Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 632

Количество 325 632

github логотип

GHSA-xq4m-cj98-7hg9

почти 4 года назад

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4280.

EPSS: Низкий
github логотип

GHSA-xq4j-x39q-xhqm

около 2 месяцев назад

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xq4j-rv6r-ch63

больше 1 года назад

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xq4j-j5qp-3mfq

около 3 лет назад

Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq4h-wqm2-668w

5 месяцев назад

Babylon's BIP322 signature implementation is not fully compliant to the spec

EPSS: Низкий
github логотип

GHSA-xq4h-hmq6-ghrv

почти 4 года назад

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.

EPSS: Низкий
github логотип

GHSA-xq4h-8qpv-793q

больше 1 года назад

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq4h-4mpj-q5jr

больше 1 года назад

Transient DOS while processing TID-to-link mapping IE elements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq4g-vf85-h54p

почти 4 года назад

EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xq4g-5hpc-wfcx

почти 2 года назад

An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq4f-rq5v-998c

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.

EPSS: Низкий
github логотип

GHSA-xq4f-j8wj-pf7x

больше 3 лет назад

An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq4f-f2vc-9hxr

почти 4 года назад

The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq4f-cq2m-g7xp

больше 1 года назад

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xq4f-9xp4-279p

больше 1 года назад

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xq4f-3jxp-qv6m

7 месяцев назад

csvjson vulnerable to prototype injection

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq4c-v44m-4gw8

почти 4 года назад

Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2015-4180.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xq4c-q7v4-538j

почти 4 года назад

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq4c-4fcc-74mp

около 4 лет назад

There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

EPSS: Низкий
github логотип

GHSA-xq49-p575-q243

почти 4 года назад

Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq4m-cj98-7hg9

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4280.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq4j-x39q-xhqm

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xq4j-rv6r-ch63

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq4j-j5qp-3mfq

Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xq4h-wqm2-668w

Babylon's BIP322 signature implementation is not fully compliant to the spec

5 месяцев назад
github логотип
GHSA-xq4h-hmq6-ghrv

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xq4h-8qpv-793q

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq4h-4mpj-q5jr

Transient DOS while processing TID-to-link mapping IE elements.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq4g-vf85-h54p

EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq4g-5hpc-wfcx

An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xq4f-rq5v-998c

Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq4f-j8wj-pf7x

An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xq4f-f2vc-9hxr

The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq4f-cq2m-g7xp

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq4f-9xp4-279p

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq4f-3jxp-qv6m

csvjson vulnerable to prototype injection

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xq4c-v44m-4gw8

Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2015-4180.

CVSS3: 7.5
16%
Средний
почти 4 года назад
github логотип
GHSA-xq4c-q7v4-538j

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq4c-4fcc-74mp

There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xq49-p575-q243

Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу