Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 322 820

Количество 322 820

github логотип

GHSA-294r-xq83-57q9

почти 4 года назад

The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-294r-c888-mvp7

почти 4 года назад

An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD card inserted by the primary user. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32523490.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-294r-867g-x8h5

почти 4 года назад

Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-294r-4892-r6wr

почти 4 года назад

md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-294q-5vvf-xj65

почти 2 года назад

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-294q-4m4m-vwq9

25 дней назад

The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global scope of smarter-analytics.php. This makes it possible for unauthenticated attackers to reset all plugin configuration and delete all per-page/per-post analytics settings via the 'reset' parameter.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-294q-4ffj-cf8j

почти 4 года назад

Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-294m-6544-vprq

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") forgot to fix up the depth check in the loop body in unflatten_dt_nodes() which makes it possible to overflow the nps[] buffer... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-294m-24v2-q6mw

почти 4 года назад

An issue was discovered on Samsung mobile devices with P(9.0) software. Secure Folder leaks preview data of recent apps. The Samsung ID is SVE-2018-13764 (March 2019).

EPSS: Низкий
github логотип

GHSA-294j-r53x-w786

почти 4 года назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-294j-98w5-p6q3

7 месяцев назад

A security flaw has been discovered in Ruijie NBR2100G-E up to 20250919. Affected by this issue is the function listAction of the file /itbox_pi/branch_passw.php?a=list. Performing manipulation of the argument city results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-294j-79hr-f57f

больше 3 лет назад

IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-294h-w6qc-2qx4

почти 4 года назад

An issue was discovered in Couchbase Server 5.5.0 and 6.0.0. The Eventing debug endpoint mishandles authentication and audit.

EPSS: Низкий
github логотип

GHSA-294h-r5v6-vw5x

почти 2 года назад

The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.18 via the search_posts function. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain post excerpts including those of draft and pending posts.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-294h-g237-97pw

почти 4 года назад

Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB file that triggers a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-294h-9fqc-xfq7

почти 4 года назад

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-294f-mx29-rgp2

почти 4 года назад

An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.

EPSS: Низкий
github логотип

GHSA-294f-6x8f-w547

почти 4 года назад

Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

EPSS: Низкий
github логотип

GHSA-294c-hx25-mgvq

больше 1 года назад

Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-294c-hpxh-5qrx

больше 2 лет назад

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

CVSS3: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-294r-xq83-57q9

The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-294r-c888-mvp7

An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD card inserted by the primary user. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32523490.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-294r-867g-x8h5

Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

2%
Низкий
почти 4 года назад
github логотип
GHSA-294r-4892-r6wr

md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-294q-5vvf-xj65

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

CVSS3: 7.5
92%
Критический
почти 2 года назад
github логотип
GHSA-294q-4m4m-vwq9

The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global scope of smarter-analytics.php. This makes it possible for unauthenticated attackers to reset all plugin configuration and delete all per-page/per-post analytics settings via the 'reset' parameter.

CVSS3: 5.3
25 дней назад
github логотип
GHSA-294q-4ffj-cf8j

Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-294m-6544-vprq

In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") forgot to fix up the depth check in the loop body in unflatten_dt_nodes() which makes it possible to overflow the nps[] buffer... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-294m-24v2-q6mw

An issue was discovered on Samsung mobile devices with P(9.0) software. Secure Folder leaks preview data of recent apps. The Samsung ID is SVE-2018-13764 (March 2019).

0%
Низкий
почти 4 года назад
github логотип
GHSA-294j-r53x-w786

ChakraCore RCE Vulnerability

CVSS3: 7.5
21%
Средний
почти 4 года назад
github логотип
GHSA-294j-98w5-p6q3

A security flaw has been discovered in Ruijie NBR2100G-E up to 20250919. Affected by this issue is the function listAction of the file /itbox_pi/branch_passw.php?a=list. Performing manipulation of the argument city results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-294j-79hr-f57f

IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-294h-w6qc-2qx4

An issue was discovered in Couchbase Server 5.5.0 and 6.0.0. The Eventing debug endpoint mishandles authentication and audit.

0%
Низкий
почти 4 года назад
github логотип
GHSA-294h-r5v6-vw5x

The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.18 via the search_posts function. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain post excerpts including those of draft and pending posts.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-294h-g237-97pw

Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB file that triggers a heap-based buffer overflow.

8%
Низкий
почти 4 года назад
github логотип
GHSA-294h-9fqc-xfq7

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-294f-mx29-rgp2

An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-294f-6x8f-w547

Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

0%
Низкий
почти 4 года назад
github логотип
GHSA-294c-hx25-mgvq

Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-294c-hpxh-5qrx

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

CVSS3: 5.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу