Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 896

Количество 288 896

github логотип

GHSA-xx83-6gm8-xx8p

12 месяцев назад

In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx82-r4r9-35vq

около 3 лет назад

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.56, 8.57 and 8.58. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-xx82-c2x3-7q3w

больше 3 лет назад

Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.

EPSS: Низкий
github логотип

GHSA-xx7x-j7hm-xqvx

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a crafted zip file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx7x-j67h-66rj

около 3 лет назад

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xx7w-qc27-vx8w

около 3 лет назад

A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx7w-8884-5pcq

около 3 лет назад

Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files.

EPSS: Низкий
github логотип

GHSA-xx7q-j5jr-xqjf

около 3 лет назад

In avdt_scb_hdl_report of avdt_scb_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-111450156.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx7m-rfgv-w2gg

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

EPSS: Средний
github логотип

GHSA-xx7m-8rq2-cw2v

около 3 лет назад

TYPO3 CMS indexed search Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx7j-rqjq-33gm

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_reset_request.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_reset_request.mhtml modules) allows Reflected XSS.This issue affects Cloud Security Gateway (CSG): before 03/29/2023; Web Security: before 03/29/2023.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx7h-hp2m-8474

больше 3 лет назад

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139589.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx7g-f287-f9fq

около 3 лет назад

XXE vulnerability in Jenkins Liquibase Runner Plugin

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xx7f-w375-6m8q

около 3 лет назад

Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xx7c-j7h3-vjcq

5 месяцев назад

TorchServe script references S3 bucket without ensuring ownership or confirming accessibility

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xx7c-hx38-xm2p

больше 1 года назад

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx7c-3hw3-xfp5

больше 3 лет назад

Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs for the device via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xx79-89wm-j32v

около 3 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, and SDX20, possible memory corruption due to invalid integer overflow checks in exif parsing.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx79-5295-gw9g

около 3 лет назад

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default debug124 password for the debug account.

EPSS: Низкий
github логотип

GHSA-xx79-4755-jq22

больше 1 года назад

SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx83-6gm8-xx8p

In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-xx82-r4r9-35vq

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.56, 8.57 and 8.58. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

1%
Низкий
около 3 лет назад
github логотип
GHSA-xx82-c2x3-7q3w

Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-xx7x-j7hm-xqvx

Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a crafted zip file.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx7x-j67h-66rj

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx7w-qc27-vx8w

A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xx7w-8884-5pcq

Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xx7q-j5jr-xqjf

In avdt_scb_hdl_report of avdt_scb_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-111450156.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx7m-rfgv-w2gg

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

31%
Средний
больше 3 лет назад
github логотип
GHSA-xx7m-8rq2-cw2v

TYPO3 CMS indexed search Cross-site Scripting vulnerability

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx7j-rqjq-33gm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_reset_request.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_reset_request.mhtml modules) allows Reflected XSS.This issue affects Cloud Security Gateway (CSG): before 03/29/2023; Web Security: before 03/29/2023.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx7h-hp2m-8474

IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139589.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx7g-f287-f9fq

XXE vulnerability in Jenkins Liquibase Runner Plugin

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx7f-w375-6m8q

Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xx7c-j7h3-vjcq

TorchServe script references S3 bucket without ensuring ownership or confirming accessibility

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xx7c-hx38-xm2p

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx7c-3hw3-xfp5

Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs for the device via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx79-89wm-j32v

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, and SDX20, possible memory corruption due to invalid integer overflow checks in exif parsing.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx79-5295-gw9g

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default debug124 password for the debug account.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xx79-4755-jq22

SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file

CVSS3: 6.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу