Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2xxg-j453-5c23

больше 3 лет назад

A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2xxc-cxf2-h97v

больше 1 года назад

Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xxc-73fv-36f7

больше 2 лет назад

llama-index vulnerable to arbitrary code execution

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xx9-w5qw-9796

больше 3 лет назад

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CV...

EPSS: Низкий
github логотип

GHSA-2xx8-62cr-6w92

больше 3 лет назад

Metaways Tine 2.0 allows remote attackers to obtain sensitive information via unknown vectors in (1) Crm/Controller.php, (2) Crm/Export/Csv.php, or (3) Calendar/Model/Attender.php, which reveal the full installation path.

EPSS: Низкий
github логотип

GHSA-2xx6-c8x3-p4jj

больше 3 лет назад

Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the dynamic expression sandbox and execute arbitrary code on the hosting system.

EPSS: Низкий
github логотип

GHSA-2xx6-8p93-4g88

больше 3 лет назад

The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xx5-rm9h-fw44

больше 3 лет назад

The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain privileges via unspecified vectors involving a new event channel port.

EPSS: Низкий
github логотип

GHSA-2xx5-jpqr-vq6g

больше 3 лет назад

** DISPUTED ** Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI. NOTE: the vendor disputes this issue because file upload is an expected feature, subject to Role Based Access Control checks where only authenticated users with proper permissions can upload files.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xx5-285p-w456

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_T files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18351.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xx4-jj5v-6mff

больше 2 лет назад

Nuclei Path Traversal vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xx3-w7pj-fmgj

больше 3 лет назад

The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.

EPSS: Низкий
github логотип

GHSA-2xx3-ghv4-f2fv

больше 3 лет назад

Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.

EPSS: Средний
github логотип

GHSA-2xx2-7jhq-rw7v

больше 3 лет назад

common.php in Post Revolution before 0.8.0c-2 allows remote attackers to cause a denial of service (infinite loop) via malformed HTML markup, as demonstrated by an a< sequence.

EPSS: Низкий
github логотип

GHSA-2xwx-qwxw-x89v

почти 3 года назад

An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2xwx-3gmg-f9vj

больше 3 лет назад

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xww-r24j-8xmc

почти 4 года назад

calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.

EPSS: Низкий
github логотип

GHSA-2xwv-qmvc-f3g6

больше 3 лет назад

, aka 'RETRACTED'.

EPSS: Низкий
github логотип

GHSA-2xwv-qj35-wxv7

больше 3 лет назад

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2xwv-3cc9-fp7c

больше 6 лет назад

Sensitive Data Exposure in seneca

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xxg-j453-5c23

A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xxc-cxf2-h97v

Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xxc-73fv-36f7

llama-index vulnerable to arbitrary code execution

CVSS3: 9.8
3%
Низкий
больше 2 лет назад
github логотип
GHSA-2xx9-w5qw-9796

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CV...

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xx8-62cr-6w92

Metaways Tine 2.0 allows remote attackers to obtain sensitive information via unknown vectors in (1) Crm/Controller.php, (2) Crm/Export/Csv.php, or (3) Calendar/Model/Attender.php, which reveal the full installation path.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xx6-c8x3-p4jj

Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the dynamic expression sandbox and execute arbitrary code on the hosting system.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2xx6-8p93-4g88

The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-2xx5-rm9h-fw44

The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain privileges via unspecified vectors involving a new event channel port.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xx5-jpqr-vq6g

** DISPUTED ** Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI. NOTE: the vendor disputes this issue because file upload is an expected feature, subject to Role Based Access Control checks where only authenticated users with proper permissions can upload files.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xx5-285p-w456

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_T files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18351.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xx4-jj5v-6mff

Nuclei Path Traversal vulnerability

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2xx3-w7pj-fmgj

The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2xx3-ghv4-f2fv

Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.

34%
Средний
больше 3 лет назад
github логотип
GHSA-2xx2-7jhq-rw7v

common.php in Post Revolution before 0.8.0c-2 allows remote attackers to cause a denial of service (infinite loop) via malformed HTML markup, as demonstrated by an a< sequence.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xwx-qwxw-x89v

An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account

CVSS3: 2.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-2xwx-3gmg-f9vj

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2xww-r24j-8xmc

calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2xwv-qmvc-f3g6

, aka 'RETRACTED'.

больше 3 лет назад
github логотип
GHSA-2xwv-qj35-wxv7

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

CVSS3: 9.8
87%
Высокий
больше 3 лет назад
github логотип
GHSA-2xwv-3cc9-fp7c

Sensitive Data Exposure in seneca

0%
Низкий
больше 6 лет назад

Уязвимостей на страницу