Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-2x45-7fc3-mxwq

около 1 года назад

php-jwt contains weak encryption

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x44-42qx-w2fx

больше 4 лет назад

Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature. (The domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.)

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2x43-7p4j-28px

около 4 лет назад

Vulnerability in the Oracle Solaris product of Oracle Systems (component: libsuri). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Solaris accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

EPSS: Низкий
github логотип

GHSA-2x43-6898-6w48

около 4 лет назад

The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8492, CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8482, CVE-2017-8480, CVE-2017-8479, CVE-2017-8478, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-0300, CVE-2017-0299, and CVE-2017-0297.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2x43-2jxv-g4v9

около 4 лет назад

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4738.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x42-x3cv-9629

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix out-of-bounds memset in command slot handling The remaining space in a command slot may be smaller than the size of the command header. Clearing the command header with memset() before verifying the available slot space can result in an out-of-bounds write and memory corruption. Fix this by moving the memset() call after the size validation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2x42-r98f-w3cp

больше 4 лет назад

The TFTP server for Red-M 1050 (Bluetooth Access Point) can not be disabled and makes it easier for remote attackers to crack the administration password via brute force methods.

EPSS: Низкий
github логотип

GHSA-2x42-h92q-qcvm

больше 3 лет назад

Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2x3x-ch63-vcqp

больше 4 лет назад

Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.

EPSS: Низкий
github логотип

GHSA-2x3w-f554-wxw8

около 4 лет назад

Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2x3v-jgm9-v94x

около 4 лет назад

An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402548.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2x3v-hc5x-cgrg

больше 1 года назад

Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-2x3r-rpmr-wmwh

больше 3 лет назад

The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2x3r-qhc4-2pjr

почти 2 года назад

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x3r-hwv5-p32x

около 1 года назад

Deno's AES GCM authentication tags are not verified

EPSS: Низкий
github логотип

GHSA-2x3r-854j-qm5f

25 дней назад

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting crafted requests through configured input paths, bypassing intended policy checks.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2x3r-7jgm-gh8x

больше 3 лет назад

Remote code execution in Voyager

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2x3r-7c7j-hfjv

около 1 года назад

A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by this vulnerability is an unknown functionality of the file /adm/index.php of the component Cadastro de Administrador Page. The manipulation of the argument Name/Usuário leads to cross site scripting. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2x3r-3grm-f4ww

около 3 лет назад

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2x3q-v3g7-gh3w

больше 4 лет назад

Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via an image with a crafted ColorSync profile, which triggers memory corruption.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2x45-7fc3-mxwq

php-jwt contains weak encryption

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2x44-42qx-w2fx

Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature. (The domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.)

CVSS3: 4.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2x43-7p4j-28px

Vulnerability in the Oracle Solaris product of Oracle Systems (component: libsuri). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Solaris accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

0%
Низкий
около 4 лет назад
github логотип
GHSA-2x43-6898-6w48

The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-8492, CVE-2017-8491, CVE-2017-8490, CVE-2017-8489, CVE-2017-8488, CVE-2017-8485, CVE-2017-8482, CVE-2017-8480, CVE-2017-8479, CVE-2017-8478, CVE-2017-8476, CVE-2017-8474, CVE-2017-8469, CVE-2017-8462, CVE-2017-0300, CVE-2017-0299, and CVE-2017-0297.

CVSS3: 5
5%
Низкий
около 4 лет назад
github логотип
GHSA-2x43-2jxv-g4v9

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4738.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2x42-x3cv-9629

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix out-of-bounds memset in command slot handling The remaining space in a command slot may be smaller than the size of the command header. Clearing the command header with memset() before verifying the available slot space can result in an out-of-bounds write and memory corruption. Fix this by moving the memset() call after the size validation.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-2x42-r98f-w3cp

The TFTP server for Red-M 1050 (Bluetooth Access Point) can not be disabled and makes it easier for remote attackers to crack the administration password via brute force methods.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2x42-h92q-qcvm

Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.

CVSS3: 6.5
21%
Средний
больше 3 лет назад
github логотип
GHSA-2x3x-ch63-vcqp

Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2x3w-f554-wxw8

Adobe Framemaker versions 2019.0.4 and below have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2x3v-jgm9-v94x

An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402548.

CVSS3: 7
2%
Низкий
около 4 лет назад
github логотип
GHSA-2x3v-hc5x-cgrg

Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2x3r-rpmr-wmwh

The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2x3r-qhc4-2pjr

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2x3r-hwv5-p32x

Deno's AES GCM authentication tags are not verified

0%
Низкий
около 1 года назад
github логотип
GHSA-2x3r-854j-qm5f

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting crafted requests through configured input paths, bypassing intended policy checks.

CVSS3: 8
0%
Низкий
25 дней назад
github логотип
GHSA-2x3r-7jgm-gh8x

Remote code execution in Voyager

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2x3r-7c7j-hfjv

A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by this vulnerability is an unknown functionality of the file /adm/index.php of the component Cadastro de Administrador Page. The manipulation of the argument Name/Usuário leads to cross site scripting. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2x3r-3grm-f4ww

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2x3q-v3g7-gh3w

Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via an image with a crafted ColorSync profile, which triggers memory corruption.

4%
Низкий
больше 4 лет назад

Уязвимостей на страницу