Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2w4j-j38j-hjcx

около 3 лет назад

D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w4h-wj52-qhcp

больше 3 лет назад

Vulnerability in the Oracle Hospitality Cruise Materials Management product of Oracle Hospitality Applications (component: MMS All). The supported version that is affected is 7.30.567. Difficult to exploit vulnerability allows physical access to compromise Oracle Hospitality Cruise Materials Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Cruise Materials Management accessible data. CVSS 3.0 Base Score 4.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-2w4h-pg4c-ww4f

больше 3 лет назад

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Text. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).

EPSS: Низкий
github логотип

GHSA-2w4h-f44w-968f

больше 3 лет назад

Improper Privilege Management in Neo4j Graph Database

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2w4h-75hc-2jv2

около 2 лет назад

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-2w4h-4498-x8m6

больше 3 лет назад

SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w4f-h4cf-767r

12 месяцев назад

Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2w4f-9fgg-q2v9

3 дня назад

melange has a path traversal in license-path which allows reading files outside workspace

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2w4f-8m3p-jrxr

почти 4 года назад

A vulnerability has been identified in COMOS (All versions < V10.4.1). The COMOS Web component of COMOS accepts arbitrary code as attachment to tasks. This could allow an attacker to inject malicious code that is executed when loading the attachment.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2w4c-wrx8-g8wh

почти 2 года назад

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_group.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2w4c-q6mw-hcjx

3 месяца назад

Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unauthorized access with elevated privileges, compromising system integrity and customer data. Dell recommends customers upgrade to the latest version at the earliest opportunity.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2w4c-hx38-p886

больше 3 лет назад

The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2w49-w2vv-p84h

больше 1 года назад

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2w49-qg9p-7jxx

больше 3 лет назад

Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subversion repository but example.com/pkg1/pkg2 points to a Git repository. If the Subversion repository includes a Git checkout in its pkg2 directory and some other work is done to ensure the proper ordering of operations, "go get" can be tricked into reusing this Git checkout for the fetch of code from pkg2. If the Subversion repository's Git checkout has malicious commands in .git/hooks/, they will execute on the system running "go get."

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w49-pm36-8jp5

больше 3 лет назад

An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTunes 12.11 for Windows. A malicious application may be able to access local users Apple IDs.

EPSS: Низкий
github логотип

GHSA-2w49-cc6p-pggp

больше 3 лет назад

Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2w48-ph92-rq3j

больше 3 лет назад

There is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1.10, a different vulnerability than CVE-2018-20541 (which is in a different part of the source code and is seen at a different address).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2w48-h3m6-2r8q

почти 4 года назад

Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to perform directory traversal attacks to read arbitrary local files, lock topics, and possibly have other security impacts. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Simple Machines Forum.

EPSS: Низкий
github логотип

GHSA-2w48-6h97-465j

больше 3 лет назад

Due to lack of proper memory management, when a victim opens manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2w47-9873-w85f

5 месяцев назад

A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the argument id/newOwnerUserId leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2w4j-j38j-hjcx

D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

CVSS3: 9.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-2w4h-wj52-qhcp

Vulnerability in the Oracle Hospitality Cruise Materials Management product of Oracle Hospitality Applications (component: MMS All). The supported version that is affected is 7.30.567. Difficult to exploit vulnerability allows physical access to compromise Oracle Hospitality Cruise Materials Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Cruise Materials Management accessible data. CVSS 3.0 Base Score 4.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 4.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w4h-pg4c-ww4f

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Text. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w4h-f44w-968f

Improper Privilege Management in Neo4j Graph Database

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2w4h-75hc-2jv2

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

CVSS3: 6
0%
Низкий
около 2 лет назад
github логотип
GHSA-2w4h-4498-x8m6

SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w4f-h4cf-767r

Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.

CVSS3: 8.5
1%
Низкий
12 месяцев назад
github логотип
GHSA-2w4f-9fgg-q2v9

melange has a path traversal in license-path which allows reading files outside workspace

CVSS3: 5.5
0%
Низкий
3 дня назад
github логотип
GHSA-2w4f-8m3p-jrxr

A vulnerability has been identified in COMOS (All versions < V10.4.1). The COMOS Web component of COMOS accepts arbitrary code as attachment to tasks. This could allow an attacker to inject malicious code that is executed when loading the attachment.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2w4c-wrx8-g8wh

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_group.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2w4c-q6mw-hcjx

Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it may result in unauthorized access with elevated privileges, compromising system integrity and customer data. Dell recommends customers upgrade to the latest version at the earliest opportunity.

CVSS3: 9.1
0%
Низкий
3 месяца назад
github логотип
GHSA-2w4c-hx38-p886

The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.

CVSS3: 9.8
46%
Средний
больше 3 лет назад
github логотип
GHSA-2w49-w2vv-p84h

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVSS3: 9.8
94%
Критический
больше 1 года назад
github логотип
GHSA-2w49-qg9p-7jxx

Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subversion repository but example.com/pkg1/pkg2 points to a Git repository. If the Subversion repository includes a Git checkout in its pkg2 directory and some other work is done to ensure the proper ordering of operations, "go get" can be tricked into reusing this Git checkout for the fetch of code from pkg2. If the Subversion repository's Git checkout has malicious commands in .git/hooks/, they will execute on the system running "go get."

CVSS3: 9.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-2w49-pm36-8jp5

An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTunes 12.11 for Windows. A malicious application may be able to access local users Apple IDs.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w49-cc6p-pggp

Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w48-ph92-rq3j

There is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1.10, a different vulnerability than CVE-2018-20541 (which is in a different part of the source code and is seen at a different address).

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w48-h3m6-2r8q

Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to perform directory traversal attacks to read arbitrary local files, lock topics, and possibly have other security impacts. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Simple Machines Forum.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2w48-6h97-465j

Due to lack of proper memory management, when a victim opens manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2w47-9873-w85f

A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the argument id/newOwnerUserId leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу