Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 322 820

Количество 322 820

github логотип

GHSA-xxjw-fx2f-9c38

около 1 года назад

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjw-6qx2-crcm

почти 4 года назад

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxjv-vh49-qq33

почти 2 года назад

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21562)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxjv-pwp6-p43h

почти 4 года назад

The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.

EPSS: Низкий
github логотип

GHSA-xxjv-9p3v-x2hv

около 1 года назад

An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjr-mmjv-4gpg

2 месяца назад

Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxjr-c99v-4h9c

больше 2 лет назад

A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxjm-jvw6-6mm7

около 3 лет назад

NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and denial of service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxjj-jhgc-r68f

почти 4 года назад

Alkacon OpenCMS Absolute Path Traversal via pathname in filePath.0 parameter

EPSS: Низкий
github логотип

GHSA-xxjj-gr7j-h6p2

22 дня назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fiorello fiorello allows PHP Local File Inclusion.This issue affects Fiorello: from n/a through <= 1.0.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xxjj-crx8-rwgg

почти 4 года назад

mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.

EPSS: Средний
github логотип

GHSA-xxjj-3mqq-qmc5

почти 4 года назад

hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-xxjh-m7wj-xf5h

почти 3 года назад

Weak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxjh-h523-972c

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: validate endpoint index for ast udc We should verify the bound of the array to assure that host may not manipulate the index to point past endpoint array. Found by static analysis.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxjh-5gpj-36xr

около 2 лет назад

Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information, potentially bypassing security measures. Exploitation of this issue does not require user interaction.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxjh-3xfp-3f5r

2 месяца назад

A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/ConfigExceptMSN. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxjg-h3wx-gvpq

почти 4 года назад

AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to move to a fixed version and change passwords used by Veritas NetBackup to access the OST shares on the NetApp AltaVault as a precaution.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxjg-g7rc-gcjx

почти 4 года назад

The web interface in EMC RSA NetWitness Informer before 2.0.5.6 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xxjg-73ww-rhcc

около 3 лет назад

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need to have valid credentials to access the web-based management interface of the affected device.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxjf-hhmr-jhmq

больше 2 лет назад

Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxjw-fx2f-9c38

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xxjw-6qx2-crcm

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

CVSS3: 7.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxjv-vh49-qq33

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21562)

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxjv-pwp6-p43h

The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxjv-9p3v-x2hv

An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xxjr-mmjv-4gpg

Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xxjr-c99v-4h9c

A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxjm-jvw6-6mm7

NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and denial of service.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxjj-jhgc-r68f

Alkacon OpenCMS Absolute Path Traversal via pathname in filePath.0 parameter

2%
Низкий
почти 4 года назад
github логотип
GHSA-xxjj-gr7j-h6p2

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fiorello fiorello allows PHP Local File Inclusion.This issue affects Fiorello: from n/a through <= 1.0.

CVSS3: 8.1
0%
Низкий
22 дня назад
github логотип
GHSA-xxjj-crx8-rwgg

mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.

39%
Средний
почти 4 года назад
github логотип
GHSA-xxjj-3mqq-qmc5

hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxjh-m7wj-xf5h

Weak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxjh-h523-972c

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: validate endpoint index for ast udc We should verify the bound of the array to assure that host may not manipulate the index to point past endpoint array. Found by static analysis.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxjh-5gpj-36xr

Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information, potentially bypassing security measures. Exploitation of this issue does not require user interaction.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxjh-3xfp-3f5r

A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/ConfigExceptMSN. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-xxjg-h3wx-gvpq

AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to move to a fixed version and change passwords used by Veritas NetBackup to access the OST shares on the NetApp AltaVault as a precaution.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxjg-g7rc-gcjx

The web interface in EMC RSA NetWitness Informer before 2.0.5.6 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxjg-73ww-rhcc

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need to have valid credentials to access the web-based management interface of the affected device.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxjf-hhmr-jhmq

Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу