Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-33p6-99p4-x6p2

3 месяца назад

Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33p6-5jxp-p3x4

3 месяца назад

utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-33p5-m25c-cp6w

больше 3 лет назад

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33p5-6c3v-v29v

около 4 лет назад

Special crafted InPage document leads to arbitrary code execution in InPage reader.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33p4-8hxp-x9pp

больше 1 года назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Nikita Advanced WordPress Backgrounds allows Code Injection. This issue affects Advanced WordPress Backgrounds: from n/a through 1.12.4.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33p4-7h6v-86r2

больше 4 лет назад

Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

EPSS: Низкий
github логотип

GHSA-33p4-33f5-c62r

около 4 лет назад

Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38653.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33p3-36hv-c9p7

около 4 лет назад

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33p2-5mfj-r94r

около 4 лет назад

CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: Низкий
github логотип

GHSA-33p2-27pp-3pqr

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

EPSS: Низкий
github логотип

GHSA-33mx-vpmc-fg9c

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Jenst Add to Header allows Stored XSS. This issue affects Add to Header: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-33mx-q46m-2wfr

больше 4 лет назад

Pramati Server 3.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

EPSS: Низкий
github логотип

GHSA-33mw-q7rj-mjwj

6 месяцев назад

Django has Inefficient Algorithmic Complexity

EPSS: Низкий
github логотип

GHSA-33mw-354r-24rw

больше 4 лет назад

A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.

EPSS: Низкий
github логотип

GHSA-33mv-fjxj-2mx6

больше 1 года назад

Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33mv-8xj7-9fx2

около 4 лет назад

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33mr-h3pf-4jg7

больше 3 лет назад

RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH service port to disrupt service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33mq-pfqq-c55m

больше 4 лет назад

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

EPSS: Низкий
github логотип

GHSA-33mq-p8m3-73xj

почти 2 года назад

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-33mq-jqvv-g676

около 4 лет назад

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth" component. It allows attackers to obtain sensitive kernel memory-layout information via a crafted app that leverages device properties.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33p6-99p4-x6p2

Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-33p6-5jxp-p3x4

utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol

CVSS3: 10
0%
Низкий
3 месяца назад
github логотип
GHSA-33p5-m25c-cp6w

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-33p5-6c3v-v29v

Special crafted InPage document leads to arbitrary code execution in InPage reader.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-33p4-8hxp-x9pp

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Nikita Advanced WordPress Backgrounds allows Code Injection. This issue affects Advanced WordPress Backgrounds: from n/a through 1.12.4.

CVSS3: 5.4
больше 1 года назад
github логотип
GHSA-33p4-7h6v-86r2

Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-33p4-33f5-c62r

Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38653.

CVSS3: 7.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-33p3-36hv-c9p7

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-33p2-5mfj-r94r

CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

1%
Низкий
около 4 лет назад
github логотип
GHSA-33p2-27pp-3pqr

Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-33mx-vpmc-fg9c

Cross-Site Request Forgery (CSRF) vulnerability in Jenst Add to Header allows Stored XSS. This issue affects Add to Header: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-33mx-q46m-2wfr

Pramati Server 3.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

2%
Низкий
больше 4 лет назад
github логотип
GHSA-33mw-q7rj-mjwj

Django has Inefficient Algorithmic Complexity

1%
Низкий
6 месяцев назад
github логотип
GHSA-33mw-354r-24rw

A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-33mv-fjxj-2mx6

Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-33mv-8xj7-9fx2

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
5%
Низкий
около 4 лет назад
github логотип
GHSA-33mr-h3pf-4jg7

RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH service port to disrupt service.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33mq-pfqq-c55m

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

2%
Низкий
больше 4 лет назад
github логотип
GHSA-33mq-p8m3-73xj

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on the underlying operating system.

CVSS3: 7.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-33mq-jqvv-g676

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth" component. It allows attackers to obtain sensitive kernel memory-layout information via a crafted app that leverages device properties.

CVSS3: 5.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу