Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-33p4-33f5-c62r

больше 3 лет назад

Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38653.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33p3-36hv-c9p7

больше 3 лет назад

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33p2-5mfj-r94r

больше 3 лет назад

CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: Низкий
github логотип

GHSA-33p2-27pp-3pqr

почти 4 года назад

Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

EPSS: Низкий
github логотип

GHSA-33mx-vpmc-fg9c

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Jenst Add to Header allows Stored XSS. This issue affects Add to Header: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-33mx-q46m-2wfr

почти 4 года назад

Pramati Server 3.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

EPSS: Низкий
github логотип

GHSA-33mw-q7rj-mjwj

5 дней назад

Django has Inefficient Algorithmic Complexity

EPSS: Низкий
github логотип

GHSA-33mw-354r-24rw

около 4 лет назад

A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.

EPSS: Низкий
github логотип

GHSA-33mv-fjxj-2mx6

около 1 года назад

Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33mv-8xj7-9fx2

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33mr-h3pf-4jg7

около 3 лет назад

RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH service port to disrupt service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33mq-pfqq-c55m

около 4 лет назад

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

EPSS: Низкий
github логотип

GHSA-33mq-p8m3-73xj

больше 1 года назад

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-33mq-jqvv-g676

больше 3 лет назад

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth" component. It allows attackers to obtain sensitive kernel memory-layout information via a crafted app that leverages device properties.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33mq-62qg-c5mm

3 месяца назад

ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source Edition < 16.5.beta1 contain an SQL injection vulnerability in the login functionality. The application does not properly validate the account parameter on /zentao/user-login.html before using it in a database query. A remote unauthenticated attacker can exploit this issue to execute crafted SQL expressions and retrieve sensitive information from the backend database, including user and application data. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-07 UTC.

EPSS: Низкий
github логотип

GHSA-33mp-r2vv-f8h8

больше 3 лет назад

XySSL before 0.9 allows remote attackers to cause a denial of service (infinite loop) via an X.509 certificate that does not pass the RSA signature check during verification.

EPSS: Низкий
github логотип

GHSA-33mp-cm7f-r29g

больше 3 лет назад

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

EPSS: Низкий
github логотип

GHSA-33mm-q6vp-mvmv

больше 3 лет назад

CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user under which CouchDB runs, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows a CouchDB admin user to gain arbitrary remote code execution, bypassing CVE-2017-12636 and CVE-2018-8007.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-33mm-j3x7-xq2g

больше 3 лет назад

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3201, CVE-2013-3206, CVE-2013-3207, and CVE-2013-3209.

EPSS: Средний
github логотип

GHSA-33mm-hrgw-4v3f

больше 3 лет назад

A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33p4-33f5-c62r

Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38653.

CVSS3: 7.8
8%
Низкий
больше 3 лет назад
github логотип
GHSA-33p3-36hv-c9p7

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 8.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-33p2-5mfj-r94r

CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33p2-27pp-3pqr

Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

0%
Низкий
почти 4 года назад
github логотип
GHSA-33mx-vpmc-fg9c

Cross-Site Request Forgery (CSRF) vulnerability in Jenst Add to Header allows Stored XSS. This issue affects Add to Header: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-33mx-q46m-2wfr

Pramati Server 3.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

0%
Низкий
почти 4 года назад
github логотип
GHSA-33mw-q7rj-mjwj

Django has Inefficient Algorithmic Complexity

0%
Низкий
5 дней назад
github логотип
GHSA-33mw-354r-24rw

A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.

0%
Низкий
около 4 лет назад
github логотип
GHSA-33mv-fjxj-2mx6

Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled

CVSS3: 5.3
1%
Низкий
около 1 года назад
github логотип
GHSA-33mv-8xj7-9fx2

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-33mr-h3pf-4jg7

RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH service port to disrupt service.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-33mq-pfqq-c55m

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

3%
Низкий
около 4 лет назад
github логотип
GHSA-33mq-p8m3-73xj

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.

CVSS3: 7.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-33mq-jqvv-g676

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth" component. It allows attackers to obtain sensitive kernel memory-layout information via a crafted app that leverages device properties.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33mq-62qg-c5mm

ZenTao Biz < 6.5, ZenTao Max < 3.0, ZenTao Open Source Edition < 16.5, and ZenTao Open Source Edition < 16.5.beta1 contain an SQL injection vulnerability in the login functionality. The application does not properly validate the account parameter on /zentao/user-login.html before using it in a database query. A remote unauthenticated attacker can exploit this issue to execute crafted SQL expressions and retrieve sensitive information from the backend database, including user and application data. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-07 UTC.

0%
Низкий
3 месяца назад
github логотип
GHSA-33mp-r2vv-f8h8

XySSL before 0.9 allows remote attackers to cause a denial of service (infinite loop) via an X.509 certificate that does not pass the RSA signature check during verification.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33mp-cm7f-r29g

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33mm-q6vp-mvmv

CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user under which CouchDB runs, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows a CouchDB admin user to gain arbitrary remote code execution, bypassing CVE-2017-12636 and CVE-2018-8007.

CVSS3: 7.2
6%
Низкий
больше 3 лет назад
github логотип
GHSA-33mm-j3x7-xq2g

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3201, CVE-2013-3206, CVE-2013-3207, and CVE-2013-3209.

41%
Средний
больше 3 лет назад
github логотип
GHSA-33mm-hrgw-4v3f

A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу