Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 538

Количество 301 538

github логотип

GHSA-27xw-q7rh-9mrw

больше 3 лет назад

A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27xw-phm9-jmx3

больше 3 лет назад

The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.

EPSS: Низкий
github логотип

GHSA-27xw-p8v6-9jjr

почти 7 лет назад

Spring Security vulnerable to Authorization Bypass

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-27xw-5882-cqhf

больше 3 лет назад

Windows Graphics Component Remote Code Execution Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27xv-cgv3-x596

больше 3 лет назад

PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.

EPSS: Низкий
github логотип

GHSA-27xv-9p99-hj75

больше 3 лет назад

Vidalia bundle before 0.1.2.18, when running on Windows, installs Privoxy with a configuration file (config.txt or config) that contains an insecure enable-remote-http-toggle setting, which allows remote attackers to bypass intended access restrictions and modify configuration.

EPSS: Низкий
github логотип

GHSA-27xr-j3f5-jw66

больше 3 лет назад

An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27xr-5mwg-m2hh

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL associated with the management screen.

EPSS: Низкий
github логотип

GHSA-27xq-w3jc-436c

почти 2 года назад

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-27xq-hgcj-7p95

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WisdmLabs Edwiser Bridge allows Reflected XSS. This issue affects Edwiser Bridge: from n/a through 3.0.8.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-27xp-xm97-jqhm

больше 3 лет назад

KENT-WEB Joyful Note before 5.3 allows remote attackers to delete files or write to files, and consequently execute arbitrary code, via vectors involving an article.

EPSS: Низкий
github логотип

GHSA-27xp-g53c-xc82

больше 2 лет назад

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-27xm-pjj9-xmm8

больше 3 лет назад

The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice delsolrecordedvideo_func function path traversal vulnerability.

EPSS: Низкий
github логотип

GHSA-27xm-379m-vgx5

4 месяца назад

The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-27xj-rqx5-2255

больше 5 лет назад

jackson-databind mishandles the interaction between serialization gadgets and typing

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-27xj-24rw-8hqp

больше 3 лет назад

The aio_setup_ring function in Linux kernel does not properly initialize a variable, which allows local users to cause a denial of service (crash) via an unspecified error path that causes an incorrect free operation.

EPSS: Низкий
github логотип

GHSA-27xh-jm24-mhr6

больше 3 лет назад

Adobe Premiere Pro versions 14.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

EPSS: Низкий
github логотип

GHSA-27xg-jff9-57pq

больше 3 лет назад

Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization vulnerability."

EPSS: Низкий
github логотип

GHSA-27xc-49hc-r9xm

больше 3 лет назад

An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.

EPSS: Низкий
github логотип

GHSA-27xc-468w-vq62

около 1 месяца назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27xw-q7rh-9mrw

A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-27xw-phm9-jmx3

The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-27xw-p8v6-9jjr

Spring Security vulnerable to Authorization Bypass

CVSS3: 7.4
0%
Низкий
почти 7 лет назад
github логотип
GHSA-27xw-5882-cqhf

Windows Graphics Component Remote Code Execution Vulnerability.

CVSS3: 7.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-27xv-cgv3-x596

PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xv-9p99-hj75

Vidalia bundle before 0.1.2.18, when running on Windows, installs Privoxy with a configuration file (config.txt or config) that contains an insecure enable-remote-http-toggle setting, which allows remote attackers to bypass intended access restrictions and modify configuration.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xr-j3f5-jw66

An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xr-5mwg-m2hh

Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL associated with the management screen.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xq-w3jc-436c

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.

CVSS3: 10
5%
Низкий
почти 2 года назад
github логотип
GHSA-27xq-hgcj-7p95

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WisdmLabs Edwiser Bridge allows Reflected XSS. This issue affects Edwiser Bridge: from n/a through 3.0.8.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-27xp-xm97-jqhm

KENT-WEB Joyful Note before 5.3 allows remote attackers to delete files or write to files, and consequently execute arbitrary code, via vectors involving an article.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-27xp-g53c-xc82

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27xm-pjj9-xmm8

The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice delsolrecordedvideo_func function path traversal vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xm-379m-vgx5

The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-27xj-rqx5-2255

jackson-databind mishandles the interaction between serialization gadgets and typing

CVSS3: 8.1
2%
Низкий
больше 5 лет назад
github логотип
GHSA-27xj-24rw-8hqp

The aio_setup_ring function in Linux kernel does not properly initialize a variable, which allows local users to cause a denial of service (crash) via an unspecified error path that causes an incorrect free operation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xh-jm24-mhr6

Adobe Premiere Pro versions 14.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-27xg-jff9-57pq

Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization vulnerability."

2%
Низкий
больше 3 лет назад
github логотип
GHSA-27xc-49hc-r9xm

An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-27xc-468w-vq62

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу