Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-232v-xqxf-3rrg

больше 3 лет назад

In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-228523213

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-232v-j27c-5pp6

3 месяца назад

REC in MCPJam inspector due to HTTP Endpoint exposes

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-232r-9jvp-5ffj

почти 4 года назад

European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-232r-6v76-wgpq

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-232r-66cg-79px

больше 7 лет назад

Paramiko not properly checking authentication before processing other requests

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-232r-27pv-pm68

почти 4 года назад

Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.

EPSS: Низкий
github логотип

GHSA-232q-w9mq-2c55

около 3 лет назад

The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-232q-v7rp-6ff8

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-232p-vwff-86mp

около 3 лет назад

Docker Swarm encrypted overlay network may be unauthenticated

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-232p-m442-j9m4

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: smc: Handle missing SCM device Commit ca61d6836e6f ("firmware: qcom: scm: fix a NULL-pointer dereference") makes it explicit that qcom_scm_get_tzmem_pool() can return NULL, therefore its users should handle this.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-232p-99pf-h332

почти 4 года назад

Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability appears to have been fixed in 14.3.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-232p-59mg-f98p

больше 3 лет назад

Microweber Cross-site Scripting can result in redirection to a malicious site

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-232m-xvr4-2347

почти 4 года назад

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-232m-53gr-9v22

почти 4 года назад

The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.

EPSS: Низкий
github логотип

GHSA-232g-vj6v-88w6

почти 4 года назад

An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of installed games to exploit this vulnerability and execute arbitrary code with elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-232g-h7w4-2pxj

около 4 лет назад

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1.0.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-232f-9f2g-m34q

почти 4 года назад

Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.

EPSS: Низкий
github логотип

GHSA-232f-8fc5-f649

почти 4 года назад

Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."

EPSS: Низкий
github логотип

GHSA-232f-66gw-9wfc

почти 4 года назад

A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2328-vc59-64q8

почти 4 года назад

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-232v-xqxf-3rrg

In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-228523213

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-232v-j27c-5pp6

REC in MCPJam inspector due to HTTP Endpoint exposes

CVSS3: 9.8
27%
Средний
3 месяца назад
github логотип
GHSA-232r-9jvp-5ffj

European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-232r-6v76-wgpq

Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-232r-66cg-79px

Paramiko not properly checking authentication before processing other requests

CVSS3: 9.8
21%
Средний
больше 7 лет назад
github логотип
GHSA-232r-27pv-pm68

Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.

5%
Низкий
почти 4 года назад
github логотип
GHSA-232q-w9mq-2c55

The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-232q-v7rp-6ff8

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-232p-vwff-86mp

Docker Swarm encrypted overlay network may be unauthenticated

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-232p-m442-j9m4

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: smc: Handle missing SCM device Commit ca61d6836e6f ("firmware: qcom: scm: fix a NULL-pointer dereference") makes it explicit that qcom_scm_get_tzmem_pool() can return NULL, therefore its users should handle this.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-232p-99pf-h332

Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability appears to have been fixed in 14.3.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-232p-59mg-f98p

Microweber Cross-site Scripting can result in redirection to a malicious site

CVSS3: 6.1
16%
Средний
больше 3 лет назад
github логотип
GHSA-232m-xvr4-2347

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-232m-53gr-9v22

The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.

0%
Низкий
почти 4 года назад
github логотип
GHSA-232g-vj6v-88w6

An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of installed games to exploit this vulnerability and execute arbitrary code with elevated privileges.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-232g-h7w4-2pxj

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1.0.8.

CVSS3: 9.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-232f-9f2g-m34q

Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.

1%
Низкий
почти 4 года назад
github логотип
GHSA-232f-8fc5-f649

Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."

0%
Низкий
почти 4 года назад
github логотип
GHSA-232f-66gw-9wfc

A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2328-vc59-64q8

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу