Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 299 736

Количество 299 736

github логотип

GHSA-22q6-wwq7-2jj9

больше 3 лет назад

OpenStack Keystone Improper Authentication vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22q6-rw64-5gjj

больше 2 лет назад

Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-22q6-hvj2-jgmw

больше 3 лет назад

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-22q6-9rvj-cmpf

больше 3 лет назад

Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".

EPSS: Низкий
github логотип

GHSA-22q6-7m3g-6r77

около 1 года назад

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-22q5-qg84-2p5f

больше 3 лет назад

Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.

EPSS: Низкий
github логотип

GHSA-22q5-9phm-744v

8 месяцев назад

XWiki allows unregistered users to access private pages information through REST endpoint

EPSS: Низкий
github логотип

GHSA-22q5-57p4-rxcv

больше 3 лет назад

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22q4-f5r6-3xqw

больше 1 года назад

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

CVSS3: 7.3
EPSS: Критический
github логотип

GHSA-22q4-5758-44qv

больше 3 лет назад

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.

EPSS: Низкий
github логотип

GHSA-22q3-mmfp-g262

больше 3 лет назад

Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.

EPSS: Низкий
github логотип

GHSA-22q3-4v32-4m7c

больше 1 года назад

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-22q2-gf4f-hvw6

около 2 месяцев назад

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.

EPSS: Низкий
github логотип

GHSA-22px-9px7-pc64

больше 3 лет назад

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

EPSS: Низкий
github логотип

GHSA-22pw-2xmq-86xg

больше 3 лет назад

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.

EPSS: Низкий
github логотип

GHSA-22pv-7v9j-hqxp

больше 3 лет назад

Symfony Host Header Injection vulnerability in the HttpFoundation component

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22pv-795j-9r7p

больше 2 лет назад

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22pr-vjq7-4qcg

больше 3 лет назад

The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-22pr-mvmh-vgg5

больше 3 лет назад

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583.

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-22pp-q7jc-mc64

больше 3 лет назад

PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22q6-wwq7-2jj9

OpenStack Keystone Improper Authentication vulnerability

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22q6-rw64-5gjj

Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.

CVSS3: 4.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22q6-hvj2-jgmw

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q6-9rvj-cmpf

Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q6-7m3g-6r77

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVSS3: 9.1
16%
Средний
около 1 года назад
github логотип
GHSA-22q5-qg84-2p5f

Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q5-9phm-744v

XWiki allows unregistered users to access private pages information through REST endpoint

0%
Низкий
8 месяцев назад
github логотип
GHSA-22q5-57p4-rxcv

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q4-f5r6-3xqw

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

CVSS3: 7.3
93%
Критический
больше 1 года назад
github логотип
GHSA-22q4-5758-44qv

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q3-mmfp-g262

Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-22q3-4v32-4m7c

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-22q2-gf4f-hvw6

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-22px-9px7-pc64

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22pw-2xmq-86xg

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22pv-7v9j-hqxp

Symfony Host Header Injection vulnerability in the HttpFoundation component

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22pv-795j-9r7p

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22pr-vjq7-4qcg

The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22pr-mvmh-vgg5

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583.

CVSS3: 5.5
23%
Средний
больше 3 лет назад
github логотип
GHSA-22pp-q7jc-mc64

PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.

13%
Средний
больше 3 лет назад

Уязвимостей на страницу