Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4pf2-37p5-x5fg

10 дней назад

Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4pcx-rr5j-rxx3

больше 4 лет назад

IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML source code.

EPSS: Низкий
github логотип

GHSA-4pcx-m3hv-2jw5

11 месяцев назад

Missing Authorization vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder.This issue affects Cost Calculator Builder: from n/a through <= 3.5.32.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4pcw-2chr-m4jj

больше 4 лет назад

Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pcv-mg8v-vrgf

3 месяца назад

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pcv-m5q3-f7q7

больше 4 лет назад

Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-4pcr-226x-2w24

больше 4 лет назад

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336700.

EPSS: Низкий
github логотип

GHSA-4pcq-7rw3-2jvx

почти 2 года назад

In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure with no additional execution privileges needed.  User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pcp-h2jw-cp6p

больше 1 года назад

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-4pcp-9v53-4m7x

10 месяцев назад

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4pcm-h7xx-qpcq

больше 3 лет назад

In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238716781References: N/A

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pcm-9qq9-65qc

больше 4 лет назад

IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.

EPSS: Средний
github логотип

GHSA-4pcj-vr36-r5w4

больше 4 лет назад

In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pcj-qpx3-mjmx

2 месяца назад

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4pcj-2vcf-4q8j

около 1 года назад

A security flaw has been discovered in SourceCodester Hotel Reservation System 1.0. This affects an unknown part of the file /admin/updateabout.php. The manipulation of the argument address results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4pch-258r-x42r

больше 4 лет назад

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.

EPSS: Низкий
github логотип

GHSA-4pcg-wr6c-h9cq

почти 4 года назад

fastify/websocket vulnerable to uncaught exception via crash on malformed packet

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4pcg-pjp5-3mc6

около 1 года назад

Concrete CMS vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page

EPSS: Низкий
github логотип

GHSA-4pcg-mhp2-2qh7

9 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-4pcg-gfm2-cvg4

почти 3 года назад

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4pf2-37p5-x5fg

Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.

CVSS3: 7.4
0%
Низкий
10 дней назад
github логотип
GHSA-4pcx-rr5j-rxx3

IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML source code.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pcx-m3hv-2jw5

Missing Authorization vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder.This issue affects Cost Calculator Builder: from n/a through <= 3.5.32.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-4pcw-2chr-m4jj

Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pcv-mg8v-vrgf

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

CVSS3: 8.8
3 месяца назад
github логотип
GHSA-4pcv-m5q3-f7q7

Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS3: 7.8
24%
Средний
больше 4 лет назад
github логотип
GHSA-4pcr-226x-2w24

In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336700.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pcq-7rw3-2jvx

In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure with no additional execution privileges needed.  User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4pcp-h2jw-cp6p

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user.

CVSS3: 2.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4pcp-9v53-4m7x

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS3: 8
2%
Низкий
10 месяцев назад
github логотип
GHSA-4pcm-h7xx-qpcq

In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238716781References: N/A

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4pcm-9qq9-65qc

IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.

68%
Средний
больше 4 лет назад
github логотип
GHSA-4pcj-vr36-r5w4

In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.c.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pcj-qpx3-mjmx

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

CVSS3: 3.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4pcj-2vcf-4q8j

A security flaw has been discovered in SourceCodester Hotel Reservation System 1.0. This affects an unknown part of the file /admin/updateabout.php. The manipulation of the argument address results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4pch-258r-x42r

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pcg-wr6c-h9cq

fastify/websocket vulnerable to uncaught exception via crash on malformed packet

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-4pcg-pjp5-3mc6

Concrete CMS vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page

0%
Низкий
около 1 года назад
github логотип
GHSA-4pcg-mhp2-2qh7

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

9 месяцев назад
github логотип
GHSA-4pcg-gfm2-cvg4

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

CVSS3: 6.8
1%
Низкий
почти 3 года назад

Уязвимостей на страницу