Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 279

Количество 323 279

github логотип

GHSA-24x5-c472-vx8w

5 месяцев назад

A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. A remote attacker may be able to cause a denial-of-service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24x4-hpq6-x4j9

почти 4 года назад

Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter.

EPSS: Низкий
github логотип

GHSA-24x4-6qmh-88qg

около 4 лет назад

Use after free in `DecodePng` kernel

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-24x4-44mg-fffp

почти 4 года назад

Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photos/.

EPSS: Низкий
github логотип

GHSA-24x2-jv4m-57w2

3 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-24wx-mghc-gchm

почти 4 года назад

A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24wx-m9jq-x9f7

3 месяца назад

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24ww-mc5x-xc43

почти 5 лет назад

Man-in-the-middle attack in Apache Cassandra

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-24ww-hqf6-2c58

3 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-24ww-94h4-w44f

почти 4 года назад

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-24wv-qqjw-rp9w

почти 4 года назад

Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-24wv-mv5m-xv4h

около 3 лет назад

redis-py Race Condition vulnerability

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-24wv-9vwj-q352

6 месяцев назад

An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24wv-6c99-f843

9 месяцев назад

Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution

CVSS3: 10
EPSS: Средний
github логотип

GHSA-24wv-53mh-2995

больше 1 года назад

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-24wr-gx4f-pwrh

почти 4 года назад

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

EPSS: Низкий
github логотип

GHSA-24wr-95c8-m99w

почти 4 года назад

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-24wq-x2jh-mcf8

почти 4 года назад

An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: Kernel-3.18. Android ID: A-31251599. References: N-CVE-2016-8400.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24wq-pwcm-cmqx

больше 2 лет назад

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-24wq-mq98-wpxw

больше 2 лет назад

Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24x5-c472-vx8w

A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. A remote attacker may be able to cause a denial-of-service.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-24x4-hpq6-x4j9

Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-24x4-6qmh-88qg

Use after free in `DecodePng` kernel

CVSS3: 7.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-24x4-44mg-fffp

Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photos/.

7%
Низкий
почти 4 года назад
github логотип
GHSA-24x2-jv4m-57w2

Rejected reason: Not used

3 месяца назад
github логотип
GHSA-24wx-mghc-gchm

A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-24wx-m9jq-x9f7

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-24ww-mc5x-xc43

Man-in-the-middle attack in Apache Cassandra

CVSS3: 5.9
0%
Низкий
почти 5 лет назад
github логотип
GHSA-24ww-hqf6-2c58

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

3 месяца назад
github логотип
GHSA-24ww-94h4-w44f

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-24wv-qqjw-rp9w

Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVSS3: 4.6
0%
Низкий
почти 4 года назад
github логотип
GHSA-24wv-mv5m-xv4h

redis-py Race Condition vulnerability

CVSS3: 3.7
1%
Низкий
около 3 лет назад
github логотип
GHSA-24wv-9vwj-q352

An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-24wv-6c99-f843

Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution

CVSS3: 10
12%
Средний
9 месяцев назад
github логотип
GHSA-24wv-53mh-2995

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 7.2
9%
Низкий
больше 1 года назад
github логотип
GHSA-24wr-gx4f-pwrh

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

0%
Низкий
почти 4 года назад
github логотип
GHSA-24wr-95c8-m99w

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

CVSS3: 6.1
14%
Средний
почти 4 года назад
github логотип
GHSA-24wq-x2jh-mcf8

An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: Kernel-3.18. Android ID: A-31251599. References: N-CVE-2016-8400.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-24wq-pwcm-cmqx

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24wq-mq98-wpxw

Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

CVSS3: 5.4
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу