Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2r6p-x88w-4f7v

около 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2r6p-73q6-355q

5 месяцев назад

Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2r6m-w2r6-qp6v

почти 4 года назад

A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2r6m-j7xh-c9fv

больше 3 лет назад

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2r6j-phhp-ffw3

больше 3 лет назад

The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.

EPSS: Низкий
github логотип

GHSA-2r6j-h9fw-2v55

почти 2 года назад

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2r6j-862c-m2v2

почти 5 лет назад

Unrestricted File Upload in Form Framework

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2r6j-2h3v-6qw4

больше 3 лет назад

The ReadPICTImage function in coders/pict.c in ImageMagick 7.0.6-3 allows attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2r6h-23v5-cm2p

больше 3 лет назад

login_screen.tcl in aMSN (aka Alvaro's Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation.

EPSS: Низкий
github логотип

GHSA-2r6g-7r83-jg72

больше 1 года назад

`spam` project on PyPI compromised, malicious releases made

EPSS: Низкий
github логотип

GHSA-2r6c-crq4-rgxw

больше 3 лет назад

Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. A strncpy overflows the destination buffer, which has a size of 16 bytes. An attacker can send an arbitrarily long "region" value in order to exploit this vulnerability.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2r69-jgh4-vvpm

больше 3 лет назад

On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, under certain conditions, a multi-bladed BIG-IP Virtual Clustered Multiprocessing (vCMP) may drop broadcast packets when they are rebroadcast to the vCMP guest secondary blades. An attacker can leverage the fragmented broadcast IP packets to perform any type of fragmentation-based attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2r69-79fj-p7wm

9 месяцев назад

VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2r69-696x-qxj9

больше 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2r68-xqjc-633p

почти 4 года назад

The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system and execute this code.

EPSS: Низкий
github логотип

GHSA-2r68-qm7v-72rg

больше 3 лет назад

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.

EPSS: Низкий
github логотип

GHSA-2r68-q5wj-6hmg

почти 3 года назад

An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute code and escalate their privilege on the system. IBM X-Force ID: 239847.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2r68-mjqv-c389

больше 3 лет назад

Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2r68-8x78-ffgh

больше 3 лет назад

The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2r68-24rm-gcc8

больше 3 лет назад

The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2r6p-x88w-4f7v

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-2r6p-73q6-355q

Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions

CVSS3: 7
0%
Низкий
5 месяцев назад
github логотип
GHSA-2r6m-w2r6-qp6v

A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-2r6m-j7xh-c9fv

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r6j-phhp-ffw3

The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2r6j-h9fw-2v55

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-2r6j-862c-m2v2

Unrestricted File Upload in Form Framework

CVSS3: 8.6
0%
Низкий
почти 5 лет назад
github логотип
GHSA-2r6j-2h3v-6qw4

The ReadPICTImage function in coders/pict.c in ImageMagick 7.0.6-3 allows attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r6h-23v5-cm2p

login_screen.tcl in aMSN (aka Alvaro's Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r6g-7r83-jg72

`spam` project on PyPI compromised, malicious releases made

больше 1 года назад
github логотип
GHSA-2r6c-crq4-rgxw

Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. A strncpy overflows the destination buffer, which has a size of 16 bytes. An attacker can send an arbitrarily long "region" value in order to exploit this vulnerability.

CVSS3: 9.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r69-jgh4-vvpm

On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, under certain conditions, a multi-bladed BIG-IP Virtual Clustered Multiprocessing (vCMP) may drop broadcast packets when they are rebroadcast to the vCMP guest secondary blades. An attacker can leverage the fragmented broadcast IP packets to perform any type of fragmentation-based attack.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2r69-79fj-p7wm

VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.

CVSS3: 8.2
0%
Низкий
9 месяцев назад
github логотип
GHSA-2r69-696x-qxj9

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r68-xqjc-633p

The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system and execute this code.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2r68-qm7v-72rg

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2r68-q5wj-6hmg

An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute code and escalate their privilege on the system. IBM X-Force ID: 239847.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2r68-mjqv-c389

Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2r68-8x78-ffgh

The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r68-24rm-gcc8

The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу