Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-xqmg-px28-29cq

около 1 года назад

Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqmg-8q55-7xxx

больше 4 лет назад

The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.

EPSS: Низкий
github логотип

GHSA-xqmf-wf6x-2cx6

больше 3 лет назад

Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqmc-wh95-fg2q

около 4 лет назад

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xqmc-vc6c-2wmv

около 4 лет назад

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.

EPSS: Низкий
github логотип

GHSA-xqmc-v3x5-h7p2

почти 4 года назад

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqmc-g86x-qfxp

больше 2 лет назад

Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xqmc-7954-658r

25 дней назад

ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xqm9-hpfh-qm5m

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence.

EPSS: Низкий
github логотип

GHSA-xqm9-g4jx-xvgw

больше 4 лет назад

Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.

EPSS: Низкий
github логотип

GHSA-xqm9-6qmm-xrqh

4 месяца назад

Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions module

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xqm9-4fqc-qh7w

около 4 лет назад

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS: Низкий
github логотип

GHSA-xqm9-2mv3-cvx4

почти 3 года назад

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqm8-jv67-vcvj

больше 2 лет назад

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqm8-c3rv-5vpf

больше 1 года назад

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-xqm7-qxfg-5xwm

8 месяцев назад

A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution under the Nomad Branch service context.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqm7-6qm9-wrqm

около 3 лет назад

The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqm7-6fmh-f42h

около 4 лет назад

Unspecified vulnerability in Oracle MySQL 5.5.50 and earlier, 5.6.31 and earlier, and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors related to DML.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqm6-6gwm-hwpw

больше 4 лет назад

The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqm5-rpmp-48hp

около 4 лет назад

Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqmg-px28-29cq

Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

CVSS3: 7.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xqmg-8q55-7xxx

The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqmf-wf6x-2cx6

Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xqmc-wh95-fg2q

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqmc-vc6c-2wmv

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xqmc-v3x5-h7p2

SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.

CVSS3: 7.5
7%
Низкий
почти 4 года назад
github логотип
GHSA-xqmc-g86x-qfxp

Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.

CVSS3: 6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqmc-7954-658r

ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service.

CVSS3: 3.3
0%
Низкий
25 дней назад
github логотип
GHSA-xqm9-hpfh-qm5m

Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqm9-g4jx-xvgw

Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqm9-6qmm-xrqh

Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions module

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-xqm9-4fqc-qh7w

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xqm9-2mv3-cvx4

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xqm8-jv67-vcvj

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xqm8-c3rv-5vpf

FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqm7-qxfg-5xwm

A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution under the Nomad Branch service context.

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xqm7-6qm9-wrqm

The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-xqm7-6fmh-f42h

Unspecified vulnerability in Oracle MySQL 5.5.50 and earlier, 5.6.31 and earlier, and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors related to DML.

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xqm6-6gwm-hwpw

The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xqm5-rpmp-48hp

Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.

CVSS3: 5.4
1%
Низкий
около 4 лет назад

Уязвимостей на страницу