Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 632

Количество 325 632

github логотип

GHSA-xq3x-grrj-fj6x

около 3 лет назад

sjqzhang go-fastdfs vulnerable to path traversal

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xq3x-fm54-p4gq

почти 4 года назад

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq3x-7w9j-26jf

почти 4 года назад

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

CVSS3: 9.6
EPSS: Высокий
github логотип

GHSA-xq3w-v528-46rv

больше 1 года назад

Denial of Service attack on windows app using netty

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq3w-mm28-x95x

почти 4 года назад

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq3w-4qf4-4638

почти 4 года назад

Unspecified vulnerability in the Oracle Warehouse Builder component in Oracle Database Server 10.2.0.5 (OWB) and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Dimensional Data Modeling.

EPSS: Низкий
github логотип

GHSA-xq3v-rpgq-hxm8

почти 4 года назад

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."

EPSS: Низкий
github логотип

GHSA-xq3v-7jhc-8vq7

почти 4 года назад

IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and gain unauthorized access to the document database. IBM X-Force ID: 156583.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq3p-jw3h-qr29

почти 4 года назад

Microsoft Windows 8 and Windows Server 2012, when Hyper-V is used, does not ensure memory-address validity, which allows guest OS users to execute arbitrary code in all guest OS instances, and allows guest OS users to cause a denial of service (host OS crash), via a guest-to-host hypercall with a crafted function parameter, aka "Address Corruption Vulnerability."

EPSS: Низкий
github логотип

GHSA-xq3p-5xwv-rm48

около 1 года назад

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xq3m-wq8x-cx6h

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks allows DOM-Based XSS. This issue affects B Blocks: from n/a through 2.0.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq3m-gw9r-v5xp

почти 3 года назад

A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file contactus.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226971.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xq3m-82wp-9899

почти 4 года назад

Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cgi tcpdump feature. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.

EPSS: Низкий
github логотип

GHSA-xq3m-6r9g-r79r

почти 4 года назад

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect availability via vectors related to WLS - Web Services.

EPSS: Низкий
github логотип

GHSA-xq3h-x3cq-7r9q

больше 2 лет назад

eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xq3h-j3m4-8fhm

почти 4 года назад

A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xq3g-xr36-vwhx

около 1 месяца назад

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq3g-m3j8-2vmm

20 дней назад

Duplicate Advisory: OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq3g-5rhc-pxgj

больше 3 лет назад

GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq3f-wxh6-25rp

почти 4 года назад

An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq3x-grrj-fj6x

sjqzhang go-fastdfs vulnerable to path traversal

CVSS3: 9.8
27%
Средний
около 3 лет назад
github логотип
GHSA-xq3x-fm54-p4gq

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 7.8
7%
Низкий
почти 4 года назад
github логотип
GHSA-xq3x-7w9j-26jf

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

CVSS3: 9.6
86%
Высокий
почти 4 года назад
github логотип
GHSA-xq3w-v528-46rv

Denial of Service attack on windows app using netty

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq3w-mm28-x95x

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-xq3w-4qf4-4638

Unspecified vulnerability in the Oracle Warehouse Builder component in Oracle Database Server 10.2.0.5 (OWB) and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Dimensional Data Modeling.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq3v-rpgq-hxm8

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq3v-7jhc-8vq7

IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and gain unauthorized access to the document database. IBM X-Force ID: 156583.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xq3p-jw3h-qr29

Microsoft Windows 8 and Windows Server 2012, when Hyper-V is used, does not ensure memory-address validity, which allows guest OS users to execute arbitrary code in all guest OS instances, and allows guest OS users to cause a denial of service (host OS crash), via a guest-to-host hypercall with a crafted function parameter, aka "Address Corruption Vulnerability."

0%
Низкий
почти 4 года назад
github логотип
GHSA-xq3p-5xwv-rm48

yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xq3m-wq8x-cx6h

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks allows DOM-Based XSS. This issue affects B Blocks: from n/a through 2.0.5.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xq3m-gw9r-v5xp

A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file contactus.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-226971.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xq3m-82wp-9899

Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cgi tcpdump feature. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.

5%
Низкий
почти 4 года назад
github логотип
GHSA-xq3m-6r9g-r79r

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect availability via vectors related to WLS - Web Services.

4%
Низкий
почти 4 года назад
github логотип
GHSA-xq3h-x3cq-7r9q

eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq3h-j3m4-8fhm

A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124.

CVSS3: 9.8
21%
Средний
почти 4 года назад
github логотип
GHSA-xq3g-xr36-vwhx

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xq3g-m3j8-2vmm

Duplicate Advisory: OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels

CVSS3: 7.5
20 дней назад
github логотип
GHSA-xq3g-5rhc-pxgj

GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xq3f-wxh6-25rp

An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу