Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-34ch-j427-vrm7

6 месяцев назад

Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory integrity.

EPSS: Низкий
github логотип

GHSA-34ch-3j79-h23c

около 4 лет назад

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123.

EPSS: Низкий
github логотип

GHSA-34cg-xv63-mm68

около 4 лет назад

WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

EPSS: Низкий
github логотип

GHSA-34cg-jxcc-fq48

23 дня назад

Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-34cf-wqp2-q33c

около 4 лет назад

Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34cf-vv27-5wvh

около 4 лет назад

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

EPSS: Низкий
github логотип

GHSA-34cf-fm33-gcq4

больше 4 лет назад

In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34cc-vv8x-3hxc

около 4 лет назад

Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS Remote Code Execution Vulnerability."

EPSS: Средний
github логотип

GHSA-34cc-vppq-rvhp

больше 1 года назад

The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-34c9-mcf5-3rp3

27 дней назад

An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers. User-supplied data is reflected into JavaScript generated by the application, allowing attacker-controlled script execution within a victim's browser.

EPSS: Низкий
github логотип

GHSA-34c9-25wc-q378

6 месяцев назад

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-34c8-m39c-4pmr

больше 4 лет назад

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34c7-r8w9-5wv8

22 дня назад

Admin-only atom exhaustion: PUT /api/users tags list

EPSS: Низкий
github логотип

GHSA-34c7-243j-jmx6

около 2 месяцев назад

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34c6-vxrp-m855

11 месяцев назад

A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (either a third-party authenticator app or email-based 2FA) without presenting a valid authentication token or proving access to an already configured 2FA method. This bypasses 2FA and results in unauthorized access to accounts that are otherwise protected by 2FA.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-34c5-vc98-4c9x

около 4 лет назад

Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Printing). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data as well as unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34c5-v528-q6jq

около 4 лет назад

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly consider the possibility of kmalloc failure, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a long unencrypted auth ticket.

EPSS: Низкий
github логотип

GHSA-34c4-q534-xwc3

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-34c4-jgq5-j63f

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34c4-54g7-73vf

4 месяца назад

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34ch-j427-vrm7

Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory integrity.

0%
Низкий
6 месяцев назад
github логотип
GHSA-34ch-3j79-h23c

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123.

0%
Низкий
около 4 лет назад
github логотип
GHSA-34cg-xv63-mm68

WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

2%
Низкий
около 4 лет назад
github логотип
GHSA-34cg-jxcc-fq48

Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.

CVSS3: 2.7
0%
Низкий
23 дня назад
github логотип
GHSA-34cf-wqp2-q33c

Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-34cf-vv27-5wvh

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

4%
Низкий
около 4 лет назад
github логотип
GHSA-34cf-fm33-gcq4

In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-34cc-vv8x-3hxc

Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS Remote Code Execution Vulnerability."

24%
Средний
около 4 лет назад
github логотип
GHSA-34cc-vppq-rvhp

The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-34c9-mcf5-3rp3

An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers. User-supplied data is reflected into JavaScript generated by the application, allowing attacker-controlled script execution within a victim's browser.

0%
Низкий
27 дней назад
github логотип
GHSA-34c9-25wc-q378

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.

CVSS3: 9.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-34c8-m39c-4pmr

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-34c7-r8w9-5wv8

Admin-only atom exhaustion: PUT /api/users tags list

22 дня назад
github логотип
GHSA-34c7-243j-jmx6

Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-34c6-vxrp-m855

A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (either a third-party authenticator app or email-based 2FA) without presenting a valid authentication token or proving access to an already configured 2FA method. This bypasses 2FA and results in unauthorized access to accounts that are otherwise protected by 2FA.

CVSS3: 9.1
1%
Низкий
11 месяцев назад
github логотип
GHSA-34c5-vc98-4c9x

Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Printing). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data as well as unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/...

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-34c5-v528-q6jq

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly consider the possibility of kmalloc failure, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a long unencrypted auth ticket.

5%
Низкий
около 4 лет назад
github логотип
GHSA-34c4-q534-xwc3

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-34c4-jgq5-j63f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34c4-54g7-73vf

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

CVSS3: 7.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу