Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 903

Количество 325 903

github логотип

GHSA-2fr7-cc7p-p45q

больше 2 лет назад

Data leak of password hash through change requests

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2fr7-cc4f-wh98

8 дней назад

OpenSTAManager: SQL Injection via Aggiornamenti Module

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fr6-xf6c-rwpx

почти 4 года назад

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1278.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fr2-x46r-5xjg

больше 3 лет назад

Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2fqx-qm63-xqgr

почти 4 года назад

The Hobby Lobby Stores (aka com.hobbylobbystores.android) application 2.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2fqx-9j9h-4f77

около 1 года назад

Missing Authorization vulnerability in NotFound LTL Freight Quotes – Unishippers Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LTL Freight Quotes – Unishippers Edition: from n/a through 2.5.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fqw-v698-338m

почти 4 года назад

Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.

EPSS: Низкий
github логотип

GHSA-2fqw-684c-pvp7

больше 4 лет назад

An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2fqv-m268-vx6f

почти 4 года назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Stored Procedure). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2fqv-h3r5-m4vf

больше 8 лет назад

Cross Site Scripting (XSS) in plotly.js

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2fqv-9f8v-r6j4

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix NULL Dereference in asoc_qcom_lpass_cpu_platform_probe() A devm_kzalloc() in asoc_qcom_lpass_cpu_platform_probe() could possibly return NULL pointer. NULL Pointer Dereference may be triggerred without addtional check. Add a NULL check for the returned pointer.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fqr-cx7q-3ph8

больше 1 года назад

openstack-heat may disclose sensitive information

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2fqr-9mfm-jj9x

почти 4 года назад

The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authentication information or (2) obtaining and replaying the PCZQX02 authentication cookie from the browser.

EPSS: Низкий
github логотип

GHSA-2fqp-gw29-6924

почти 4 года назад

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.

EPSS: Низкий
github логотип

GHSA-2fqm-p827-242q

10 месяцев назад

Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with program files crc32.C. This vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib (WITH_SYSTEM_ZLIB=FALSE).

EPSS: Низкий
github логотип

GHSA-2fqm-m4r2-fh98

почти 3 года назад

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2fqm-grvm-7h89

почти 4 года назад

Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.

EPSS: Средний
github логотип

GHSA-2fqj-v35v-q68v

4 месяца назад

SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2fqj-hp28-886h

почти 4 года назад

A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2fqh-vmvf-c822

больше 3 лет назад

A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fr7-cc7p-p45q

Data leak of password hash through change requests

CVSS3: 7.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2fr7-cc4f-wh98

OpenSTAManager: SQL Injection via Aggiornamenti Module

CVSS3: 8.8
0%
Низкий
8 дней назад
github логотип
GHSA-2fr6-xf6c-rwpx

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1278.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2fr2-x46r-5xjg

Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fqx-qm63-xqgr

The Hobby Lobby Stores (aka com.hobbylobbystores.android) application 2.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fqx-9j9h-4f77

Missing Authorization vulnerability in NotFound LTL Freight Quotes – Unishippers Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LTL Freight Quotes – Unishippers Edition: from n/a through 2.5.8.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2fqw-v698-338m

Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2fqw-684c-pvp7

An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.

CVSS3: 8.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2fqv-m268-vx6f

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Stored Procedure). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fqv-h3r5-m4vf

Cross Site Scripting (XSS) in plotly.js

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
github логотип
GHSA-2fqv-9f8v-r6j4

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix NULL Dereference in asoc_qcom_lpass_cpu_platform_probe() A devm_kzalloc() in asoc_qcom_lpass_cpu_platform_probe() could possibly return NULL pointer. NULL Pointer Dereference may be triggerred without addtional check. Add a NULL check for the returned pointer.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fqr-cx7q-3ph8

openstack-heat may disclose sensitive information

CVSS3: 5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fqr-9mfm-jj9x

The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authentication information or (2) obtaining and replaying the PCZQX02 authentication cookie from the browser.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fqp-gw29-6924

IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194451.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fqm-p827-242q

Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with program files crc32.C. This vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib (WITH_SYSTEM_ZLIB=FALSE).

0%
Низкий
10 месяцев назад
github логотип
GHSA-2fqm-m4r2-fh98

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

CVSS3: 8.1
5%
Низкий
почти 3 года назад
github логотип
GHSA-2fqm-grvm-7h89

Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.

23%
Средний
почти 4 года назад
github логотип
GHSA-2fqj-v35v-q68v

SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2fqj-hp28-886h

A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

CVSS3: 8.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-2fqh-vmvf-c822

A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу