Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-2q3h-7f53-9q6j

8 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in wpmediadownload Media Library File Download media-download allows Cross Site Request Forgery.This issue affects Media Library File Download: from n/a through <= 1.4.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2q3g-jqmc-9v3v

около 4 лет назад

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2q3f-q5pq-g8wv

около 1 месяца назад

Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2q3f-g73p-pfc8

больше 4 лет назад

setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.

EPSS: Низкий
github логотип

GHSA-2q3f-cqqf-9p6p

около 4 лет назад

A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The affected systems do not properly validate input that is sent to the underlying message passing framework. This could allow an remote attacker to trigger a denial of service of the affected system.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2q3c-8r2c-m3xv

около 4 лет назад

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1089, CVE-2016-1091, CVE-2016-6944, CVE-2016-6945, CVE-2016-6946, CVE-2016-6949, CVE-2016-6952, CVE-2016-6953, CVE-2016-6961, CVE-2016-6962, CVE-2016-6963, CVE-2016-6964, CVE-2016-6967, CVE-2016-6968, CVE-2016-6969, CVE-2016-6971, CVE-2016-6979, CVE-2016-6988, and CVE-2016-6993.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2q39-w2hw-2pjm

больше 1 года назад

Infinispan Potential Out of Memory Error via REST Compare API Buffer API

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2q39-pgjq-rf75

около 4 лет назад

A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2q39-47wm-4cw8

9 месяцев назад

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2q38-w8jv-6jxm

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2q38-88hx-3qf7

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: recordmcount: Fix memory leaks in the uwrite function Common realloc mistake: 'file_append' nulled but not freed upon failure

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2q37-8v55-frjg

больше 4 лет назад

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512.

EPSS: Низкий
github логотип

GHSA-2q36-p4gw-j822

около 4 лет назад

The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect configuration display.

EPSS: Низкий
github логотип

GHSA-2q36-87w3-hm7h

около 4 лет назад

A vulnerability classified as critical has been found in Itech Classifieds Script 7.27. Affected is an unknown function of the file /subpage.php. The manipulation of the argument scat with the input =51' AND 4941=4941 AND 'hoCP'='hoCP leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2q35-gf6f-226r

около 4 лет назад

The Groupon Redemptions application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: Низкий
github логотип

GHSA-2q34-v688-cp5m

около 4 лет назад

Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2q34-5hcw-fqmv

около 4 лет назад

The Ultimate Target-Armored Sniper (aka air.wood.liame.ultimatetarget) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2q33-97fp-mrjr

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.

EPSS: Низкий
github логотип

GHSA-2q32-mvgg-6pfc

около 3 лет назад

Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configuration which allows local users to access data via network

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2q32-mmxp-hxr7

5 месяцев назад

HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2q3h-7f53-9q6j

Cross-Site Request Forgery (CSRF) vulnerability in wpmediadownload Media Library File Download media-download allows Cross Site Request Forgery.This issue affects Media Library File Download: from n/a through <= 1.4.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2q3g-jqmc-9v3v

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2q3f-q5pq-g8wv

Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image

CVSS3: 9.9
около 1 месяца назад
github логотип
GHSA-2q3f-g73p-pfc8

setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2q3f-cqqf-9p6p

A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The affected systems do not properly validate input that is sent to the underlying message passing framework. This could allow an remote attacker to trigger a denial of service of the affected system.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2q3c-8r2c-m3xv

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1089, CVE-2016-1091, CVE-2016-6944, CVE-2016-6945, CVE-2016-6946, CVE-2016-6949, CVE-2016-6952, CVE-2016-6953, CVE-2016-6961, CVE-2016-6962, CVE-2016-6963, CVE-2016-6964, CVE-2016-6967, CVE-2016-6968, CVE-2016-6969, CVE-2016-6971, CVE-2016-6979, CVE-2016-6988, and CVE-2016-6993.

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-2q39-w2hw-2pjm

Infinispan Potential Out of Memory Error via REST Compare API Buffer API

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2q39-pgjq-rf75

A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2q39-47wm-4cw8

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2q38-w8jv-6jxm

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69.

CVSS3: 8.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2q38-88hx-3qf7

In the Linux kernel, the following vulnerability has been resolved: recordmcount: Fix memory leaks in the uwrite function Common realloc mistake: 'file_append' nulled but not freed upon failure

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2q37-8v55-frjg

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2q36-p4gw-j822

The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect configuration display.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2q36-87w3-hm7h

A vulnerability classified as critical has been found in Itech Classifieds Script 7.27. Affected is an unknown function of the file /subpage.php. The manipulation of the argument scat with the input =51' AND 4941=4941 AND 'hoCP'='hoCP leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2q35-gf6f-226r

The Groupon Redemptions application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2q34-v688-cp5m

Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2q34-5hcw-fqmv

The Ultimate Target-Armored Sniper (aka air.wood.liame.ultimatetarget) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2q33-97fp-mrjr

Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2q32-mvgg-6pfc

Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configuration which allows local users to access data via network

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2q32-mmxp-hxr7

HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.

CVSS3: 3.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу