Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-22vf-p665-w63c

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aesopinteractive Aesop Story Engine allows Stored XSS.This issue affects Aesop Story Engine: from n/a through 2.3.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22vc-cp5h-m3m9

около 1 месяца назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Premium Addons for Elementor: from n/a through <= 4.11.53.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22vc-9pq7-fp6q

около 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18340.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22vc-92p3-x699

около 2 лет назад

Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22vc-5pgw-644q

около 3 лет назад

KubeView vulnerable to full cluster takeover due to improper authentication

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-22v9-p596-vfhg

почти 4 года назад

Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.

EPSS: Низкий
github логотип

GHSA-22v9-2p6r-qwwx

11 месяцев назад

Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22v8-p7h2-rj7p

8 месяцев назад

Markdownify MCP Server allows attackers to read arbitrary files

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22v8-m2j9-v5f6

почти 4 года назад

Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22v7-w6c5-v4rr

больше 3 лет назад

Apache Ranger Access Restriction Bypass

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22v7-v3mj-pm8r

почти 2 года назад

Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-22v6-vh64-279g

больше 3 лет назад

There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22v6-4f2p-rcq7

больше 3 лет назад

Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS v3.0 Base Score 4.7 (Integrity impacts).

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-22v5-q59j-h85m

8 месяцев назад

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22v5-h5m8-j4hf

почти 4 года назад

ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-22v5-644q-6x94

7 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita allows PHP Local File Inclusion. This issue affects Zita: from n/a through 1.6.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-22v4-7fpv-5gx7

почти 4 года назад

XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22v4-3qpp-69q8

12 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-22v3-g286-xrpf

14 дней назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-22v3-6xfr-m72g

больше 3 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1752.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22vf-p665-w63c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aesopinteractive Aesop Story Engine allows Stored XSS.This issue affects Aesop Story Engine: from n/a through 2.3.2.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-22vc-cp5h-m3m9

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Premium Addons for Elementor: from n/a through <= 4.11.53.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-22vc-9pq7-fp6q

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18340.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-22vc-92p3-x699

Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-22vc-5pgw-644q

KubeView vulnerable to full cluster takeover due to improper authentication

CVSS3: 9.8
93%
Критический
около 3 лет назад
github логотип
GHSA-22v9-p596-vfhg

Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22v9-2p6r-qwwx

Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-22v8-p7h2-rj7p

Markdownify MCP Server allows attackers to read arbitrary files

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-22v8-m2j9-v5f6

Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-22v7-w6c5-v4rr

Apache Ranger Access Restriction Bypass

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22v7-v3mj-pm8r

Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability

CVSS3: 8.8
79%
Высокий
почти 2 года назад
github логотип
GHSA-22v6-vh64-279g

There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22v6-4f2p-rcq7

Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS v3.0 Base Score 4.7 (Integrity impacts).

CVSS3: 4.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22v5-q59j-h85m

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-22v5-h5m8-j4hf

ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22v5-644q-6x94

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita allows PHP Local File Inclusion. This issue affects Zita: from n/a through 1.6.5.

CVSS3: 8.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-22v4-7fpv-5gx7

XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-22v4-3qpp-69q8

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

12 месяцев назад
github логотип
GHSA-22v3-g286-xrpf

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 8.2
0%
Низкий
14 дней назад
github логотип
GHSA-22v3-6xfr-m72g

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1752.

24%
Средний
больше 3 лет назад

Уязвимостей на страницу