Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2ghq-fx5m-357p

больше 1 года назад

Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2ghq-f5hx-5jwp

около 4 лет назад

resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2ghq-8m9c-mqjm

около 4 лет назад

STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0.

EPSS: Низкий
github логотип

GHSA-2ghp-ghc5-jw25

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2ghp-fh92-8w9r

8 месяцев назад

Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2ghm-r75j-pjx2

больше 2 лет назад

Cross-site Scripting in DOMSanitizer

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2ghm-cqrg-hhpv

около 4 лет назад

IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624.

EPSS: Низкий
github логотип

GHSA-2ghj-g7p4-5ff7

около 4 лет назад

Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering.

EPSS: Низкий
github логотип

GHSA-2ghj-fm9g-w3jm

5 месяцев назад

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.

EPSS: Низкий
github логотип

GHSA-2ghj-7h29-wmc5

около 4 лет назад

The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2ghh-xmvf-53hw

больше 1 года назад

Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2ghh-4f9c-3725

больше 4 лет назад

Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.

EPSS: Низкий
github логотип

GHSA-2ghg-fvx3-9q3q

почти 3 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2ghg-c3m2-fxfm

больше 1 года назад

The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2ghg-9rgq-99xh

около 4 лет назад

In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-2ghc-9393-f9wv

7 месяцев назад

NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2ghc-6v89-pw9j

почти 5 лет назад

body-parser-xml vulnerable to Prototype Pollution

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2gh9-j675-j2ff

почти 4 года назад

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2gh9-f6jf-23hq

около 2 лет назад

Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-2gh8-q6wj-fwpq

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2ghq-fx5m-357p

Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2ghq-f5hx-5jwp

resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.

CVSS3: 7.2
3%
Низкий
около 4 лет назад
github логотип
GHSA-2ghq-8m9c-mqjm

STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2ghp-ghc5-jw25

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-2ghp-fh92-8w9r

Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2ghm-r75j-pjx2

Cross-site Scripting in DOMSanitizer

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2ghm-cqrg-hhpv

IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2ghj-g7p4-5ff7

Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2ghj-fm9g-w3jm

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.

0%
Низкий
5 месяцев назад
github логотип
GHSA-2ghj-7h29-wmc5

The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2ghh-xmvf-53hw

Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2ghh-4f9c-3725

Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2ghg-fvx3-9q3q

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-2ghg-c3m2-fxfm

The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2ghg-9rgq-99xh

In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940.

CVSS3: 4.2
0%
Низкий
около 4 лет назад
github логотип
GHSA-2ghc-9393-f9wv

NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering.

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-2ghc-6v89-pw9j

body-parser-xml vulnerable to Prototype Pollution

CVSS3: 7.6
1%
Низкий
почти 5 лет назад
github логотип
GHSA-2gh9-j675-j2ff

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gh9-f6jf-23hq

Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception.

CVSS3: 5.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-2gh8-q6wj-fwpq

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу