Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2h2x-8hh2-mfq8

больше 1 года назад

NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h2w-vccm-6fx5

8 месяцев назад

Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2h2w-cg7r-99fh

больше 3 лет назад

In Messaging, there is a possible way to attach files to a message without proper access checks due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226134095

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2h2v-vcj6-9g2j

почти 4 года назад

Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action.

EPSS: Низкий
github логотип

GHSA-2h2v-8cgx-wfvj

больше 3 лет назад

A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h2r-w6vh-2w6r

больше 3 лет назад

DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2h2r-cg5q-pf39

почти 3 года назад

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted content from the lock screen.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h2q-fhfv-pjvj

больше 3 лет назад

The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0108.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2h2q-cpp4-qphp

почти 4 года назад

Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.

EPSS: Низкий
github логотип

GHSA-2h2q-74g8-r928

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool allows Cross Site Request Forgery. This issue affects Football Pool: from n/a through 2.12.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h2q-6mw2-pq7r

3 месяца назад

A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2h2q-4chj-wggp

почти 4 года назад

Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2h2q-3qrx-m3j7

7 месяцев назад

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2h2q-247m-jhjc

8 месяцев назад

A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the argument filename leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h2p-h37h-5phg

почти 4 года назад

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

EPSS: Высокий
github логотип

GHSA-2h2m-v2mg-656c

6 дней назад

Craft Commerce has Stored XSS in Product Type Name

EPSS: Низкий
github логотип

GHSA-2h2m-7hfv-6h4g

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."

EPSS: Низкий
github логотип

GHSA-2h2m-3wv3-pqw4

почти 4 года назад

mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.

EPSS: Средний
github логотип

GHSA-2h2j-mg4w-wm75

больше 3 лет назад

cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2h2j-hwh4-6vfv

больше 3 лет назад

VP9 Video Extensions Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h2x-8hh2-mfq8

NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h2w-vccm-6fx5

Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 4.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-2h2w-cg7r-99fh

In Messaging, there is a possible way to attach files to a message without proper access checks due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226134095

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h2v-vcj6-9g2j

Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2h2v-8cgx-wfvj

A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h2r-w6vh-2w6r

DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2h2r-cg5q-pf39

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted content from the lock screen.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2h2q-fhfv-pjvj

The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0108.

CVSS3: 7.5
24%
Средний
больше 3 лет назад
github логотип
GHSA-2h2q-cpp4-qphp

Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2h2q-74g8-r928

Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool allows Cross Site Request Forgery. This issue affects Football Pool: from n/a through 2.12.2.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2h2q-6mw2-pq7r

A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 2.4
0%
Низкий
3 месяца назад
github логотип
GHSA-2h2q-4chj-wggp

Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2h2q-3qrx-m3j7

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-2h2q-247m-jhjc

A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the argument filename leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2h2p-h37h-5phg

IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.

84%
Высокий
почти 4 года назад
github логотип
GHSA-2h2m-v2mg-656c

Craft Commerce has Stored XSS in Product Type Name

0%
Низкий
6 дней назад
github логотип
GHSA-2h2m-7hfv-6h4g

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2h2m-3wv3-pqw4

mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.

16%
Средний
почти 4 года назад
github логотип
GHSA-2h2j-mg4w-wm75

cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h2j-hwh4-6vfv

VP9 Video Extensions Remote Code Execution Vulnerability

CVSS3: 7.8
9%
Низкий
больше 3 лет назад

Уязвимостей на страницу