Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 363 419

Количество 363 419

github логотип

GHSA-3m9x-qjwr-9h5x

больше 2 лет назад

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3m9x-7phq-w66g

больше 4 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user with access to the DB2 instance account to leverage a fenced execution process to execute arbitrary code as root. IBM X-Force ID: 156567.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3m9x-2qfj-xvq4

почти 2 года назад

PHPExcel XXE Vulnerability

EPSS: Низкий
github логотип

GHSA-3m9w-44xv-rc3v

больше 4 лет назад

Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and CVE-2006-4777.

EPSS: Низкий
github логотип

GHSA-3m9v-ghrv-898r

около 4 лет назад

Microsoft Excel Security Feature Bypass Vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3m9q-xm72-wq62

почти 2 года назад

Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3m9q-w3gq-68j3

больше 3 лет назад

bgERP v22.31 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3m9q-mqh2-jf39

около 1 месяца назад

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-3m9q-9522-7fx6

около 4 лет назад

Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

CVSS3: 2.3
EPSS: Низкий
github логотип

GHSA-3m9q-37cm-v3j6

9 дней назад

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.

EPSS: Низкий
github логотип

GHSA-3m9p-gg83-8m75

около 4 лет назад

A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted PCB files. This could allow an attacker to execute code in the context of the current process. (FG-VD-22-038)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3m9p-8m3g-ppxv

больше 4 лет назад

Windows Installer Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-28440.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3m9m-rx9m-5pm3

около 2 месяцев назад

Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3m9m-hq7w-gxvp

больше 4 лет назад

In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3m9m-c43p-g4h3

около 2 лет назад

A vulnerability was found in itsourcecode Monbela Tourist Inn Online Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The identifier VDB-268865 was assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3m9m-24vh-39wx

4 месяца назад

Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations

EPSS: Низкий
github логотип

GHSA-3m9j-v59x-pvvm

больше 2 лет назад

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3m9j-mhpf-84wj

около 1 года назад

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3m9j-9gr2-vv75

больше 4 лет назад

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.

EPSS: Низкий
github логотип

GHSA-3m9j-8q5f-868v

больше 1 года назад

The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the mas_options function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3m9x-qjwr-9h5x

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVSS3: 5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3m9x-7phq-w66g

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user with access to the DB2 instance account to leverage a fenced execution process to execute arbitrary code as root. IBM X-Force ID: 156567.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3m9x-2qfj-xvq4

PHPExcel XXE Vulnerability

почти 2 года назад
github логотип
GHSA-3m9w-44xv-rc3v

Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and CVE-2006-4777.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3m9v-ghrv-898r

Microsoft Excel Security Feature Bypass Vulnerability.

CVSS3: 7.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-3m9q-xm72-wq62

Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

CVSS3: 7.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3m9q-w3gq-68j3

bgERP v22.31 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3m9q-mqh2-jf39

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 8.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3m9q-9522-7fx6

Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

CVSS3: 2.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-3m9q-37cm-v3j6

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.

0%
Низкий
9 дней назад
github логотип
GHSA-3m9p-gg83-8m75

A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted PCB files. This could allow an attacker to execute code in the context of the current process. (FG-VD-22-038)

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3m9p-8m3g-ppxv

Windows Installer Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-28440.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3m9m-rx9m-5pm3

Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3m9m-hq7w-gxvp

In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3m9m-c43p-g4h3

A vulnerability was found in itsourcecode Monbela Tourist Inn Online Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The identifier VDB-268865 was assigned to this vulnerability.

CVSS3: 7.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-3m9m-24vh-39wx

Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations

0%
Низкий
4 месяца назад
github логотип
GHSA-3m9j-v59x-pvvm

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3m9j-mhpf-84wj

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cache is not cleared after the files of one account are exported.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3m9j-9gr2-vv75

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3m9j-8q5f-868v

The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the mas_options function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу