Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-25x4-r7rm-rcw2

больше 1 года назад

A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-maid.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-25x4-hf95-v9w5

почти 3 года назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. HollerBox plugin <= 2.3.2 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-25x3-vv3q-35jw

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. There is an issue with the way the product handles URIs within certain schemes. The product does not warn the user that a dangerous navigation is about to take place. Because special characters in the URI are not sanitized, this could lead to the execution of arbitrary commands. An attacker can leverage this vulnerability to execute code in the context of the current user at medium integrity. Was ZDI-CAN-7162.

EPSS: Низкий
github логотип

GHSA-25x3-rfqm-vgrr

больше 4 лет назад

OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.

EPSS: Низкий
github логотип

GHSA-25x3-cmg3-5883

около 4 лет назад

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_edit_titre.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-25x2-hxpj-w7rj

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-25x2-3h45-fchh

около 4 лет назад

The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method.

EPSS: Низкий
github логотип

GHSA-25wx-66jf-2p4j

около 2 месяцев назад

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25wx-48p7-wfpx

около 1 года назад

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25wx-2r9g-p2hv

около 4 лет назад

In the Android kernel in i2c driver there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-25ww-mhx2-69ff

около 1 года назад

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25wv-pf2x-9jpv

больше 4 лет назад

Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.

EPSS: Низкий
github логотип

GHSA-25wv-8phj-8p7r

4 месяца назад

OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-25wv-52pf-rghh

21 день назад

Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitive API key metadata including user_id, mode, org scoping, and expiration details when supplied a valid key value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25wr-cfxr-69vm

около 4 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.

CVSS3: 5.3
EPSS: Высокий
github логотип

GHSA-25wr-8m9x-v3pr

около 4 лет назад

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3376, CVE-2016-7185, and CVE-2016-7211.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25wq-m5r4-rrm3

около 1 года назад

Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25wp-vwm5-27pw

5 месяцев назад

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized modification of critical system files.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-25wm-p4q5-cvgw

около 4 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25wj-x94f-xxw3

около 4 лет назад

The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (application crash) via an embedded JPEG-LS image with dimensions larger than the selected region in a (1) two-dimensional or (2) three-dimensional DICOM image file, which triggers an out-of-bounds read.

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25x4-r7rm-rcw2

A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-maid.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-25x4-hf95-v9w5

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Groundhogg Inc. HollerBox plugin <= 2.3.2 versions.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-25x3-vv3q-35jw

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. There is an issue with the way the product handles URIs within certain schemes. The product does not warn the user that a dangerous navigation is about to take place. Because special characters in the URI are not sanitized, this could lead to the execution of arbitrary commands. An attacker can leverage this vulnerability to execute code in the context of the current user at medium integrity. Was ZDI-CAN-7162.

10%
Низкий
около 4 лет назад
github логотип
GHSA-25x3-rfqm-vgrr

OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-25x3-cmg3-5883

doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_edit_titre.

CVSS3: 4.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-25x2-hxpj-w7rj

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-25x2-3h45-fchh

The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method.

4%
Низкий
около 4 лет назад
github логотип
GHSA-25wx-66jf-2p4j

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

CVSS3: 6.5
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-25wx-48p7-wfpx

A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-25wx-2r9g-p2hv

In the Android kernel in i2c driver there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-25ww-mhx2-69ff

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-25wv-pf2x-9jpv

Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-25wv-8phj-8p7r

OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths

CVSS3: 3.7
0%
Низкий
4 месяца назад
github логотип
GHSA-25wv-52pf-rghh

Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitive API key metadata including user_id, mode, org scoping, and expiration details when supplied a valid key value.

CVSS3: 7.5
0%
Низкий
21 день назад
github логотип
GHSA-25wr-cfxr-69vm

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.

CVSS3: 5.3
76%
Высокий
около 4 лет назад
github логотип
GHSA-25wr-8m9x-v3pr

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3376, CVE-2016-7185, and CVE-2016-7211.

CVSS3: 7.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-25wq-m5r4-rrm3

Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-25wp-vwm5-27pw

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized modification of critical system files.

CVSS3: 8.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-25wm-p4q5-cvgw

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-25wj-x94f-xxw3

The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (application crash) via an embedded JPEG-LS image with dimensions larger than the selected region in a (1) two-dimensional or (2) three-dimensional DICOM image file, which triggers an out-of-bounds read.

CVSS3: 8.2
4%
Низкий
около 4 лет назад

Уязвимостей на страницу