Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-24wv-mv5m-xv4h

почти 3 года назад

redis-py Race Condition vulnerability

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-24wv-9vwj-q352

4 месяца назад

An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24wv-6c99-f843

8 месяцев назад

Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution

CVSS3: 10
EPSS: Средний
github логотип

GHSA-24wv-53mh-2995

больше 1 года назад

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-24wr-gx4f-pwrh

больше 3 лет назад

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

EPSS: Низкий
github логотип

GHSA-24wr-95c8-m99w

больше 3 лет назад

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-24wq-x2jh-mcf8

больше 3 лет назад

An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: Kernel-3.18. Android ID: A-31251599. References: N-CVE-2016-8400.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24wq-pwcm-cmqx

около 2 лет назад

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-24wq-mq98-wpxw

около 2 лет назад

Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24wq-3g32-9xrw

больше 2 лет назад

fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24wp-g4q8-wwcx

больше 3 лет назад

The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24wp-35x7-5hx9

больше 3 лет назад

The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression.

EPSS: Низкий
github логотип

GHSA-24wp-3277-85vf

11 месяцев назад

An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24wp-2mp6-6g43

почти 4 года назад

Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_PUBLISH.

EPSS: Средний
github логотип

GHSA-24wm-cqx7-gv2j

около 3 лет назад

A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability. This vulnerability is due to the use of a hardcoded value to encrypt a token used for certain APIs calls . An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP request. A successful exploit could allow the attacker to impersonate another valid user and execute commands with the privileges of that user account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24wm-5x58-mcgj

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows Reflected XSS. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24wm-5mgw-39c9

больше 3 лет назад

There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' in parser_parse_function_arguments in JerryScript 2.2.0.

EPSS: Низкий
github логотип

GHSA-24wj-qprw-6f7x

больше 3 лет назад

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-24wh-gwj5-gmw5

почти 4 года назад

Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long nickname in an MSN protocol message.

EPSS: Низкий
github логотип

GHSA-24wg-pxg5-46cj

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24wv-mv5m-xv4h

redis-py Race Condition vulnerability

CVSS3: 3.7
1%
Низкий
почти 3 года назад
github логотип
GHSA-24wv-9vwj-q352

An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-24wv-6c99-f843

Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution

CVSS3: 10
30%
Средний
8 месяцев назад
github логотип
GHSA-24wv-53mh-2995

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 7.2
14%
Средний
больше 1 года назад
github логотип
GHSA-24wr-gx4f-pwrh

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24wr-95c8-m99w

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

CVSS3: 6.1
14%
Средний
больше 3 лет назад
github логотип
GHSA-24wq-x2jh-mcf8

An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: Kernel-3.18. Android ID: A-31251599. References: N-CVE-2016-8400.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24wq-pwcm-cmqx

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 3.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-24wq-mq98-wpxw

Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

CVSS3: 5.4
2%
Низкий
около 2 лет назад
github логотип
GHSA-24wq-3g32-9xrw

fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24wp-g4q8-wwcx

The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24wp-35x7-5hx9

The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24wp-3277-85vf

An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.

CVSS3: 9.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-24wp-2mp6-6g43

Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_PUBLISH.

48%
Средний
почти 4 года назад
github логотип
GHSA-24wm-cqx7-gv2j

A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability. This vulnerability is due to the use of a hardcoded value to encrypt a token used for certain APIs calls . An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP request. A successful exploit could allow the attacker to impersonate another valid user and execute commands with the privileges of that user account.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-24wm-5x58-mcgj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows Reflected XSS. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-24wm-5mgw-39c9

There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' in parser_parse_function_arguments in JerryScript 2.2.0.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24wj-qprw-6f7x

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24wh-gwj5-gmw5

Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long nickname in an MSN protocol message.

3%
Низкий
почти 4 года назад
github логотип
GHSA-24wg-pxg5-46cj

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу