Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 083

Количество 323 083

github логотип

GHSA-2457-vhh5-pcc4

почти 4 года назад

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

EPSS: Низкий
github логотип

GHSA-2457-jhx6-82v4

почти 4 года назад

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2457-j253-9gg8

почти 2 года назад

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21878.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2457-gqr3-47vq

больше 2 лет назад

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2457-2263-mm9f

около 4 лет назад

Memory leak in micronaut-core

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2456-m625-hcj6

больше 2 лет назад

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2456-4748-m2m2

3 месяца назад

Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2455-5p2g-hrg7

около 3 лет назад

A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2454-7cjj-wj2v

почти 4 года назад

Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.

EPSS: Низкий
github логотип

GHSA-2454-558w-967q

почти 4 года назад

PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

EPSS: Средний
github логотип

GHSA-2454-3wfw-h893

почти 4 года назад

The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2454-2h9h-6wx6

8 месяцев назад

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port 7777, and then downloading video via port 7778 and audio via port 7779.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2453-p5w4-2rh4

12 месяцев назад

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2453-mppf-46cj

около 2 месяцев назад

Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`

EPSS: Низкий
github логотип

GHSA-2452-xqvj-2c63

больше 3 лет назад

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2452-6xj8-jh47

около 1 года назад

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2452-3rwv-x89c

почти 5 лет назад

Out-of-bounds write

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-244x-f55f-vxmr

больше 2 лет назад

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-244x-c938-j3qj

8 месяцев назад

Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-244w-wm8j-4mcg

больше 2 лет назад

An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2457-vhh5-pcc4

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2457-jhx6-82v4

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVSS3: 6.6
1%
Низкий
почти 4 года назад
github логотип
GHSA-2457-j253-9gg8

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-21878.

CVSS3: 3.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-2457-gqr3-47vq

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2457-2263-mm9f

Memory leak in micronaut-core

CVSS3: 5.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2456-m625-hcj6

The Skype Legacy Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skype-status' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2456-4748-m2m2

Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2455-5p2g-hrg7

A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2454-7cjj-wj2v

Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2454-558w-967q

PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

11%
Средний
почти 4 года назад
github логотип
GHSA-2454-3wfw-h893

The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.

CVSS3: 5.5
5%
Низкий
почти 4 года назад
github логотип
GHSA-2454-2h9h-6wx6

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port 7777, and then downloading video via port 7778 and audio via port 7779.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2453-p5w4-2rh4

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

CVSS3: 4.6
0%
Низкий
12 месяцев назад
github логотип
GHSA-2453-mppf-46cj

Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2452-xqvj-2c63

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2452-6xj8-jh47

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2452-3rwv-x89c

Out-of-bounds write

CVSS3: 7.5
5%
Низкий
почти 5 лет назад
github логотип
GHSA-244x-f55f-vxmr

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.

CVSS3: 2.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-244x-c938-j3qj

Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.

CVSS3: 4.6
0%
Низкий
8 месяцев назад
github логотип
GHSA-244w-wm8j-4mcg

An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу