Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-25wj-phmw-qw67

около 4 лет назад

Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-25wj-f645-7mjg

больше 4 лет назад

X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.

EPSS: Низкий
github логотип

GHSA-25wj-5m66-r5mg

около 4 лет назад

SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25wh-jjx3-jq6q

7 месяцев назад

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-25wh-8v9q-4p3q

больше 4 лет назад

Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.

EPSS: Низкий
github логотип

GHSA-25wg-q69h-xh22

около 4 лет назад

The Photos in Wifi application 1.0.1 for iOS has directory traversal via the ext parameter to assets-library://asset/asset.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25wg-pp2p-rfw9

около 4 лет назад

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1167.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25wf-hqcv-7qc9

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-25wf-7x6c-wmpf

9 месяцев назад

Moodle does not properly enforce MFA

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-25wc-vm27-vmmq

около 4 лет назад

A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleControl Server Basic's port 8000/tcp could escalate his privileges and perform administrative operations.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25w9-wqfq-gwqx

больше 1 года назад

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25w9-qw26-8c4r

около 4 лет назад

Stack-based buffer overflow in the image tooltip implementation in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a long image filename, related to "AIM IMG Tag Parsing."

EPSS: Низкий
github логотип

GHSA-25w9-jxhc-6r43

почти 2 года назад

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-25w9-jc8c-rx9w

больше 3 лет назад

Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased its reference count (leading to Use-After-Free and Local Privilege Escalation). Fixed files are permanently registered to the ring, and should not be put separately. We recommend upgrading past commit https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679 https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25w8-v4rh-3fg2

около 4 лет назад

The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers to obtain credentials via the browser cache.

EPSS: Низкий
github логотип

GHSA-25w6-x449-427j

11 месяцев назад

Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) component, in Open5GS thru 2.7.5 allowing attackers to cause a denial of service or other unspecified impacts via repeated UE connect and disconnect message sequences.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25w6-w4pw-wf47

около 4 лет назад

The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.

EPSS: Низкий
github логотип

GHSA-25w6-fx24-w953

около 4 лет назад

Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-25w5-f3x8-83vw

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget allows Stored XSS. This issue affects Ultimate twitter profile widget: from n/a through 1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-25w5-c8hw-pg9c

около 4 лет назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25wj-phmw-qw67

Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

1%
Низкий
около 4 лет назад
github логотип
GHSA-25wj-f645-7mjg

X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-25wj-5m66-r5mg

SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.

CVSS3: 6.1
8%
Низкий
около 4 лет назад
github логотип
GHSA-25wh-jjx3-jq6q

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
7 месяцев назад
github логотип
GHSA-25wh-8v9q-4p3q

Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-25wg-q69h-xh22

The Photos in Wifi application 1.0.1 for iOS has directory traversal via the ext parameter to assets-library://asset/asset.php.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-25wg-pp2p-rfw9

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1167.

CVSS3: 7.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-25wf-hqcv-7qc9

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-25wf-7x6c-wmpf

Moodle does not properly enforce MFA

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-25wc-vm27-vmmq

A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleControl Server Basic's port 8000/tcp could escalate his privileges and perform administrative operations.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-25w9-wqfq-gwqx

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-25w9-qw26-8c4r

Stack-based buffer overflow in the image tooltip implementation in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a long image filename, related to "AIM IMG Tag Parsing."

8%
Низкий
около 4 лет назад
github логотип
GHSA-25w9-jxhc-6r43

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS3: 8.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-25w9-jc8c-rx9w

Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased its reference count (leading to Use-After-Free and Local Privilege Escalation). Fixed files are permanently registered to the ring, and should not be put separately. We recommend upgrading past commit https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679 https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25w8-v4rh-3fg2

The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers to obtain credentials via the browser cache.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25w6-x449-427j

Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) component, in Open5GS thru 2.7.5 allowing attackers to cause a denial of service or other unspecified impacts via repeated UE connect and disconnect message sequences.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-25w6-w4pw-wf47

The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.

3%
Низкий
около 4 лет назад
github логотип
GHSA-25w6-fx24-w953

Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.

CVSS3: 6.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-25w5-f3x8-83vw

Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget allows Stored XSS. This issue affects Ultimate twitter profile widget: from n/a through 1.0.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-25w5-c8hw-pg9c

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

1%
Низкий
около 4 лет назад

Уязвимостей на страницу