Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2fx2-jv5q-q4m6

больше 3 лет назад

Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fwx-xc3r-67p8

больше 3 лет назад

Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresses via a packet with a small TTL, which triggers an ICMP_TIMXCEED_INTRANS (aka ICMP time exceeded in-transit) response containing an encapsulated IP packet with an intranet address, as demonstrated by a TCP packet to the firewall management server on port 18264.

EPSS: Низкий
github логотип

GHSA-2fwx-cj48-8qqf

почти 3 года назад

An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fww-xpgm-c42v

больше 3 лет назад

HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22018, CVE-2022-29111, CVE-2022-29119.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fww-mhh6-5mxr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.

EPSS: Низкий
github логотип

GHSA-2fww-fj3r-9677

больше 1 года назад

The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for unauthenticated attackers to gain unauthorized access to the site.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2fww-cx7f-4r69

больше 3 лет назад

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to AD Utilities.

EPSS: Низкий
github логотип

GHSA-2fwv-796r-67vv

около 4 лет назад

Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigations. Additionally, pages that do make use of CSRF tokens are trivially bypassable as the server does not appear to validate them properly (i.e. re-using an old token or finding the token thru some other method is possible).

EPSS: Низкий
github логотип

GHSA-2fwv-2r36-xvh5

7 месяцев назад

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. The manipulation of the argument productId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2fwq-wx47-hm6x

больше 5 лет назад

Malicious Package in bcion

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2fwq-2wwr-qrww

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: fix NULL-deref on runtime suspend Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation") removed most users of the platform device driver data, but mistakenly also removed the initialisation despite the data still being used in the runtime PM callbacks. Restore the driver data initialisation at probe to avoid a NULL-pointer dereference on runtime suspend. Apparently no one uses runtime PM, which currently needs to be enabled manually through sysfs, with this driver.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fwp-8972-4pv4

больше 3 лет назад

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-2fwm-m84p-x5qh

больше 3 лет назад

The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2fwm-fp55-mv7p

около 3 лет назад

Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fwg-qpp6-4fv9

больше 3 лет назад

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS Chart service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fwg-qc8c-frhr

больше 3 лет назад

Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in the product's Captive Portal.

EPSS: Низкий
github логотип

GHSA-2fwf-jc53-g325

больше 3 лет назад

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126.

EPSS: Низкий
github логотип

GHSA-2fwf-gr55-x95r

больше 3 лет назад

The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.

EPSS: Низкий
github логотип

GHSA-2fwf-5jpg-282p

около 2 лет назад

Rejected reason: This CVE ID was unused by the CNA.

EPSS: Низкий
github логотип

GHSA-2fw9-5c4f-hmp4

больше 3 лет назад

Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fx2-jv5q-q4m6

Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.

CVSS3: 7.8
10%
Низкий
больше 3 лет назад
github логотип
GHSA-2fwx-xc3r-67p8

Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresses via a packet with a small TTL, which triggers an ICMP_TIMXCEED_INTRANS (aka ICMP time exceeded in-transit) response containing an encapsulated IP packet with an intranet address, as demonstrated by a TCP packet to the firewall management server on port 18264.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fwx-cj48-8qqf

An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2fww-xpgm-c42v

HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22018, CVE-2022-29111, CVE-2022-29119.

CVSS3: 7.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2fww-mhh6-5mxr

Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fww-fj3r-9677

The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for unauthenticated attackers to gain unauthorized access to the site.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fww-cx7f-4r69

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to AD Utilities.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fwv-796r-67vv

Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigations. Additionally, pages that do make use of CSRF tokens are trivially bypassable as the server does not appear to validate them properly (i.e. re-using an old token or finding the token thru some other method is possible).

0%
Низкий
около 4 лет назад
github логотип
GHSA-2fwv-2r36-xvh5

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. The manipulation of the argument productId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2fwq-wx47-hm6x

Malicious Package in bcion

CVSS3: 9.1
больше 5 лет назад
github логотип
GHSA-2fwq-2wwr-qrww

In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: fix NULL-deref on runtime suspend Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation") removed most users of the platform device driver data, but mistakenly also removed the initialisation despite the data still being used in the runtime PM callbacks. Restore the driver data initialisation at probe to avoid a NULL-pointer dereference on runtime suspend. Apparently no one uses runtime PM, which currently needs to be enabled manually through sysfs, with this driver.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2fwp-8972-4pv4

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
11%
Средний
больше 3 лет назад
github логотип
GHSA-2fwm-m84p-x5qh

The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fwm-fp55-mv7p

Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2fwg-qpp6-4fv9

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS Chart service.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fwg-qc8c-frhr

Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in the product's Captive Portal.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fwf-jc53-g325

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fwf-gr55-x95r

The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fwf-5jpg-282p

Rejected reason: This CVE ID was unused by the CNA.

около 2 лет назад
github логотип
GHSA-2fw9-5c4f-hmp4

Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу