Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-xqmq-3744-539p

больше 1 года назад

Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-xqmp-fxgv-xvq5

9 дней назад

libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handling

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xqmm-x45g-6wf4

11 месяцев назад

Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xqmh-wj7x-9rxf

почти 4 года назад

Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

EPSS: Низкий
github логотип

GHSA-xqmh-c3cf-jrc8

почти 4 года назад

IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqmg-px4m-r5qm

почти 4 года назад

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.

EPSS: Низкий
github логотип

GHSA-xqmg-px28-29cq

9 месяцев назад

Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqmg-8q55-7xxx

почти 4 года назад

The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.

EPSS: Низкий
github логотип

GHSA-xqmf-wf6x-2cx6

больше 3 лет назад

Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqmc-wh95-fg2q

почти 4 года назад

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xqmc-vc6c-2wmv

почти 4 года назад

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.

EPSS: Низкий
github логотип

GHSA-xqmc-v3x5-h7p2

больше 3 лет назад

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqmc-g86x-qfxp

больше 2 лет назад

Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xqm9-hpfh-qm5m

почти 4 года назад

Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence.

EPSS: Низкий
github логотип

GHSA-xqm9-g4jx-xvgw

почти 4 года назад

Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.

EPSS: Низкий
github логотип

GHSA-xqm9-6qmm-xrqh

1 день назад

Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Group, Category or Description parameters.

EPSS: Низкий
github логотип

GHSA-xqm9-4fqc-qh7w

почти 4 года назад

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS: Низкий
github логотип

GHSA-xqm9-2mv3-cvx4

больше 2 лет назад

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqm8-jv67-vcvj

больше 2 лет назад

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqm8-c3rv-5vpf

больше 1 года назад

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqmq-3744-539p

Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service.

CVSS3: 5.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqmp-fxgv-xvq5

libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handling

CVSS3: 5.9
0%
Низкий
9 дней назад
github логотип
GHSA-xqmm-x45g-6wf4

Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

CVSS3: 9.1
3%
Низкий
11 месяцев назад
github логотип
GHSA-xqmh-wj7x-9rxf

Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqmh-c3cf-jrc8

IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqmg-px4m-r5qm

In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xqmg-px28-29cq

Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xqmg-8q55-7xxx

The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqmf-wf6x-2cx6

Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xqmc-wh95-fg2q

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction.

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-xqmc-vc6c-2wmv

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqmc-v3x5-h7p2

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-xqmc-g86x-qfxp

Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.

CVSS3: 6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqm9-hpfh-qm5m

Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xqm9-g4jx-xvgw

Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqm9-6qmm-xrqh

Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Group, Category or Description parameters.

1 день назад
github логотип
GHSA-xqm9-4fqc-qh7w

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xqm9-2mv3-cvx4

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqm8-jv67-vcvj

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqm8-c3rv-5vpf

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.

CVSS3: 6.2
0%
Низкий
больше 1 года назад

Уязвимостей на страницу