Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2hjx-qmr7-gg4r

почти 4 года назад

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

EPSS: Низкий
github логотип

GHSA-2hjx-g8mm-qjgv

больше 1 года назад

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to access or modify sensitive configuration files without proper authorization.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hjw-jh9v-m769

больше 3 лет назад

Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-4175.

EPSS: Низкий
github логотип

GHSA-2hjw-hf33-2w8v

почти 4 года назад

Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.

EPSS: Низкий
github логотип

GHSA-2hjw-h4fr-9x35

почти 4 года назад

Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.

EPSS: Низкий
github логотип

GHSA-2hjv-5gg5-2v4c

почти 4 года назад

Multiple SQL injection vulnerabilities in TCExam before 5.1.000 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2hjr-wwf2-rh3g

больше 3 лет назад

Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2605, CVE-2015-2606, and CVE-2015-4745.

EPSS: Низкий
github логотип

GHSA-2hjr-vmf3-xwvp

больше 1 года назад

Elasticsearch Insertion of Sensitive Information into Log File

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-2hjr-fg6c-v2h6

почти 4 года назад

Unauthorized access to Class instance in Jinjava

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hjq-rgfg-v4rj

почти 4 года назад

Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target's email address.

EPSS: Низкий
github логотип

GHSA-2hjm-r8h9-f78j

больше 3 лет назад

A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2hjm-gpw3-28qp

больше 3 лет назад

SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hjm-64qm-49pp

больше 3 лет назад

Audio in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hjm-52g5-36gm

около 1 месяца назад

FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2hjh-495w-hmxc

около 1 года назад

Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts

EPSS: Низкий
github логотип

GHSA-2hjg-p8gh-97px

больше 1 года назад

Secure Boot Security Feature Bypass Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2hjg-g7x8-jf42

больше 3 лет назад

IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hjg-83v5-q3mf

3 месяца назад

A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of credentials. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2hjg-246p-2f5p

почти 4 года назад

An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XSLT Injection vulnerability. Attackers could exploit this issue to achieve remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hjc-v6h4-434p

больше 3 лет назад

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hjx-qmr7-gg4r

An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via an API call

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hjx-g8mm-qjgv

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to access or modify sensitive configuration files without proper authorization.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hjw-jh9v-m769

Buffer overflow in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-4172, CVE-2012-4173, CVE-2012-4174, and CVE-2012-4175.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-2hjw-hf33-2w8v

Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hjw-h4fr-9x35

Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hjv-5gg5-2v4c

Multiple SQL injection vulnerabilities in TCExam before 5.1.000 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hjr-wwf2-rh3g

Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2605, CVE-2015-2606, and CVE-2015-4745.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2hjr-vmf3-xwvp

Elasticsearch Insertion of Sensitive Information into Log File

CVSS3: 5.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-2hjr-fg6c-v2h6

Unauthorized access to Class instance in Jinjava

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2hjq-rgfg-v4rj

Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target's email address.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hjm-r8h9-f78j

A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 9.1
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2hjm-gpw3-28qp

SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hjm-64qm-49pp

Audio in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hjm-52g5-36gm

FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication.

CVSS3: 6.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2hjh-495w-hmxc

Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts

3%
Низкий
около 1 года назад
github логотип
GHSA-2hjg-p8gh-97px

Secure Boot Security Feature Bypass Vulnerability

CVSS3: 8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2hjg-g7x8-jf42

IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID: 124359.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hjg-83v5-q3mf

A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of credentials. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2hjg-246p-2f5p

An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XSLT Injection vulnerability. Attackers could exploit this issue to achieve remote code execution.

CVSS3: 8.8
4%
Низкий
почти 4 года назад
github логотип
GHSA-2hjc-v6h4-434p

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.

CVSS3: 5.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу