Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-xp9c-c3h6-pg4m

больше 2 лет назад

An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp9c-82x8-7f67

больше 5 лет назад

Prototype Pollution in Node-Red

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-xp9c-82jq-4pp7

больше 4 лет назад

Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.

EPSS: Низкий
github логотип

GHSA-xp9c-49cm-62q9

11 месяцев назад

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access contact info related to notifications in Notification Center.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xp99-74mm-rpv2

12 месяцев назад

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp97-f35x-xjmv

больше 4 лет назад

Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-42309.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xp97-6w7r-4cjc

около 4 лет назад

OpenStack Keystone token expiration issues

EPSS: Низкий
github логотип

GHSA-xp95-8cxx-xfmw

больше 1 года назад

Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xp93-v7v5-cx68

около 4 лет назад

PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=, g=Team&m=Department&a=index&keyword=, and g=Team&m=Bulletin&a=index&keyword=.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp93-22jw-4857

около 4 лет назад

The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.

EPSS: Низкий
github логотип

GHSA-xp92-74fm-xffq

около 4 лет назад

Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp92-3q3c-qcqj

около 2 лет назад

Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xp8w-jxfc-xrqq

около 2 лет назад

An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp8w-7pr3-w557

больше 4 лет назад

The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp8w-5r26-q5qh

больше 1 года назад

Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. As a result, by accessing a specific port an attacker can send call request to all registered services in router and achieve command injection vulnerability.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xp8v-w5q3-jgf9

около 4 лет назад

In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp8v-ff5g-65c6

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - prevent integer overflows The "code_length" value comes from the firmware file. If your firmware is untrusted realistically there is probably very little you can do to protect yourself. Still we try to limit the damage as much as possible. Also Smatch marks any data read from the filesystem as untrusted and prints warnings if it not capped correctly. The "code_length * 2" can overflow. The round_up(ucode_size, 16) + sizeof() expression can overflow too. Prevent these overflows.

EPSS: Низкий
github логотип

GHSA-xp8r-pgxf-vrhm

больше 1 года назад

A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component File Upload. The manipulation of the argument filename leads to cross site scripting. The attack can be launched remotely. Upgrading to version 9.12 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xp8p-9rq5-4wgv

около 4 лет назад

ZendXml and Zend Framework contain XXE and XEE Vulnerabilities

EPSS: Низкий
github логотип

GHSA-xp8m-vj7j-cr35

около 4 лет назад

An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp9c-c3h6-pg4m

An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xp9c-82x8-7f67

Prototype Pollution in Node-Red

CVSS3: 7.7
1%
Низкий
больше 5 лет назад
github логотип
GHSA-xp9c-82jq-4pp7

Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xp9c-49cm-62q9

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access contact info related to notifications in Notification Center.

CVSS3: 3.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xp99-74mm-rpv2

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell commands via the Git Repository field during project creation. By submitting a crafted repository string containing command injection syntax, an attacker can execute arbitrary commands on the underlying host system, resulting in full server compromise.

CVSS3: 8.8
3%
Низкий
12 месяцев назад
github логотип
GHSA-xp97-f35x-xjmv

Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-42309.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xp97-6w7r-4cjc

OpenStack Keystone token expiration issues

2%
Низкий
около 4 лет назад
github логотип
GHSA-xp95-8cxx-xfmw

Path traversal for some Intel(R) Extension for Transformers software before version 1.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-xp93-v7v5-cx68

PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=, g=Team&m=Department&a=index&keyword=, and g=Team&m=Bulletin&a=index&keyword=.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xp93-22jw-4857

The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xp92-74fm-xffq

Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xp92-3q3c-qcqj

Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xp8w-jxfc-xrqq

An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allows a local attacker to escalate privileges via the DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages components.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xp8w-7pr3-w557

The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xp8w-5r26-q5qh

Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. As a result, by accessing a specific port an attacker can send call request to all registered services in router and achieve command injection vulnerability.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp8v-w5q3-jgf9

In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.

CVSS3: 5.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xp8v-ff5g-65c6

In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - prevent integer overflows The "code_length" value comes from the firmware file. If your firmware is untrusted realistically there is probably very little you can do to protect yourself. Still we try to limit the damage as much as possible. Also Smatch marks any data read from the filesystem as untrusted and prints warnings if it not capped correctly. The "code_length * 2" can overflow. The round_up(ucode_size, 16) + sizeof() expression can overflow too. Prevent these overflows.

0%
Низкий
8 месяцев назад
github логотип
GHSA-xp8r-pgxf-vrhm

A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component File Upload. The manipulation of the argument filename leads to cross site scripting. The attack can be launched remotely. Upgrading to version 9.12 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp8p-9rq5-4wgv

ZendXml and Zend Framework contain XXE and XEE Vulnerabilities

10%
Низкий
около 4 лет назад
github логотип
GHSA-xp8m-vj7j-cr35

An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу