Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-2824-3r6m-mjx4

около 4 лет назад

IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 214617.

EPSS: Низкий
github логотип

GHSA-2823-wfgm-j3hr

10 месяцев назад

open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2822-72rm-gg4h

больше 1 года назад

Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting in a DoS. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2822-476f-3j55

10 месяцев назад

Missing Authorization vulnerability in fromdoppler Doppler Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Doppler Forms: from n/a through 2.4.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-27xx-mxf2-ph5m

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-27xx-c7h4-4vc8

больше 3 лет назад

Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-27xx-9jff-78j2

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the web server in IBM Domino 8.5.x before 8.5.3 FP6 IF8 and 9.x before 9.0.1 FP4, when Webmail is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYH9WYPR5.

EPSS: Низкий
github логотип

GHSA-27xx-4333-8mw4

почти 4 года назад

PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.

EPSS: Низкий
github логотип

GHSA-27xw-w55h-qcr4

больше 3 лет назад

In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172908358

EPSS: Низкий
github логотип

GHSA-27xw-q7rh-9mrw

больше 3 лет назад

A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27xw-phm9-jmx3

больше 3 лет назад

The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.

EPSS: Низкий
github логотип

GHSA-27xw-p8v6-9jjr

около 7 лет назад

Spring Security vulnerable to Authorization Bypass

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-27xw-5882-cqhf

почти 4 года назад

Windows Graphics Component Remote Code Execution Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27xv-cgv3-x596

почти 4 года назад

PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.

EPSS: Низкий
github логотип

GHSA-27xv-9p99-hj75

почти 4 года назад

Vidalia bundle before 0.1.2.18, when running on Windows, installs Privoxy with a configuration file (config.txt or config) that contains an insecure enable-remote-http-toggle setting, which allows remote attackers to bypass intended access restrictions and modify configuration.

EPSS: Низкий
github логотип

GHSA-27xr-j3f5-jw66

больше 3 лет назад

An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27xr-5mwg-m2hh

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL associated with the management screen.

EPSS: Низкий
github логотип

GHSA-27xq-wwxh-hrf6

около 1 месяца назад

Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27xq-w3jc-436c

около 2 лет назад

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-27xq-hgcj-7p95

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WisdmLabs Edwiser Bridge allows Reflected XSS. This issue affects Edwiser Bridge: from n/a through 3.0.8.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2824-3r6m-mjx4

IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 214617.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2823-wfgm-j3hr

open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.

CVSS3: 3.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2822-72rm-gg4h

Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting in a DoS. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2822-476f-3j55

Missing Authorization vulnerability in fromdoppler Doppler Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Doppler Forms: from n/a through 2.4.5.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-27xx-mxf2-ph5m

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-27xx-c7h4-4vc8

Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-27xx-9jff-78j2

Cross-site scripting (XSS) vulnerability in the web server in IBM Domino 8.5.x before 8.5.3 FP6 IF8 and 9.x before 9.0.1 FP4, when Webmail is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYH9WYPR5.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xx-4333-8mw4

PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.

7%
Низкий
почти 4 года назад
github логотип
GHSA-27xw-w55h-qcr4

In ih264e_fmt_conv_422i_to_420sp of ih264e_fmt_conv.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172908358

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xw-q7rh-9mrw

A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-27xw-phm9-jmx3

The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-27xw-p8v6-9jjr

Spring Security vulnerable to Authorization Bypass

CVSS3: 7.4
0%
Низкий
около 7 лет назад
github логотип
GHSA-27xw-5882-cqhf

Windows Graphics Component Remote Code Execution Vulnerability.

CVSS3: 7.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-27xv-cgv3-x596

PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.

0%
Низкий
почти 4 года назад
github логотип
GHSA-27xv-9p99-hj75

Vidalia bundle before 0.1.2.18, when running on Windows, installs Privoxy with a configuration file (config.txt or config) that contains an insecure enable-remote-http-toggle setting, which allows remote attackers to bypass intended access restrictions and modify configuration.

0%
Низкий
почти 4 года назад
github логотип
GHSA-27xr-j3f5-jw66

An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xr-5mwg-m2hh

Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL associated with the management screen.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27xq-wwxh-hrf6

Missing Authorization vulnerability in WPFunnels Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through <= 1.1.12.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-27xq-w3jc-436c

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through 7.1.1 and 7.0.0 through 7.0.2 and 6.7.0 through 6.7.8 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.2 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via via crafted API requests.

CVSS3: 10
6%
Низкий
около 2 лет назад
github логотип
GHSA-27xq-hgcj-7p95

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WisdmLabs Edwiser Bridge allows Reflected XSS. This issue affects Edwiser Bridge: from n/a through 3.0.8.

CVSS3: 7.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу