Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2fw8-6c95-mmp8

больше 3 лет назад

Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fw7-6f7r-fx94

11 дней назад

Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2fw6-rcj8-hfw7

2 месяца назад

A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fw5-rvf2-jq56

больше 7 лет назад

Apache Camel's XSLT component allows remote attackers to read arbitrary files

EPSS: Средний
github логотип

GHSA-2fw5-hcch-p3cj

11 месяцев назад

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2fw4-mgq9-39cx

почти 5 лет назад

Code Injection in oauth2-server

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fw3-wc2h-wv2q

почти 4 года назад

PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.

EPSS: Высокий
github логотип

GHSA-2fw3-jw4x-3m5f

почти 4 года назад

Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.

EPSS: Средний
github логотип

GHSA-2fw2-jxh6-36cg

около 3 лет назад

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fw2-hj8q-m4ff

больше 3 лет назад

Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.

EPSS: Низкий
github логотип

GHSA-2fvx-vhr6-r4cv

около 4 лет назад

Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side attacks.

EPSS: Низкий
github логотип

GHSA-2fvx-fjcj-g5x8

больше 3 лет назад

An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33547247.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2fvx-54hx-6r34

почти 2 года назад

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263311. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2fvx-46rg-mf9q

около 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-2fvw-qmcc-8m37

12 месяцев назад

An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without proper hardware programming, leading to a potential denial-of-service with privileged access.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2fvw-ppfc-cm77

больше 2 лет назад

In JetBrains Ktor before 2.3.5 server certificates were not verified

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2fvw-mmpv-h962

больше 3 лет назад

The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2fvw-6h8p-qwr7

больше 3 лет назад

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

CVSS3: 6.1
EPSS: Высокий
github логотип

GHSA-2fvw-3vhp-2m2r

почти 4 года назад

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg.

EPSS: Низкий
github логотип

GHSA-2fvv-qxrq-7jq6

больше 3 лет назад

apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fw8-6c95-mmp8

Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fw7-6f7r-fx94

Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.

CVSS3: 6.1
0%
Низкий
11 дней назад
github логотип
GHSA-2fw6-rcj8-hfw7

A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-2fw5-rvf2-jq56

Apache Camel's XSLT component allows remote attackers to read arbitrary files

29%
Средний
больше 7 лет назад
github логотип
GHSA-2fw5-hcch-p3cj

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2fw4-mgq9-39cx

Code Injection in oauth2-server

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-2fw3-wc2h-wv2q

PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.

72%
Высокий
почти 4 года назад
github логотип
GHSA-2fw3-jw4x-3m5f

Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.

55%
Средний
почти 4 года назад
github логотип
GHSA-2fw2-jxh6-36cg

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2fw2-hj8q-m4ff

Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvx-vhr6-r4cv

Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side attacks.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2fvx-fjcj-g5x8

An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33547247.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvx-54hx-6r34

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263311. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2fvx-46rg-mf9q

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

около 2 лет назад
github логотип
GHSA-2fvw-qmcc-8m37

An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without proper hardware programming, leading to a potential denial-of-service with privileged access.

CVSS3: 7.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-2fvw-ppfc-cm77

In JetBrains Ktor before 2.3.5 server certificates were not verified

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fvw-mmpv-h962

The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvw-6h8p-qwr7

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

CVSS3: 6.1
74%
Высокий
больше 3 лет назад
github логотип
GHSA-2fvw-3vhp-2m2r

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2fvv-qxrq-7jq6

apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page

больше 3 лет назад

Уязвимостей на страницу