Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2gfp-29x3-m5qq

больше 3 лет назад

Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via vectors related to SVP.

EPSS: Низкий
github логотип

GHSA-2gfm-xchp-vj2m

почти 4 года назад

Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-2gfm-8cgv-xpwx

почти 4 года назад

Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."

EPSS: Средний
github логотип

GHSA-2gfj-wm5m-4vc3

около 4 лет назад

In StarWind Command Center before V2 build 6021, an authenticated read-only user can elevate privileges to administrator through the REST API.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gfj-2fgr-3hmh

почти 2 года назад

IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to move laterally to affected systems and to escalate their privileges. IBM X-Force ID: 281619.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-2gfh-jx79-m8hg

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople CP Polls allows Reflected XSS.This issue affects CP Polls: from n/a through 1.0.74.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2gfh-cmxv-5j8h

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2gfh-cg4p-chjr

почти 4 года назад

Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.

EPSS: Низкий
github логотип

GHSA-2gfg-vm36-6mvj

больше 3 лет назад

The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.

EPSS: Низкий
github логотип

GHSA-2gfg-v7vx-m6gx

больше 3 лет назад

COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2gfg-p5mp-gf94

почти 4 года назад

CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.

EPSS: Низкий
github логотип

GHSA-2gff-x2x6-mqv3

больше 3 лет назад

For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-5852 ID is for the NVTray Plugin unquoted service path.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gff-65gq-h5qw

больше 3 лет назад

If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer making "view-source:" linkable. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gfc-j4qr-8wcc

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gfc-3f49-cfq7

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sohelwpexpert WP Responsive Video allows DOM-Based XSS.This issue affects WP Responsive Video: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gf9-crwq-fg52

почти 4 года назад

The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.

EPSS: Низкий
github логотип

GHSA-2gf8-x72h-g57r

больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2gf8-64pg-49p7

больше 1 года назад

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2gf7-wf94-4pqj

больше 3 лет назад

Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2gf7-pwpq-8w42

больше 3 лет назад

Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gfp-29x3-m5qq

Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via vectors related to SVP.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gfm-xchp-vj2m

Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gfm-8cgv-xpwx

Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."

44%
Средний
почти 4 года назад
github логотип
GHSA-2gfj-wm5m-4vc3

In StarWind Command Center before V2 build 6021, an authenticated read-only user can elevate privileges to administrator through the REST API.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gfj-2fgr-3hmh

IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to move laterally to affected systems and to escalate their privileges. IBM X-Force ID: 281619.

CVSS3: 9
0%
Низкий
почти 2 года назад
github логотип
GHSA-2gfh-jx79-m8hg

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople CP Polls allows Reflected XSS.This issue affects CP Polls: from n/a through 1.0.74.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gfh-cmxv-5j8h

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 5.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2gfh-cg4p-chjr

Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gfg-vm36-6mvj

The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2gfg-v7vx-m6gx

COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gfg-p5mp-gf94

CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gff-x2x6-mqv3

For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-5852 ID is for the NVTray Plugin unquoted service path.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gff-65gq-h5qw

If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer making "view-source:" linkable. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gfc-j4qr-8wcc

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gfc-3f49-cfq7

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sohelwpexpert WP Responsive Video allows DOM-Based XSS.This issue affects WP Responsive Video: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2gf9-crwq-fg52

The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gf8-x72h-g57r

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier.

CVSS3: 9.8
86%
Высокий
больше 3 лет назад
github логотип
GHSA-2gf8-64pg-49p7

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gf7-wf94-4pqj

Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gf7-pwpq-8w42

Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.

63%
Средний
больше 3 лет назад

Уязвимостей на страницу