Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-23rx-79r7-6cpx

около 2 лет назад

Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-23rw-h3j3-5576

больше 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.

EPSS: Низкий
github логотип

GHSA-23rw-79p3-xgcm

почти 2 года назад

Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23rv-9x82-j4fq

около 1 месяца назад

A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-23rr-vcw7-54r8

больше 3 лет назад

An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote attackers to upload any files to the /tmp directory of the device through the webpage API. This can result in critical files being overwritten.

EPSS: Низкий
github логотип

GHSA-23rr-6phq-5p65

больше 2 лет назад

Jenkins mabl Plugin missing permission check

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23rq-jcxh-rmv6

почти 4 года назад

AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9.0" directory, which allows local users to gain privileges by replacing critical files.

EPSS: Низкий
github логотип

GHSA-23rp-qg5j-5vm7

почти 2 года назад

Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23rp-cxj2-cgcm

почти 3 года назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23rg-jpw2-p6r8

больше 2 лет назад

A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236207.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23rg-j4mh-2pmr

почти 4 года назад

Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.

EPSS: Низкий
github логотип

GHSA-23rg-hpwq-h786

почти 4 года назад

Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.

EPSS: Высокий
github логотип

GHSA-23rg-886v-9rqm

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-23rf-wq7x-gvq7

10 месяцев назад

WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically WebService::Xero uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses the rand() function.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23rc-q984-j9jx

почти 2 года назад

An issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximate attacker to disable the phone lock via the Walkie Talkie menu option.

CVSS3: 2.1
EPSS: Низкий
github логотип

GHSA-23rc-p8q2-gh38

больше 1 года назад

A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an unknown part of the file /admin/edit-brand.php. The manipulation of the argument Brand Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions the parameter "phone_number" to be affected. But this might be a mistake because the textbox field label is "Brand Name".

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-23r8-p7qp-rwcq

больше 3 лет назад

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23r8-fhxm-33gj

больше 3 лет назад

A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an unexpected restart of the netstack process on an affected device. The vulnerability is due to improper validation of IPv6 traffic sent through an affected device. An attacker could exploit this vulnerability by sending a malformed IPv6 packet through an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition while the netstack process restarts. A sustained attack could lead to a reboot of the device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23r7-hf6g-qqqg

больше 3 лет назад

CSRF vulnerability in Jenkins SOASTA CloudTest Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23r7-45cv-87cf

почти 4 года назад

create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23rx-79r7-6cpx

Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox

CVSS3: 8.2
около 2 лет назад
github логотип
GHSA-23rw-h3j3-5576

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23rw-79p3-xgcm

Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
6%
Низкий
почти 2 года назад
github логотип
GHSA-23rv-9x82-j4fq

A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-23rr-vcw7-54r8

An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote attackers to upload any files to the /tmp directory of the device through the webpage API. This can result in critical files being overwritten.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23rr-6phq-5p65

Jenkins mabl Plugin missing permission check

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23rq-jcxh-rmv6

AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9.0" directory, which allows local users to gain privileges by replacing critical files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-23rp-qg5j-5vm7

Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-23rp-cxj2-cgcm

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-23rg-jpw2-p6r8

A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236207.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23rg-j4mh-2pmr

Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.

1%
Низкий
почти 4 года назад
github логотип
GHSA-23rg-hpwq-h786

Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.

87%
Высокий
почти 4 года назад
github логотип
GHSA-23rg-886v-9rqm

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-23rf-wq7x-gvq7

WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically WebService::Xero uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses the rand() function.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-23rc-q984-j9jx

An issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximate attacker to disable the phone lock via the Walkie Talkie menu option.

CVSS3: 2.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-23rc-p8q2-gh38

A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an unknown part of the file /admin/edit-brand.php. The manipulation of the argument Brand Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions the parameter "phone_number" to be affected. But this might be a mistake because the textbox field label is "Brand Name".

CVSS3: 2.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-23r8-p7qp-rwcq

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

CVSS3: 8.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-23r8-fhxm-33gj

A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an unexpected restart of the netstack process on an affected device. The vulnerability is due to improper validation of IPv6 traffic sent through an affected device. An attacker could exploit this vulnerability by sending a malformed IPv6 packet through an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition while the netstack process restarts. A sustained attack could lead to a reboot of the device.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23r7-hf6g-qqqg

CSRF vulnerability in Jenkins SOASTA CloudTest Plugin

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23r7-45cv-87cf

create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу