kapost-bridge

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-32gr-j934-98f7

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-32gr-4cq6-5w5q

rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters

CVSS3: 6.1
0%
Низкий
почти 3 года назад

Уязвимостей на страницу