Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 330

Количество 301 330

github логотип

GHSA-2753-chm6-qr3j

больше 3 лет назад

IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.

EPSS: Низкий
github логотип

GHSA-2753-9vwc-54j2

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: NFSv4.2 fix problems with __nfs42_ssc_open A destination server while doing a COPY shouldn't accept using the passed in filehandle if its not a regular filehandle. If alloc_file_pseudo() has failed, we need to decrement a reference on the newly created inode, otherwise it leaks.

EPSS: Низкий
github логотип

GHSA-2753-42q2-rqvx

больше 3 лет назад

mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.

EPSS: Низкий
github логотип

GHSA-2753-2vv3-rp6p

почти 3 года назад

Raw Image Extension Remote Code Execution Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2752-qr49-v2qw

больше 3 лет назад

Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.

EPSS: Низкий
github логотип

GHSA-2752-9rh4-pmmr

больше 3 лет назад

Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the Administrator with the XSS to steal cookies. A ticket can be created with a XSS payload in the subject field. This attack appears to be exploitable via <svg/onload=alert(1)> as the payload user on the Subject field. This makes it possible to obtain the cookies of all users that have permission to view the tickets. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2752-8gwx-98x4

больше 3 лет назад

IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.

EPSS: Средний
github логотип

GHSA-2752-84hq-w9hq

больше 3 лет назад

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMware Remote Console for Mac or Horizon Client for Mac is installed.

EPSS: Низкий
github логотип

GHSA-274x-fvxh-wq55

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in com_contact in Joomla! CMS 3.1.2 through 3.2.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-274x-796c-pwp4

больше 3 лет назад

Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote attackers to gain access to PDF files that are being processed within that session.

EPSS: Низкий
github логотип

GHSA-274w-x34j-q3q6

больше 3 лет назад

monotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command.

EPSS: Низкий
github логотип

GHSA-274w-mwh6-wgm3

больше 3 лет назад

SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.

EPSS: Низкий
github логотип

GHSA-274w-2mj6-9594

больше 3 лет назад

Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-274w-2j5w-m2xj

больше 3 лет назад

Magento 2 Community Edition Information Disclosure

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-274v-r947-v34r

больше 3 лет назад

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

EPSS: Низкий
github логотип

GHSA-274v-mgcv-cm8j

10 месяцев назад

Argo CD GitOps Engine does not scrub secret values from patch errors

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-274v-224f-5f86

около 1 месяца назад

Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-274r-p6v6-fhh4

больше 3 лет назад

Spring Batch Admin vulnerable to Cross-site request forgery (CSRF) in the file upload functionality

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-274r-2m95-945c

больше 3 лет назад

A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-274q-q482-p3xq

около 2 месяцев назад

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2753-chm6-qr3j

IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2753-9vwc-54j2

In the Linux kernel, the following vulnerability has been resolved: NFSv4.2 fix problems with __nfs42_ssc_open A destination server while doing a COPY shouldn't accept using the passed in filehandle if its not a regular filehandle. If alloc_file_pseudo() has failed, we need to decrement a reference on the newly created inode, otherwise it leaks.

0%
Низкий
5 месяцев назад
github логотип
GHSA-2753-42q2-rqvx

mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-2753-2vv3-rp6p

Raw Image Extension Remote Code Execution Vulnerability.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2752-qr49-v2qw

Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2752-9rh4-pmmr

Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the Administrator with the XSS to steal cookies. A ticket can be created with a XSS payload in the subject field. This attack appears to be exploitable via <svg/onload=alert(1)> as the payload user on the Subject field. This makes it possible to obtain the cookies of all users that have permission to view the tickets. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2752-8gwx-98x4

IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.

31%
Средний
больше 3 лет назад
github логотип
GHSA-2752-84hq-w9hq

VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMware Remote Console for Mac or Horizon Client for Mac is installed.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-274x-fvxh-wq55

Cross-site scripting (XSS) vulnerability in com_contact in Joomla! CMS 3.1.2 through 3.2.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-274x-796c-pwp4

Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote attackers to gain access to PDF files that are being processed within that session.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-274w-x34j-q3q6

monotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-274w-mwh6-wgm3

SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-274w-2mj6-9594

Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-274w-2j5w-m2xj

Magento 2 Community Edition Information Disclosure

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-274v-r947-v34r

OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege

1%
Низкий
больше 3 лет назад
github логотип
GHSA-274v-mgcv-cm8j

Argo CD GitOps Engine does not scrub secret values from patch errors

CVSS3: 6.8
10 месяцев назад
github логотип
GHSA-274v-224f-5f86

Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

CVSS3: 5.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-274r-p6v6-fhh4

Spring Batch Admin vulnerable to Cross-site request forgery (CSRF) in the file upload functionality

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-274r-2m95-945c

A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.

CVSS3: 9.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-274q-q482-p3xq

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу