Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2h53-ffj5-hg3q

больше 3 лет назад

A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Memory Corruption Vulnerability'.

EPSS: Низкий
github логотип

GHSA-2h52-qv92-fqx2

почти 4 года назад

SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is already covered by CVE-2005-2049.

EPSS: Низкий
github логотип

GHSA-2h52-m7f3-9vxw

больше 3 лет назад

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2h52-9qm5-hq7p

около 1 года назад

The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_ajax_post_it_list_comment' function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view comments on any post, including private and password protected posts, and pending and draft posts if they were previously published. The vulnerability was partially patched in version 1.3.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h4w-p9fh-9rmv

11 месяцев назад

Apache Ranger Improper Neutralization of Formula Elements vulnerability

EPSS: Низкий
github логотип

GHSA-2h4v-5pj9-9hm9

больше 3 лет назад

An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that causes the service to stop responding. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.21; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h4; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h3; PAN-OS 10.0 versions earlier than PAN-OS 10.0.8-h4; PAN-OS 10.1 versions earlier than PAN-OS 10.1.3. Prisma Access customers are not impacted by this issue.

EPSS: Низкий
github логотип

GHSA-2h4r-wqvw-g722

5 месяцев назад

In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-2h4r-77vh-7qcf

5 месяцев назад

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to upload a .php file containing arbitrary code, which is then executed by the server.

EPSS: Средний
github логотип

GHSA-2h4r-2xrx-xmfc

больше 3 лет назад

PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2h4p-p367-3gr4

8 месяцев назад

yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2h4m-9mfv-2j2r

больше 3 лет назад

Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h4m-4gc2-w5rm

больше 3 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA Transactions.

EPSS: Низкий
github логотип

GHSA-2h4j-hwr9-94jw

больше 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2h4j-gh7g-9vcw

больше 3 лет назад

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Data Source). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Technical Foundation accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

EPSS: Низкий
github логотип

GHSA-2h4h-cj8f-67g5

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show() The csts_state_names[] array only has six sparse entries, but the iteration code in nvmet_ctrl_state_show() iterates seven, resulting in a potential out-of-bounds stack read. Fix that. Fixes the following warning with an UBSAN kernel: vmlinux.o: warning: objtool: .text.nvmet_ctrl_state_show: unexpected end of section

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2h4h-6mrx-52ff

больше 3 лет назад

Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2h4f-vpmv-8mr9

почти 2 года назад

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to view sensitive log information after enumerating filenames. IBM X-Force ID: 269408.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h4c-xw3w-rpgx

почти 4 года назад

nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.

EPSS: Низкий
github логотип

GHSA-2h4c-mfg2-2f7f

больше 3 лет назад

The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h4c-86hw-hmr7

больше 3 лет назад

Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h53-ffj5-hg3q

A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Memory Corruption Vulnerability'.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-2h52-qv92-fqx2

SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is already covered by CVE-2005-2049.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2h52-m7f3-9vxw

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h52-9qm5-hq7p

The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_ajax_post_it_list_comment' function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view comments on any post, including private and password protected posts, and pending and draft posts if they were previously published. The vulnerability was partially patched in version 1.3.5.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2h4w-p9fh-9rmv

Apache Ranger Improper Neutralization of Formula Elements vulnerability

1%
Низкий
11 месяцев назад
github логотип
GHSA-2h4v-5pj9-9hm9

An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that causes the service to stop responding. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.21; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h4; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h3; PAN-OS 10.0 versions earlier than PAN-OS 10.0.8-h4; PAN-OS 10.1 versions earlier than PAN-OS 10.1.3. Prisma Access customers are not impacted by this issue.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h4r-wqvw-g722

In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 5.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-2h4r-77vh-7qcf

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to upload a .php file containing arbitrary code, which is then executed by the server.

70%
Средний
5 месяцев назад
github логотип
GHSA-2h4r-2xrx-xmfc

PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h4p-p367-3gr4

yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-2h4m-9mfv-2j2r

Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h4m-4gc2-w5rm

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA Transactions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h4j-hwr9-94jw

Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.

CVSS3: 8.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2h4j-gh7g-9vcw

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Data Source). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Technical Foundation accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2h4h-cj8f-67g5

In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in nvmet_ctrl_state_show() The csts_state_names[] array only has six sparse entries, but the iteration code in nvmet_ctrl_state_show() iterates seven, resulting in a potential out-of-bounds stack read. Fix that. Fixes the following warning with an UBSAN kernel: vmlinux.o: warning: objtool: .text.nvmet_ctrl_state_show: unexpected end of section

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-2h4h-6mrx-52ff

Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2h4f-vpmv-8mr9

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to view sensitive log information after enumerating filenames. IBM X-Force ID: 269408.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2h4c-xw3w-rpgx

nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2h4c-mfg2-2f7f

The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2h4c-86hw-hmr7

Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу