Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-32wm-p53q-684m

3 месяца назад

An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue enables an attacker to retrieve data such as GPS coordinates, encryption keys, initialization vectors, model numbers, and fuel statistics belonging to other users, instead of being limited to their own vehicle data. This is a server-side authorization fix.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-32wm-927m-gppc

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in CMSaccount Photo Video Store allows Cross-Site Scripting (XSS).This issue affects Photo Video Store: from n/a through 21.07.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-32wh-5vv8-c8px

почти 4 года назад

SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter.

EPSS: Низкий
github логотип

GHSA-32wh-2cq7-f29f

около 1 года назад

A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-32wg-h523-82pp

почти 4 года назад

Comodo Personal Firewall 2.3.6.81 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.

EPSS: Низкий
github логотип

GHSA-32wg-gc37-9jjj

больше 3 лет назад

The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32wf-9fvj-8hx8

больше 1 года назад

A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32wf-3wxg-68pf

больше 3 лет назад

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-32w9-wxmj-7cv4

больше 3 лет назад

An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32w9-cgpf-p2wf

больше 3 лет назад

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

EPSS: Низкий
github логотип

GHSA-32w9-2qpc-5f9v

больше 3 лет назад

Docker image code execution with Apache Mesos

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32w8-rwc8-j8q2

почти 4 года назад

DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.

EPSS: Средний
github логотип

GHSA-32w7-9whp-cjp9

около 7 лет назад

Session Fixation in Tryton

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-32w7-8jrj-h2v7

4 месяца назад

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-32w7-6rgv-w2xg

больше 3 лет назад

An issue was discovered in UC Berkeley RISE Opaque before 2018-12-01. There is no boundary check on ocall_malloc. The return value could be a pointer to enclave memory. It could cause an arbitrary enclave memory write.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32w6-xw3w-3qh3

12 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-32w5-785v-xx4q

больше 1 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-32w5-6g7q-f4f8

больше 3 лет назад

An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32w5-2rp6-rg25

почти 3 года назад

Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-32w4-gwv8-pcf9

больше 3 лет назад

The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6768.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32wm-p53q-684m

An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue enables an attacker to retrieve data such as GPS coordinates, encryption keys, initialization vectors, model numbers, and fuel statistics belonging to other users, instead of being limited to their own vehicle data. This is a server-side authorization fix.

CVSS3: 8.5
0%
Низкий
3 месяца назад
github логотип
GHSA-32wm-927m-gppc

Cross-Site Request Forgery (CSRF) vulnerability in CMSaccount Photo Video Store allows Cross-Site Scripting (XSS).This issue affects Photo Video Store: from n/a through 21.07.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-32wh-5vv8-c8px

SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32wh-2cq7-f29f

A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-32wg-h523-82pp

Comodo Personal Firewall 2.3.6.81 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32wg-gc37-9jjj

The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-32wf-9fvj-8hx8

A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-32wf-3wxg-68pf

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32w9-wxmj-7cv4

An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32w9-cgpf-p2wf

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32w9-2qpc-5f9v

Docker image code execution with Apache Mesos

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32w8-rwc8-j8q2

DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.

32%
Средний
почти 4 года назад
github логотип
GHSA-32w7-9whp-cjp9

Session Fixation in Tryton

CVSS3: 5.9
0%
Низкий
около 7 лет назад
github логотип
GHSA-32w7-8jrj-h2v7

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

CVSS3: 7.4
0%
Низкий
4 месяца назад
github логотип
GHSA-32w7-6rgv-w2xg

An issue was discovered in UC Berkeley RISE Opaque before 2018-12-01. There is no boundary check on ocall_malloc. The return value could be a pointer to enclave memory. It could cause an arbitrary enclave memory write.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32w6-xw3w-3qh3

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

12 месяцев назад
github логотип
GHSA-32w5-785v-xx4q

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-32w5-6g7q-f4f8

An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

CVSS3: 7.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-32w5-2rp6-rg25

Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-32w4-gwv8-pcf9

The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6768.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу