Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-26vq-f7w9-38r3

больше 3 лет назад

SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.

EPSS: Низкий
github логотип

GHSA-26vp-298r-fj8f

больше 3 лет назад

In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185193932

EPSS: Низкий
github логотип

GHSA-26vj-q53w-3g76

9 месяцев назад

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-26vj-jqr4-v7fv

больше 2 лет назад

Dynamics 365 Finance Spoofing Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26vh-pr9j-whxx

почти 4 года назад

Unspecified vulnerability in the wpprop code for Project EROS bbsengine before 20060622-0315 has unknown impact and remote attack vectors via [img] tags, possibly cross-site scripting (XSS).

EPSS: Низкий
github логотип

GHSA-26vh-hjq5-fv9v

около 1 года назад

Missing Authorization vulnerability in wppal Easy Captcha allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Captcha: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26vg-2p3j-9wv3

больше 3 лет назад

A vulnerability in TCP port management in Cisco ONS 15454 Series Multiservice Provisioning Platforms could allow an unauthenticated, remote attacker to cause the controller card to unexpectedly reload. More Information: CSCuw26032. Known Affected Releases: 10.51.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26vc-chp7-cj4q

больше 3 лет назад

u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Voice & Music in Bitra, Nicobar, Saipan, SM6150, SM8150, SM8250, SXR2130

EPSS: Низкий
github логотип

GHSA-26vc-7jr9-jq6g

больше 3 лет назад

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.

EPSS: Низкий
github логотип

GHSA-26v9-qvmq-8frg

больше 3 лет назад

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

EPSS: Низкий
github логотип

GHSA-26v8-q35j-h6q9

больше 3 лет назад

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26v8-ffh8-7vqg

больше 3 лет назад

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-26v8-8f97-fq68

почти 3 года назад

H3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-26v7-7j6w-h2wc

больше 3 лет назад

xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."

EPSS: Низкий
github логотип

GHSA-26v6-wwwv-j4cc

больше 1 года назад

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26v6-w6fw-rh94

больше 7 лет назад

Apache Camel can allow remote attackers to execute arbitrary commands

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-26v6-w2vj-4j4v

больше 3 лет назад

The Big Win Slots - Slot Machines (aka com.gosub60.BigWinSlots) application 1.11.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-26v6-r4x8-vv44

больше 3 лет назад

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-26v6-mp3h-qg6h

больше 3 лет назад

The JavaScript implementation in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

EPSS: Средний
github логотип

GHSA-26v6-j796-w9w7

11 месяцев назад

A vulnerability, which was classified as critical, was found in VAM Virtual Airlines Manager up to 2.6.2. Affected is an unknown function of the file /vam/index.php of the component HTTP GET Parameter Handler. The manipulation of the argument ID/registry_id/plane_icao leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26vq-f7w9-38r3

SES Evolution before 2.1.0 allows duplicating an existing security policy by leveraging access of a user having read-only access to security policies.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26vp-298r-fj8f

In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-185193932

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26vj-q53w-3g76

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-26vj-jqr4-v7fv

Dynamics 365 Finance Spoofing Vulnerability

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26vh-pr9j-whxx

Unspecified vulnerability in the wpprop code for Project EROS bbsengine before 20060622-0315 has unknown impact and remote attack vectors via [img] tags, possibly cross-site scripting (XSS).

0%
Низкий
почти 4 года назад
github логотип
GHSA-26vh-hjq5-fv9v

Missing Authorization vulnerability in wppal Easy Captcha allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Captcha: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-26vg-2p3j-9wv3

A vulnerability in TCP port management in Cisco ONS 15454 Series Multiservice Provisioning Platforms could allow an unauthenticated, remote attacker to cause the controller card to unexpectedly reload. More Information: CSCuw26032. Known Affected Releases: 10.51.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-26vc-chp7-cj4q

u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Voice & Music in Bitra, Nicobar, Saipan, SM6150, SM8150, SM8250, SXR2130

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26vc-7jr9-jq6g

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26v9-qvmq-8frg

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26v8-q35j-h6q9

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26v8-ffh8-7vqg

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
94%
Критический
больше 3 лет назад
github логотип
GHSA-26v8-8f97-fq68

H3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.

CVSS3: 4.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-26v7-7j6w-h2wc

xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-26v6-wwwv-j4cc

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

CVSS3: 5.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-26v6-w6fw-rh94

Apache Camel can allow remote attackers to execute arbitrary commands

CVSS3: 8.1
7%
Низкий
больше 7 лет назад
github логотип
GHSA-26v6-w2vj-4j4v

The Big Win Slots - Slot Machines (aka com.gosub60.BigWinSlots) application 1.11.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26v6-r4x8-vv44

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

CVSS3: 7.7
7%
Низкий
больше 3 лет назад
github логотип
GHSA-26v6-mp3h-qg6h

The JavaScript implementation in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

23%
Средний
больше 3 лет назад
github логотип
GHSA-26v6-j796-w9w7

A vulnerability, which was classified as critical, was found in VAM Virtual Airlines Manager up to 2.6.2. Affected is an unknown function of the file /vam/index.php of the component HTTP GET Parameter Handler. The manipulation of the argument ID/registry_id/plane_icao leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу