Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 571

Количество 323 571

github логотип

GHSA-xpxr-6mr7-m8w3

почти 4 года назад

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.

EPSS: Низкий
github логотип

GHSA-xpxq-j6pj-5vxg

почти 4 года назад

The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.

EPSS: Низкий
github логотип

GHSA-xpxq-cp94-87j2

больше 3 лет назад

A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xpxq-44xv-wmh3

8 месяцев назад

A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xpxq-36mx-cwhx

почти 4 года назад

An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attacker could gain access to the admin panel or a customer account when using the password reset function. To do so, it is required to own a domain name similar to the one the victim uses for their e-mail accounts.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xpxp-v33m-5jp9

почти 4 года назад

phpMyAdmin Unsafe Fetching of Javascript Code

EPSS: Низкий
github логотип

GHSA-xpxp-r8hf-wgf6

10 месяцев назад

WSO2 products vulnerable to Cross-site Scripting

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-xpxm-pf7g-2534

почти 5 лет назад

Cross-site scripting in media2click

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xpxm-j39p-5vcw

почти 4 года назад

Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.

EPSS: Низкий
github логотип

GHSA-xpxm-gwv9-2g2q

почти 4 года назад

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

EPSS: Низкий
github логотип

GHSA-xpxm-9vvw-pjc3

почти 4 года назад

There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpxj-fcm9-9v47

около 1 года назад

Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpxj-28xv-5xh7

почти 4 года назад

Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-xpxh-fh9m-hf5v

почти 4 года назад

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

EPSS: Низкий
github логотип

GHSA-xpxg-5vmj-vx9g

больше 2 лет назад

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpxf-p5mx-cq4f

почти 4 года назад

It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xpxf-4p9g-j69p

почти 4 года назад

The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xpxc-7j8q-3794

почти 4 года назад

Microsoft Windows 7 SP1 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft browsers handle objects in memory, aka "Windows Shell Remote Code Execution Vulnerability".

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xpx9-f724-2jfc

больше 1 года назад

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xpx9-9jmc-8j4w

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webvitaly Extra Shortcodes allows Stored XSS.This issue affects Extra Shortcodes: from n/a through 2.2.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpxr-6mr7-m8w3

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xpxq-j6pj-5vxg

The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xpxq-cp94-87j2

A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xpxq-44xv-wmh3

A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

CVSS3: 3.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-xpxq-36mx-cwhx

An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attacker could gain access to the admin panel or a customer account when using the password reset function. To do so, it is required to own a domain name similar to the one the victim uses for their e-mail accounts.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpxp-v33m-5jp9

phpMyAdmin Unsafe Fetching of Javascript Code

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpxp-r8hf-wgf6

WSO2 products vulnerable to Cross-site Scripting

CVSS3: 5.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-xpxm-pf7g-2534

Cross-site scripting in media2click

CVSS3: 6.4
0%
Низкий
почти 5 лет назад
github логотип
GHSA-xpxm-j39p-5vcw

Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpxm-gwv9-2g2q

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xpxm-9vvw-pjc3

There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpxj-fcm9-9v47

Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xpxj-28xv-5xh7

Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.

CVSS3: 6.1
21%
Средний
почти 4 года назад
github логотип
GHSA-xpxh-fh9m-hf5v

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpxg-5vmj-vx9g

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpxf-p5mx-cq4f

It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.

CVSS3: 3.7
2%
Низкий
почти 4 года назад
github логотип
GHSA-xpxf-4p9g-j69p

The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xpxc-7j8q-3794

Microsoft Windows 7 SP1 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft browsers handle objects in memory, aka "Windows Shell Remote Code Execution Vulnerability".

CVSS3: 7.5
26%
Средний
почти 4 года назад
github логотип
GHSA-xpx9-f724-2jfc

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpx9-9jmc-8j4w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webvitaly Extra Shortcodes allows Stored XSS.This issue affects Extra Shortcodes: from n/a through 2.2.

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу