Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-2mx8-3jpw-29fq

больше 3 лет назад

Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are before version 4.12.0.

EPSS: Низкий
github логотип

GHSA-2mx7-xvfg-fg53

около 2 лет назад

Liferay Portal's account lockout does not invalidate existing user sessions

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mx7-9ww8-vf6w

почти 4 года назад

browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.

EPSS: Низкий
github логотип

GHSA-2mx7-93rf-q2qj

больше 3 лет назад

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at IMM32!ImmLockImeDpi+0x0000000000000050."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mx7-6jw4-m4gw

почти 4 года назад

Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.

EPSS: Низкий
github логотип

GHSA-2mx6-fq24-g2mh

4 месяца назад

ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal

EPSS: Низкий
github логотип

GHSA-2mx6-9mw9-88cc

больше 3 лет назад

dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mx6-6v5m-wj8m

больше 3 лет назад

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

EPSS: Низкий
github логотип

GHSA-2mx5-rvwp-q23x

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemeGUM Gum Elementor Addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through 1.3.5.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2mx5-492m-xqp6

больше 3 лет назад

H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mx4-jrqf-62cp

9 месяцев назад

A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchdata parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mx4-g8fr-m5m8

3 месяца назад

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction on the 'rtafar_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to call arbitrary plugin functions and execute code within those functions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mx4-9h4m-vvxh

9 месяцев назад

A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this issue is some unknown functionality of the file /login.data. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2mx4-9226-r9j6

больше 3 лет назад

An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_comm via a crafted XMLRPC call.

EPSS: Низкий
github логотип

GHSA-2mx3-6gff-v3gh

больше 3 лет назад

Unquoted search path vulnerability in MSI True Color before 3.0.52.0 allows privilege escalation to SYSTEM.

EPSS: Низкий
github логотип

GHSA-2mx3-6c3v-gprg

больше 3 лет назад

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially crafted lure resource ID.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mx3-3v4c-p542

больше 3 лет назад

In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237717857

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mx3-33rv-244v

больше 3 лет назад

Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493.

EPSS: Низкий
github логотип

GHSA-2mwx-p789-p6c8

почти 4 года назад

PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad parameter.

EPSS: Средний
github логотип

GHSA-2mwx-fmf7-pp2w

почти 4 года назад

BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mx8-3jpw-29fq

Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are before version 4.12.0.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mx7-xvfg-fg53

Liferay Portal's account lockout does not invalidate existing user sessions

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-2mx7-9ww8-vf6w

browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2mx7-93rf-q2qj

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at IMM32!ImmLockImeDpi+0x0000000000000050."

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mx7-6jw4-m4gw

Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2mx6-fq24-g2mh

ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal

4 месяца назад
github логотип
GHSA-2mx6-9mw9-88cc

dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability."

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mx6-6v5m-wj8m

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mx5-rvwp-q23x

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemeGUM Gum Elementor Addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through 1.3.5.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-2mx5-492m-xqp6

H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mx4-jrqf-62cp

A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the searchdata parameter.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-2mx4-g8fr-m5m8

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction on the 'rtafar_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to call arbitrary plugin functions and execute code within those functions.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2mx4-9h4m-vvxh

A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this issue is some unknown functionality of the file /login.data. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-2mx4-9226-r9j6

An infinite loop in Open Robotics ros_comm XMLRPC server in ROS Melodic through 1.4.11 and ROS Noetic through1.15.11 allows remote attackers to cause a Denial of Service in ros_comm via a crafted XMLRPC call.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mx3-6gff-v3gh

Unquoted search path vulnerability in MSI True Color before 3.0.52.0 allows privilege escalation to SYSTEM.

больше 3 лет назад
github логотип
GHSA-2mx3-6c3v-gprg

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests with specially crafted lure resource ID.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mx3-3v4c-p542

In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237717857

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mx3-33rv-244v

Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mwx-p789-p6c8

PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad parameter.

12%
Средний
почти 4 года назад
github логотип
GHSA-2mwx-fmf7-pp2w

BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу