Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-29gp-96hf-p856

около 3 лет назад

Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29gp-92wp-94q8

около 7 лет назад

react-dev-utils on Windows vulnerable to Remote Code Execution

EPSS: Низкий
github логотип

GHSA-29gp-2c3m-3j6m

около 4 лет назад

Sandbox Escape by math function in smarty

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-29gm-gchh-5j4j

около 1 года назад

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29gj-xrph-g435

больше 3 лет назад

A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests, aka 'Microsoft IIS Server Denial of Service Vulnerability'.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-29gj-jj49-x9g7

больше 2 лет назад

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29gh-89p4-ffqv

почти 3 года назад

European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29gh-3cpv-qpjp

больше 3 лет назад

Check Point Endpoint Security Client E83 through E86 before E86.50 does not protect against a specific registry modification, and thus allows a local administrator to disable endpoint protection.

CVSS3: 2.3
EPSS: Низкий
github логотип

GHSA-29gg-qvj7-46c7

8 месяцев назад

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29gg-8679-22q3

больше 3 лет назад

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29gc-r2qh-wc5v

28 дней назад

A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may disclose internal states of the app.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29gc-hgfp-33m5

больше 3 лет назад

A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-29g9-qwhc-hg77

больше 3 лет назад

Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29g9-48v7-9r7c

больше 1 года назад

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29g8-w5j3-pph4

больше 3 лет назад

A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).

EPSS: Низкий
github логотип

GHSA-29g8-6h62-f7vc

почти 4 года назад

Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-29g7-m78g-3fx6

почти 4 года назад

serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.

EPSS: Низкий
github логотип

GHSA-29g7-g95p-w4ww

почти 4 года назад

Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-29g7-9vcg-g9rm

около 2 лет назад

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29g5-m8v7-v564

7 месяцев назад

Measured is vulnerable to Path Traversal attacks during class initialization

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29gp-96hf-p856

Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-29gp-92wp-94q8

react-dev-utils on Windows vulnerable to Remote Code Execution

1%
Низкий
около 7 лет назад
github логотип
GHSA-29gp-2c3m-3j6m

Sandbox Escape by math function in smarty

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-29gm-gchh-5j4j

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
около 1 года назад
github логотип
GHSA-29gj-xrph-g435

A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests, aka 'Microsoft IIS Server Denial of Service Vulnerability'.

CVSS3: 4.4
3%
Низкий
больше 3 лет назад
github логотип
GHSA-29gj-jj49-x9g7

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29gh-89p4-ffqv

European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-29gh-3cpv-qpjp

Check Point Endpoint Security Client E83 through E86 before E86.50 does not protect against a specific registry modification, and thus allows a local administrator to disable endpoint protection.

CVSS3: 2.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29gg-qvj7-46c7

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-29gg-8679-22q3

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-29gc-r2qh-wc5v

A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may disclose internal states of the app.

CVSS3: 4.3
0%
Низкий
28 дней назад
github логотип
GHSA-29gc-hgfp-33m5

A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-29g9-qwhc-hg77

Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-29g9-48v7-9r7c

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-29g8-w5j3-pph4

A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29g8-6h62-f7vc

Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29g7-m78g-3fx6

serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29g7-g95p-w4ww

Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

3%
Низкий
почти 4 года назад
github логотип
GHSA-29g7-9vcg-g9rm

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-29g5-m8v7-v564

Measured is vulnerable to Path Traversal attacks during class initialization

7 месяцев назад

Уязвимостей на страницу