Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-22r7-4wq2-qrrj

около 4 лет назад

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-22r7-2v6v-5qmw

около 4 лет назад

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

EPSS: Низкий
github логотип

GHSA-22r5-h494-2vm4

около 4 лет назад

Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of service (flow daemon crash) via an unspecified sequence of TCP packets.

EPSS: Низкий
github логотип

GHSA-22r5-83g8-x228

около 4 лет назад

Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.

EPSS: Средний
github логотип

GHSA-22r4-f9q2-4m9g

около 4 лет назад

In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22r3-hxrp-33gc

около 3 лет назад

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22r3-9w55-cj54

больше 2 лет назад

Pkg Local Privilege Escalation

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-22r2-m2r8-4chj

11 месяцев назад

A weakness has been identified in Campcodes Online Loan Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_borrower. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-22r2-gj47-5f7c

около 2 месяцев назад

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-22r2-8jr8-3hmr

около 4 лет назад

Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22r2-3hp3-ff6j

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Poll Maker allows DOM-Based XSS. This issue affects Poll Maker: from n/a through 6.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22qx-x99p-8745

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-22qx-rv28-v9m8

почти 2 года назад

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22qx-hc7j-pqmg

около 4 лет назад

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data as well as unauthorized access to critical data or complete access to all Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and r...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-22qw-g2hg-q8w6

около 4 лет назад

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.

EPSS: Низкий
github логотип

GHSA-22qw-643c-4mjg

почти 4 года назад

In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-217185011

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-22qw-3g47-hgw6

около 4 лет назад

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22qv-x7vv-h86h

около 4 лет назад

A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-22qr-vprq-hjw2

около 4 лет назад

Improper input validation in WLAN encrypt/decrypt module can lead to a buffer copy in Snapdragon Mobile in version SD 835, SD 845, SD 850

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22qr-rp27-j9wm

2 месяца назад

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22r7-4wq2-qrrj

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106.

CVSS3: 5.4
2%
Низкий
около 4 лет назад
github логотип
GHSA-22r7-2v6v-5qmw

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22r5-h494-2vm4

Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of service (flow daemon crash) via an unspecified sequence of TCP packets.

2%
Низкий
около 4 лет назад
github логотип
GHSA-22r5-83g8-x228

Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.

33%
Средний
около 4 лет назад
github логотип
GHSA-22r4-f9q2-4m9g

In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-22r3-hxrp-33gc

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-22r3-9w55-cj54

Pkg Local Privilege Escalation

CVSS3: 6.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22r2-m2r8-4chj

A weakness has been identified in Campcodes Online Loan Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_borrower. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-22r2-gj47-5f7c

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-22r2-8jr8-3hmr

Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-22r2-3hp3-ff6j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Poll Maker allows DOM-Based XSS. This issue affects Poll Maker: from n/a through 6.0.1.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-22qx-x99p-8745

Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.

2%
Низкий
около 4 лет назад
github логотип
GHSA-22qx-rv28-v9m8

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-22qx-hc7j-pqmg

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE accessible data as well as unauthorized access to critical data or complete access to all Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and r...

CVSS3: 6.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-22qw-g2hg-q8w6

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22qw-643c-4mjg

In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-217185011

CVSS3: 3.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-22qw-3g47-hgw6

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-22qv-x7vv-h86h

A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.

CVSS3: 5.9
3%
Низкий
около 4 лет назад
github логотип
GHSA-22qr-vprq-hjw2

Improper input validation in WLAN encrypt/decrypt module can lead to a buffer copy in Snapdragon Mobile in version SD 835, SD 845, SD 850

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-22qr-rp27-j9wm

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE

CVSS3: 8.8
0%
Низкий
2 месяца назад

Уязвимостей на страницу