Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 078

Количество 314 078

github логотип

GHSA-2q4g-wvwx-8q3w

около 1 года назад

Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2q4g-wfm6-5fpm

почти 4 года назад

SaltStack Improper Verification of Cryptographic Signature

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2q4g-w47c-4674

больше 5 лет назад

Unpreventable top-level navigation

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2q4g-qm2f-cq2j

больше 3 лет назад

The REENT_CHECK macro (see newlib/libc/include/sys/reent.h) as used by REENT_CHECK_TM, REENT_CHECK_MISC, REENT_CHECK_MP and other newlib macros in verisons prior to 3.3.0, does not check for memory allocation problems when the DEBUG flag is unset (as is the case in production firmware builds).

EPSS: Низкий
github логотип

GHSA-2q4g-fw9r-2xxm

почти 4 года назад

Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.

EPSS: Низкий
github логотип

GHSA-2q4f-xv44-vmqf

около 2 лет назад

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2q4f-gjpq-vfmh

11 месяцев назад

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2q4c-rgm8-v3rp

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue affects Beaver Builder: from n/a through 2.8.2.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2q49-prvr-qrg4

больше 3 лет назад

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the conversion module that reads U3D data. A successful attack can lead to sensitive data exposure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2q49-5v6q-6qr6

почти 3 года назад

Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2q48-8wh9-4hjx

6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shen2 多说社会化评论框 allows Reflected XSS. This issue affects 多说社会化评论框: from n/a through 1.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2q48-3ch2-69v7

больше 3 лет назад

On Juniper Networks EX4300-MP Series, EX4600 Series, EX4650 Series, QFX5K Series deployed as a Virtual Chassis with a specific Layer 2 circuit configuration, Packet Forwarding Engine manager (FXPC) process may crash and restart upon receipt of specific layer 2 frames. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS on EX4300-MP Series, EX4600 Series, EX4650 Series, QFX5K Series 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S4, 17.4R3-S5; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R2-S7, 18.4R3-S6; 19.1 versions prior to 19.1R3-S4; 19.2 versions prior to 19.2R1-S6, 19.2R3-S1; 19.3 versions prior to 19.3R3-S1; 19.4 versions prior to 19.4R2-S4, 19.4R3-S1; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R2, 20.2R3; 20.3 versions prior to 20.3R1-S2, 20.3R2;

EPSS: Низкий
github логотип

GHSA-2q45-953f-m2g9

больше 3 лет назад

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

EPSS: Низкий
github логотип

GHSA-2q43-24pg-qchj

больше 3 лет назад

rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2q3x-mqw8-qf9r

больше 3 лет назад

An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

EPSS: Низкий
github логотип

GHSA-2q3x-j945-f36w

больше 3 лет назад

Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans from a remote host using MLet that leads to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2q3x-h8wg-223x

почти 4 года назад

PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter.

EPSS: Низкий
github логотип

GHSA-2q3x-64cr-5mp5

3 месяца назад

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when excessively large values are submitted. This results in the inability to create new memories, impacting the stability of the service.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2q3w-q48r-7m5f

больше 3 лет назад

Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.

EPSS: Низкий
github логотип

GHSA-2q3w-m82w-3h55

почти 4 года назад

The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0473.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2q4g-wvwx-8q3w

Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2q4g-wfm6-5fpm

SaltStack Improper Verification of Cryptographic Signature

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2q4g-w47c-4674

Unpreventable top-level navigation

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-2q4g-qm2f-cq2j

The REENT_CHECK macro (see newlib/libc/include/sys/reent.h) as used by REENT_CHECK_TM, REENT_CHECK_MISC, REENT_CHECK_MP and other newlib macros in verisons prior to 3.3.0, does not check for memory allocation problems when the DEBUG flag is unset (as is the case in production firmware builds).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2q4g-fw9r-2xxm

Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2q4f-xv44-vmqf

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization.

CVSS3: 6.4
2%
Низкий
около 2 лет назад
github логотип
GHSA-2q4f-gjpq-vfmh

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

CVSS3: 4.6
5%
Низкий
11 месяцев назад
github логотип
GHSA-2q4c-rgm8-v3rp

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue affects Beaver Builder: from n/a through 2.8.2.2.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2q49-prvr-qrg4

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the conversion module that reads U3D data. A successful attack can lead to sensitive data exposure.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2q49-5v6q-6qr6

Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-2q48-8wh9-4hjx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shen2 多说社会化评论框 allows Reflected XSS. This issue affects 多说社会化评论框: from n/a through 1.2.

CVSS3: 7.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-2q48-3ch2-69v7

On Juniper Networks EX4300-MP Series, EX4600 Series, EX4650 Series, QFX5K Series deployed as a Virtual Chassis with a specific Layer 2 circuit configuration, Packet Forwarding Engine manager (FXPC) process may crash and restart upon receipt of specific layer 2 frames. Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS on EX4300-MP Series, EX4600 Series, EX4650 Series, QFX5K Series 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S4, 17.4R3-S5; 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R2-S7, 18.4R3-S6; 19.1 versions prior to 19.1R3-S4; 19.2 versions prior to 19.2R1-S6, 19.2R3-S1; 19.3 versions prior to 19.3R3-S1; 19.4 versions prior to 19.4R2-S4, 19.4R3-S1; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R2, 20.2R3; 20.3 versions prior to 20.3R1-S2, 20.3R2;

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2q45-953f-m2g9

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2q43-24pg-qchj

rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2q3x-mqw8-qf9r

An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2q3x-j945-f36w

Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans from a remote host using MLet that leads to arbitrary code execution.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2q3x-h8wg-223x

PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter.

4%
Низкий
почти 4 года назад
github логотип
GHSA-2q3x-64cr-5mp5

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when excessively large values are submitted. This results in the inability to create new memories, impacting the stability of the service.

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-2q3w-q48r-7m5f

Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-2q3w-m82w-3h55

The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0473.

12%
Средний
почти 4 года назад

Уязвимостей на страницу