Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2j57-grq2-wrg8

больше 3 лет назад

An XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2j56-fcwx-7q33

больше 3 лет назад

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j56-f322-jxrm

почти 4 года назад

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2j55-pcw5-x4h2

больше 7 лет назад

active-support impersonates 'activesupport' gem

EPSS: Низкий
github логотип

GHSA-2j54-3gcc-fxxg

около 1 года назад

A server-side request forgery in PAN-OS software enables an unauthenticated attacker to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2j54-2x3p-5g5f

почти 4 года назад

SQL injection vulnerability in Advanced Electron Forum (AEF) 1.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the filename in an uploaded attachment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2j53-x2qc-m5h5

больше 3 лет назад

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30128.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2j53-wh2m-93x6

больше 3 лет назад

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2j53-mg54-5gm9

больше 3 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, MDM9650, MDM9655, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 808, SD 810, and SDX20, in a QTEE syscall handler, HLOS can cause a buffer overflow to occur.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j53-64jx-6w47

больше 3 лет назад

Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.

EPSS: Низкий
github логотип

GHSA-2j52-jv7p-x34h

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.

EPSS: Низкий
github логотип

GHSA-2j4x-8g92-58rm

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2j4w-p7qh-8g4g

больше 3 лет назад

Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j4w-p5m4-8q93

почти 4 года назад

Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. (dot dot) in the template parameter.

EPSS: Низкий
github логотип

GHSA-2j4v-jvmw-mq8v

больше 3 лет назад

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.

EPSS: Низкий
github логотип

GHSA-2j4r-v4xj-p2f4

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2j4r-j436-59p3

больше 3 лет назад

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2j4q-9fff-236j

больше 3 лет назад

Apache Struts XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2j4p-5xx5-582x

больше 3 лет назад

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342.

EPSS: Низкий
github логотип

GHSA-2j4p-2hc9-62f4

почти 3 года назад

Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j57-grq2-wrg8

An XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j56-fcwx-7q33

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16296, and CVE-2018-16297. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j56-f322-jxrm

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

CVSS3: 5.9
1%
Низкий
почти 4 года назад
github логотип
GHSA-2j55-pcw5-x4h2

active-support impersonates 'activesupport' gem

5%
Низкий
больше 7 лет назад
github логотип
GHSA-2j54-3gcc-fxxg

A server-side request forgery in PAN-OS software enables an unauthenticated attacker to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.

CVSS3: 4.9
0%
Низкий
около 1 года назад
github логотип
GHSA-2j54-2x3p-5g5f

SQL injection vulnerability in Advanced Electron Forum (AEF) 1.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the filename in an uploaded attachment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2j53-x2qc-m5h5

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-30128.

CVSS3: 8.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j53-wh2m-93x6

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j53-mg54-5gm9

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, MDM9650, MDM9655, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 808, SD 810, and SDX20, in a QTEE syscall handler, HLOS can cause a buffer overflow to occur.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j53-64jx-6w47

Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j52-jv7p-x34h

Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary web pages via a showcats action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4x-8g92-58rm

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-2j4w-p7qh-8g4g

Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4w-p5m4-8q93

Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. (dot dot) in the template parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2j4v-jvmw-mq8v

IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4r-v4xj-p2f4

Cross-Site Request Forgery (CSRF) vulnerability in Viktoria Rei Bauer WP-BlackCheck allows Stored XSS.This issue affects WP-BlackCheck: from n/a through 2.7.2.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2j4r-j436-59p3

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

CVSS3: 7.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4q-9fff-236j

Apache Struts XSS Vulnerability

CVSS3: 6.1
7%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4p-5xx5-582x

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j4p-2hc9-62f4

Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.

CVSS3: 6.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу