Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 899

Количество 300 899

github логотип

GHSA-25hc-2p68-qc2g

8 месяцев назад

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25h9-28j4-4h3g

больше 3 лет назад

Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.

EPSS: Низкий
github логотип

GHSA-25h8-g2f4-5mwj

около 2 лет назад

Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25h8-7qpw-h33r

3 дня назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-25h7-w4hq-hgjg

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleMeta module 6.x-1.x before 6.x-2.0 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) delete or (2) add a meta tag entry.

EPSS: Низкий
github логотип

GHSA-25h7-qcgx-8445

больше 3 лет назад

An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1365.

EPSS: Низкий
github логотип

GHSA-25h7-f24x-98pg

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Node basket module for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add or (2) remove nodes from a basket via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-25h6-xmmh-34gc

9 месяцев назад

Microsoft Digest Authentication Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25h5-rq96-q5mq

больше 3 лет назад

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25h5-m4r3-86jm

больше 3 лет назад

Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25h4-xpfg-774m

больше 3 лет назад

Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-25h4-w2qr-hmpx

больше 3 лет назад

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7355.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25h3-mw3p-w8r7

больше 3 лет назад

Dolibarr CRM allows Privilege Escalation

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25h2-xj4x-29h3

около 3 лет назад

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25gx-qr96-f826

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts allows Stored XSS. This issue affects Get Posts: from n/a through 0.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25gw-crq8-3qhc

больше 3 лет назад

An Out-of-Bounds Write vulnerability exists when reading a DXF file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF files. Crafted data in a DXF file (an invalid number of properties) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25gw-4pcc-45cf

больше 3 лет назад

Deserialization of Untrusted Data in Apache Batik

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25gv-wg6f-6frp

около 3 лет назад

Centreon SQL Injection vulnerability via esc_name parameter

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25gv-mvm7-5h3h

почти 3 года назад

Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25gv-jrjg-43pj

4 месяца назад

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25hc-2p68-qc2g

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-25h9-28j4-4h3g

Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-25h8-g2f4-5mwj

Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-25h8-7qpw-h33r

Rejected reason: Not used

3 дня назад
github логотип
GHSA-25h7-w4hq-hgjg

Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleMeta module 6.x-1.x before 6.x-2.0 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) delete or (2) add a meta tag entry.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25h7-qcgx-8445

An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1365.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25h7-f24x-98pg

Multiple cross-site request forgery (CSRF) vulnerabilities in the Node basket module for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add or (2) remove nodes from a basket via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25h6-xmmh-34gc

Microsoft Digest Authentication Remote Code Execution Vulnerability

CVSS3: 8.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-25h5-rq96-q5mq

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25h5-m4r3-86jm

Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25h4-xpfg-774m

Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25h4-w2qr-hmpx

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7355.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25h3-mw3p-w8r7

Dolibarr CRM allows Privilege Escalation

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25h2-xj4x-29h3

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-25gx-qr96-f826

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts allows Stored XSS. This issue affects Get Posts: from n/a through 0.6.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-25gw-crq8-3qhc

An Out-of-Bounds Write vulnerability exists when reading a DXF file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF files. Crafted data in a DXF file (an invalid number of properties) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25gw-4pcc-45cf

Deserialization of Untrusted Data in Apache Batik

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25gv-wg6f-6frp

Centreon SQL Injection vulnerability via esc_name parameter

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-25gv-mvm7-5h3h

Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-25gv-jrjg-43pj

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу