Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3394-h5f6-fpwc

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for 2.6.

EPSS: Низкий
github логотип

GHSA-3394-cqqj-2g45

больше 1 года назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3394-6qr2-55gf

больше 3 лет назад

Unspecified vulnerability in the MICROS Retail component in Oracle Retail Applications Xstore: 3.2.1, 3.4.2, 3.5.0, 4.0.1, 4.5.1, 4.8.0, 5.0.3, 5.5.3, 6.0.6, and 6.5.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Xstore Point of Sale.

EPSS: Низкий
github логотип

GHSA-3394-4x69-rcm8

больше 3 лет назад

The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.

EPSS: Низкий
github логотип

GHSA-3393-xjfj-fh77

7 месяцев назад

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3393-r4p5-vhqh

больше 3 лет назад

Gitea Allows 1FA Even for 2FA-Enrolled Accounts

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3393-hvrj-w7v3

больше 4 лет назад

Denial of Service in Elasticsearch

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3393-gh57-mr75

почти 4 года назад

The rsh/rlogin service is running.

EPSS: Средний
github логотип

GHSA-3393-4w74-98fc

больше 3 лет назад

Untrusted search path vulnerability in Music Center for PC version 1.0.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-338x-rqm6-3p3h

почти 4 года назад

Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0511, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.

EPSS: Средний
github логотип

GHSA-338x-q4qx-prw7

около 2 лет назад

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-338x-j9c9-2c8v

около 2 месяцев назад

This issue was addressed with improved URL validation. This issue is fixed in macOS Tahoe 26.2, Safari 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-338x-hfx8-vx9x

больше 1 года назад

Apache Karaf Cave: Cave SSRF and arbitrary file access

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-338x-7hhr-q38p

больше 3 лет назад

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

EPSS: Низкий
github логотип

GHSA-338w-rmx2-4pjj

почти 4 года назад

SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.

EPSS: Низкий
github логотип

GHSA-338v-jj52-qpg4

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fintelligence Fintelligence Calculator allows Stored XSS.This issue affects Fintelligence Calculator: from n/a through 1.0.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-338v-3958-8v8r

больше 5 лет назад

Information disclosure in JBoss Weld

EPSS: Низкий
github логотип

GHSA-338r-39f8-6rqm

почти 4 года назад

FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo function.

EPSS: Низкий
github логотип

GHSA-338q-vjff-j9cr

больше 3 лет назад

An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-338q-gcv2-fx6x

больше 3 лет назад

Unspecified vulnerability in the Oracle Financial Consolidation Hub component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Business Intelligence.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3394-h5f6-fpwc

Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for 2.6.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3394-cqqj-2g45

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

CVSS3: 8.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-3394-6qr2-55gf

Unspecified vulnerability in the MICROS Retail component in Oracle Retail Applications Xstore: 3.2.1, 3.4.2, 3.5.0, 4.0.1, 4.5.1, 4.8.0, 5.0.3, 5.5.3, 6.0.6, and 6.5.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Xstore Point of Sale.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3394-4x69-rcm8

The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3393-xjfj-fh77

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3393-r4p5-vhqh

Gitea Allows 1FA Even for 2FA-Enrolled Accounts

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3393-hvrj-w7v3

Denial of Service in Elasticsearch

CVSS3: 5.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3393-gh57-mr75

The rsh/rlogin service is running.

50%
Средний
почти 4 года назад
github логотип
GHSA-3393-4w74-98fc

Untrusted search path vulnerability in Music Center for PC version 1.0.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-338x-rqm6-3p3h

Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0511, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.

13%
Средний
почти 4 года назад
github логотип
GHSA-338x-q4qx-prw7

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-338x-j9c9-2c8v

This issue was addressed with improved URL validation. This issue is fixed in macOS Tahoe 26.2, Safari 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-338x-hfx8-vx9x

Apache Karaf Cave: Cave SSRF and arbitrary file access

CVSS3: 9.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-338x-7hhr-q38p

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-338w-rmx2-4pjj

SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-338v-jj52-qpg4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fintelligence Fintelligence Calculator allows Stored XSS.This issue affects Fintelligence Calculator: from n/a through 1.0.3.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-338v-3958-8v8r

Information disclosure in JBoss Weld

1%
Низкий
больше 5 лет назад
github логотип
GHSA-338r-39f8-6rqm

FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo function.

0%
Низкий
почти 4 года назад
github логотип
GHSA-338q-vjff-j9cr

An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1535, CVE-2020-1539, CVE-2020-1540, CVE-2020-1541, CVE-2020-1542, CVE-2020-1543, CVE-2020-1544, CVE-2020-1545, CVE-2020-1546, CVE-2020-1547, CVE-2020-1551.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-338q-gcv2-fx6x

Unspecified vulnerability in the Oracle Financial Consolidation Hub component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Business Intelligence.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу