Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 867

Количество 364 867

github логотип

GHSA-24gf-6m5f-h6pg

больше 2 лет назад

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-24gf-6fhm-ccvq

больше 4 лет назад

Buffer Over-read when WLAN module gets a WMI message for SAR limits with invalid number of limits to be enforced in Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8098, IPQ8074, MSM8998, QCA8081, QCN7605, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM8150, SXR1130

EPSS: Низкий
github логотип

GHSA-24gf-3vg7-m9fh

около 1 года назад

The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24gc-vqxp-wmhf

больше 4 лет назад

Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.

EPSS: Низкий
github логотип

GHSA-24gc-rw47-8xrm

7 месяцев назад

An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused by an authenticated local attacker to gather credential information which is processed by the PVI client application. The logging function of the PVI client application is disabled by default and must be explicitly enabled by the user.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-24gc-8wwv-g9pv

больше 4 лет назад

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24g8-xhgr-ch6g

около 2 лет назад

Untrusted Search Path, Incorrect Default Permissions vulnerability in Cato Networks SDP Client on Windows allows Privilege Escalation.This issue affects SDP Client: before 5.10.34.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24g8-x36j-cf39

около 21 часа назад

Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

EPSS: Низкий
github логотип

GHSA-24g8-35x9-fv8r

больше 4 лет назад

Stored XSS vulnerability in Jenkins FindBugs Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24g7-95rm-cqcc

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24g6-h5ch-r4vh

больше 4 лет назад

There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly unspecified other impact via a crafted js file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24g6-h25q-mhq8

больше 4 лет назад

Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24g6-5rx7-58wj

больше 4 лет назад

Missing Initialization of Resource in pnet

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24g5-w2rq-8ppc

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-24g5-r7q6-hhmg

больше 2 лет назад

An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Specific valid link-local traffic is not blocked on ports in STP blocked state but is instead sent to the control plane of the device. This leads to excessive resource consumption and in turn severe impact on all control and management protocols of the device. This issue affects Juniper Networks Junos OS: * 21.2 version 21.2R3-S3 and later versions earlier than 21.2R3-S6; * 22.1 version 22.1R3 and later versions earlier than 22.1R3-S4; * 22.2 version 22.2R2 and later versions earlier than 22.2R3-S2; * 22.3 version 22.3R2 and later versions earlier than 22.3R3-S1; * 22.4 versions earlier than 22.4R2-S2, 22.4R3; * 23.2 versions earlier than 23.2R1-S1, 23.2R2. This issue does not affect Juniper Networks Junos OS 21.4R1 and later vers...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24g5-659f-65j9

больше 4 лет назад

Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request.

EPSS: Средний
github логотип

GHSA-24g4-h784-g3mx

около 1 года назад

Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-24g4-fh3x-4f5h

больше 4 лет назад

An issue in provider/libserver/ECKrbAuth.cpp of Kopano-Core v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24g4-c97f-v22x

больше 4 лет назад

In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-80432928

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24g4-9847-8c6x

около 1 месяца назад

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply malicious serviceUrl values through configured input paths to retrieve sensitive authentication data outside the trusted boundary.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24gf-6m5f-h6pg

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.

CVSS3: 8.8
87%
Высокий
больше 2 лет назад
github логотип
GHSA-24gf-6fhm-ccvq

Buffer Over-read when WLAN module gets a WMI message for SAR limits with invalid number of limits to be enforced in Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8098, IPQ8074, MSM8998, QCA8081, QCN7605, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM8150, SXR1130

0%
Низкий
больше 4 лет назад
github логотип
GHSA-24gf-3vg7-m9fh

The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authentication.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-24gc-vqxp-wmhf

Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-24gc-rw47-8xrm

An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused by an authenticated local attacker to gather credential information which is processed by the PVI client application. The logging function of the PVI client application is disabled by default and must be explicitly enabled by the user.

CVSS3: 5
0%
Низкий
7 месяцев назад
github логотип
GHSA-24gc-8wwv-g9pv

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-24g8-xhgr-ch6g

Untrusted Search Path, Incorrect Default Permissions vulnerability in Cato Networks SDP Client on Windows allows Privilege Escalation.This issue affects SDP Client: before 5.10.34.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-24g8-x36j-cf39

Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

около 21 часа назад
github логотип
GHSA-24g8-35x9-fv8r

Stored XSS vulnerability in Jenkins FindBugs Plugin

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-24g7-95rm-cqcc

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-24g6-h5ch-r4vh

There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly unspecified other impact via a crafted js file.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-24g6-h25q-mhq8

Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-24g6-5rx7-58wj

Missing Initialization of Resource in pnet

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-24g5-w2rq-8ppc

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-24g5-r7q6-hhmg

An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX 300 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). Specific valid link-local traffic is not blocked on ports in STP blocked state but is instead sent to the control plane of the device. This leads to excessive resource consumption and in turn severe impact on all control and management protocols of the device. This issue affects Juniper Networks Junos OS: * 21.2 version 21.2R3-S3 and later versions earlier than 21.2R3-S6; * 22.1 version 22.1R3 and later versions earlier than 22.1R3-S4; * 22.2 version 22.2R2 and later versions earlier than 22.2R3-S2; * 22.3 version 22.3R2 and later versions earlier than 22.3R3-S1; * 22.4 versions earlier than 22.4R2-S2, 22.4R3; * 23.2 versions earlier than 23.2R1-S1, 23.2R2. This issue does not affect Juniper Networks Junos OS 21.4R1 and later vers...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24g5-659f-65j9

Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request.

24%
Средний
больше 4 лет назад
github логотип
GHSA-24g4-h784-g3mx

Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-24g4-fh3x-4f5h

An issue in provider/libserver/ECKrbAuth.cpp of Kopano-Core v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-24g4-c97f-v22x

In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-80432928

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-24g4-9847-8c6x

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply malicious serviceUrl values through configured input paths to retrieve sensitive authentication data outside the trusted boundary.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу