Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-2975-qhjf-83mc

11 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 1.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2974-6593-2jqm

больше 3 лет назад

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

EPSS: Низкий
github логотип

GHSA-2974-5gjv-486c

больше 2 лет назад

A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2973-q4qx-mjf5

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle errors from btrfs_dec_ref() properly In walk_up_proc() we BUG_ON(ret) from btrfs_dec_ref(). This is incorrect, we have proper error handling here, return the error.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2973-f65x-7j53

около 2 лет назад

Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2972-gp35-c62r

8 месяцев назад

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-296x-83m2-v73h

больше 3 лет назад

vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.

EPSS: Низкий
github логотип

GHSA-296x-6w33-2mmq

больше 3 лет назад

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0920, CVE-2019-1005, CVE-2019-1055, CVE-2019-1080.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-296w-6qhq-gf92

больше 3 лет назад

Django denial of service via file upload naming

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-296v-w4c4-j24q

больше 3 лет назад

The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-296v-w233-rg6j

больше 2 лет назад

AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to the loss confidentiality, integrity, and authentication.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-296v-93wv-2fxf

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NanoSupport allows Reflected XSS. This issue affects NanoSupport: from n/a through 0.6.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-296q-wv58-25qg

больше 3 лет назад

JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-296q-vjcw-5f97

около 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eDoc Intelligence LLC eDoc Easy Tables allows SQL Injection.This issue affects eDoc Easy Tables: from n/a through 1.29.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-296q-rj83-g9rq

больше 1 года назад

Reflected Cross Site-Scripting (XSS) in Oveleon Cookiebar

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-296q-fx3q-6h3p

больше 1 года назад

Windows Networking Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-296p-gcc5-5329

9 месяцев назад

Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-296p-8497-97w8

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PWRS or (2) Description field when posting a new vehicle; (3) news title when creating news; (4) Name when creating a sub user; (5) group name when creating a group; or (6) dealer name, (7) first name, or (8) last name when changing a profile.

EPSS: Низкий
github логотип

GHSA-296m-vh37-r649

почти 4 года назад

Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long CONNECT_OPTIONS request, a different issue than CVE-2006-6222.

EPSS: Средний
github логотип

GHSA-296m-v66m-w8jp

больше 1 года назад

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2975-qhjf-83mc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 1.0.

CVSS3: 8.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2974-6593-2jqm

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2974-5gjv-486c

A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2973-q4qx-mjf5

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle errors from btrfs_dec_ref() properly In walk_up_proc() we BUG_ON(ret) from btrfs_dec_ref(). This is incorrect, we have proper error handling here, return the error.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2973-f65x-7j53

Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-2972-gp35-c62r

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-296x-83m2-v73h

vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-296x-6w33-2mmq

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0920, CVE-2019-1005, CVE-2019-1055, CVE-2019-1080.

CVSS3: 7.5
6%
Низкий
больше 3 лет назад
github логотип
GHSA-296w-6qhq-gf92

Django denial of service via file upload naming

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-296v-w4c4-j24q

The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-296v-w233-rg6j

AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to the loss confidentiality, integrity, and authentication.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-296v-93wv-2fxf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NanoSupport allows Reflected XSS. This issue affects NanoSupport: from n/a through 0.6.0.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-296q-wv58-25qg

JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-296q-vjcw-5f97

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eDoc Intelligence LLC eDoc Easy Tables allows SQL Injection.This issue affects eDoc Easy Tables: from n/a through 1.29.

CVSS3: 8.5
0%
Низкий
около 1 года назад
github логотип
GHSA-296q-rj83-g9rq

Reflected Cross Site-Scripting (XSS) in Oveleon Cookiebar

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-296q-fx3q-6h3p

Windows Networking Denial of Service Vulnerability

CVSS3: 7.5
14%
Средний
больше 1 года назад
github логотип
GHSA-296p-gcc5-5329

Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.

CVSS3: 4
0%
Низкий
9 месяцев назад
github логотип
GHSA-296p-8497-97w8

Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PWRS or (2) Description field when posting a new vehicle; (3) news title when creating news; (4) Name when creating a sub user; (5) group name when creating a group; or (6) dealer name, (7) first name, or (8) last name when changing a profile.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-296m-vh37-r649

Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long CONNECT_OPTIONS request, a different issue than CVE-2006-6222.

39%
Средний
почти 4 года назад
github логотип
GHSA-296m-v66m-w8jp

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.

CVSS3: 7.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу