Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2j66-59x2-vc2p

больше 3 лет назад

Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2j65-72jp-x2mj

больше 2 лет назад

A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x will not be fixed.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j64-wxj4-5fr9

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2j64-3f3h-4p9c

больше 3 лет назад

The ANSendForReview method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.

EPSS: Низкий
github логотип

GHSA-2j63-x9pq-h9wc

около 2 лет назад

A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2j63-r66v-jwpq

больше 2 лет назад

OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2j62-rj59-pvjj

больше 3 лет назад

core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google Chrome before 28.0.1500.71, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2j62-pc6c-rfvc

больше 3 лет назад

Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality. This is fixed in version 2.6.1_Windows.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2j5x-56p6-hj6x

больше 6 лет назад

Path Traversal in statichttpserver

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2j5x-2fxv-c77c

больше 3 лет назад

Windows Remote Access Connection Manager Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-33763, CVE-2021-34454.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j5w-q8vw-5g5m

больше 3 лет назад

Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenticated low privileged attacker may potentially exploit this vulnerability leading to disclosure of the OIDC server credentials.

EPSS: Низкий
github логотип

GHSA-2j5w-cwc3-8hxw

больше 3 лет назад

Improper Certificate Validation in Jenkins Spira Importer Plugin

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2j5w-557m-jffq

почти 3 года назад

Datakit CrossCadWare_x64.dll contains an out-of-bounds write past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j5v-vvg9-5xx3

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.

EPSS: Низкий
github логотип

GHSA-2j5v-fc74-j9q2

почти 7 лет назад

Cross-Site Scripting in editor.md

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2j5v-7wgm-q5gw

больше 3 лет назад

WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

EPSS: Низкий
github логотип

GHSA-2j5r-64m5-jpx3

почти 4 года назад

An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2j5q-x2p7-vgw7

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

EPSS: Низкий
github логотип

GHSA-2j5q-ph68-3hp6

больше 3 лет назад

Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j5q-9qj3-658m

больше 3 лет назад

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j66-59x2-vc2p

Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j65-72jp-x2mj

A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x will not be fixed.

CVSS3: 9.8
10%
Низкий
больше 2 лет назад
github логотип
GHSA-2j64-wxj4-5fr9

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j64-3f3h-4p9c

The ANSendForReview method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j63-x9pq-h9wc

A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2j63-r66v-jwpq

OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.

CVSS3: 9.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2j62-rj59-pvjj

core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google Chrome before 28.0.1500.71, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j62-pc6c-rfvc

Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality. This is fixed in version 2.6.1_Windows.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5x-56p6-hj6x

Path Traversal in statichttpserver

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
github логотип
GHSA-2j5x-2fxv-c77c

Windows Remote Access Connection Manager Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-33763, CVE-2021-34454.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5w-q8vw-5g5m

Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenticated low privileged attacker may potentially exploit this vulnerability leading to disclosure of the OIDC server credentials.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5w-cwc3-8hxw

Improper Certificate Validation in Jenkins Spira Importer Plugin

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5w-557m-jffq

Datakit CrossCadWare_x64.dll contains an out-of-bounds write past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2j5v-vvg9-5xx3

Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2j5v-fc74-j9q2

Cross-Site Scripting in editor.md

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
github логотип
GHSA-2j5v-7wgm-q5gw

WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5r-64m5-jpx3

An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 7.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2j5q-x2p7-vgw7

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

8%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5q-ph68-3hp6

Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5q-9qj3-658m

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу