Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 109

Количество 326 109

github логотип

GHSA-xp9f-x7wr-8cp4

около 3 лет назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp9f-vm29-4q5v

почти 4 года назад

A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier). They contain an undocumented default account (smc) with a hard-coded password that may be used with certain web servlets. A remote attacker with the knowledge of the hard-coded password and the message format may use vulnerable servlets to gain unauthorized access to the system. Note: This account cannot be used to log in via the web user interface.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xp9f-jwgv-v2wj

почти 2 года назад

In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp9f-jj97-j8gx

18 дней назад

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to access sensitive user data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp9f-5q2c-rrp4

почти 4 года назад

MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."

EPSS: Низкий
github логотип

GHSA-xp9c-w8w2-2477

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.4 SP1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xp9c-c3h6-pg4m

больше 2 лет назад

An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp9c-82x8-7f67

около 5 лет назад

Prototype Pollution in Node-Red

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-xp9c-82jq-4pp7

почти 4 года назад

Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.

EPSS: Низкий
github логотип

GHSA-xp9c-49cm-62q9

7 месяцев назад

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access contact info related to notifications in Notification Center.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xp99-74mm-rpv2

8 месяцев назад

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp97-f35x-xjmv

больше 4 лет назад

Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-42309.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xp97-6w7r-4cjc

почти 4 года назад

OpenStack Keystone token expiration issues

EPSS: Низкий
github логотип

GHSA-xp95-8cxx-xfmw

больше 1 года назад

Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xp93-v7v5-cx68

почти 4 года назад

PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=, g=Team&m=Department&a=index&keyword=, and g=Team&m=Bulletin&a=index&keyword=.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp93-22jw-4857

почти 4 года назад

The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.

EPSS: Низкий
github логотип

GHSA-xp92-74fm-xffq

почти 4 года назад

Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp92-3q3c-qcqj

почти 2 года назад

Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xp8w-jxfc-xrqq

почти 2 года назад

An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp8w-7pr3-w557

около 4 лет назад

The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp9f-x7wr-8cp4

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xp9f-vm29-4q5v

A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier). They contain an undocumented default account (smc) with a hard-coded password that may be used with certain web servlets. A remote attacker with the knowledge of the hard-coded password and the message format may use vulnerable servlets to gain unauthorized access to the system. Note: This account cannot be used to log in via the web user interface.

CVSS3: 9.8
6%
Низкий
почти 4 года назад
github логотип
GHSA-xp9f-jwgv-v2wj

In ss_AnalyzeOssReturnResUssdArgIe of ss_OssAsnManagement.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xp9f-jj97-j8gx

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to access sensitive user data.

CVSS3: 7.5
0%
Низкий
18 дней назад
github логотип
GHSA-xp9f-5q2c-rrp4

MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."

3%
Низкий
почти 4 года назад
github логотип
GHSA-xp9c-w8w2-2477

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.4 SP1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp9c-c3h6-pg4m

An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xp9c-82x8-7f67

Prototype Pollution in Node-Red

CVSS3: 7.7
0%
Низкий
около 5 лет назад
github логотип
GHSA-xp9c-82jq-4pp7

Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xp9c-49cm-62q9

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access contact info related to notifications in Notification Center.

CVSS3: 3.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xp99-74mm-rpv2

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.

CVSS3: 8.8
1%
Низкий
8 месяцев назад
github логотип
GHSA-xp97-f35x-xjmv

Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-42309.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xp97-6w7r-4cjc

OpenStack Keystone token expiration issues

1%
Низкий
почти 4 года назад
github логотип
GHSA-xp95-8cxx-xfmw

Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp93-v7v5-cx68

PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=, g=Team&m=Department&a=index&keyword=, and g=Team&m=Bulletin&a=index&keyword=.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp93-22jw-4857

The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xp92-74fm-xffq

Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp92-3q3c-qcqj

Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xp8w-jxfc-xrqq

An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xp8w-7pr3-w557

The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.

CVSS3: 7.8
0%
Низкий
около 4 лет назад

Уязвимостей на страницу