Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2grw-cv7g-wxwm

около 2 лет назад

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This issue affects Photo Gallery by Ays: from n/a before 5.7.1.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-2grr-frxh-j4fg

около 4 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

EPSS: Средний
github логотип

GHSA-2grq-h2qw-x3px

больше 4 лет назад

There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process and service abnormal. Affected product versions include: CloudEngine 12800 V200R019C10SPC800, V200R019C10SPC900; CloudEngine 5800 V200R019C10SPC800, V200R020C00SPC600; CloudEngine 6800 versions V200R019C10SPC800, V200R019C10SPC900, V200R020C00SPC600, V300R020C00SPC200; CloudEngine 7800 V200R019C10SPC800.

EPSS: Низкий
github логотип

GHSA-2grp-34h8-p48c

больше 4 лет назад

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2grm-wcfh-hhgj

12 месяцев назад

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2grm-pxpf-4j6v

около 4 лет назад

A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.

EPSS: Низкий
github логотип

GHSA-2grj-9rmj-333f

около 4 лет назад

SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2grj-6p8q-gfq4

8 месяцев назад

There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2grh-pj67-4p6p

больше 4 лет назад

In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2grh-hm3w-w7hv

почти 5 лет назад

Race condition in tokio

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2grh-gr37-2283

больше 2 лет назад

Solr search discloses email addresses of users

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-2grg-mh77-gc8w

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Social Book Facebook Clone 2010 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) signup.php, (2) lostpass.php, (3) login.php, (4) index.php, (5) help_tos.php, (6) help_contact.php, or (7) help.php.

EPSS: Низкий
github логотип

GHSA-2grg-m45x-hwh6

около 4 лет назад

IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2grg-6j4w-c3v4

около 4 лет назад

CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2grf-mxvh-rqrf

около 4 лет назад

PhpSecInfo 0.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Test/Test_Suhosin.php and certain other files.

EPSS: Низкий
github логотип

GHSA-2grc-rqmm-2cj8

почти 2 года назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2grc-9vqr-3q7x

около 4 лет назад

Unspecified vulnerability in the Oracle Retail Central Office component in Oracle Industry Applications 13.1, 13.2, 13.3, and 13.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Customer Operations (Add, Search).

EPSS: Низкий
github логотип

GHSA-2grc-69vf-g6vr

около 4 лет назад

PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fileroot] parameter.

EPSS: Низкий
github логотип

GHSA-2gr9-gwrg-jc3v

6 месяцев назад

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gr9-3f9h-5pc3

больше 4 лет назад

Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2grw-cv7g-wxwm

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This issue affects Photo Gallery by Ays: from n/a before 5.7.1.

CVSS3: 3.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2grr-frxh-j4fg

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

22%
Средний
около 4 лет назад
github логотип
GHSA-2grq-h2qw-x3px

There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process and service abnormal. Affected product versions include: CloudEngine 12800 V200R019C10SPC800, V200R019C10SPC900; CloudEngine 5800 V200R019C10SPC800, V200R020C00SPC600; CloudEngine 6800 versions V200R019C10SPC800, V200R019C10SPC900, V200R020C00SPC600, V300R020C00SPC200; CloudEngine 7800 V200R019C10SPC800.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2grp-34h8-p48c

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2grm-wcfh-hhgj

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 7.5
1%
Низкий
12 месяцев назад
github логотип
GHSA-2grm-pxpf-4j6v

A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2grj-9rmj-333f

SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905.

CVSS3: 9.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2grj-6p8q-gfq4

There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2grh-pj67-4p6p

In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2grh-hm3w-w7hv

Race condition in tokio

CVSS3: 5.9
1%
Низкий
почти 5 лет назад
github логотип
GHSA-2grh-gr37-2283

Solr search discloses email addresses of users

CVSS3: 5.3
59%
Средний
больше 2 лет назад
github логотип
GHSA-2grg-mh77-gc8w

Multiple cross-site scripting (XSS) vulnerabilities in Social Book Facebook Clone 2010 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) signup.php, (2) lostpass.php, (3) login.php, (4) index.php, (5) help_tos.php, (6) help_contact.php, or (7) help.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2grg-m45x-hwh6

IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2grg-6j4w-c3v4

CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2grf-mxvh-rqrf

PhpSecInfo 0.2.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Test/Test_Suhosin.php and certain other files.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2grc-rqmm-2cj8

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2grc-9vqr-3q7x

Unspecified vulnerability in the Oracle Retail Central Office component in Oracle Industry Applications 13.1, 13.2, 13.3, and 13.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Customer Operations (Add, Search).

1%
Низкий
около 4 лет назад
github логотип
GHSA-2grc-69vf-g6vr

PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fileroot] parameter.

6%
Низкий
около 4 лет назад
github логотип
GHSA-2gr9-gwrg-jc3v

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-2gr9-3f9h-5pc3

Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу