Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xp7j-9g27-rqpj

больше 4 лет назад

Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

EPSS: Низкий
github логотип

GHSA-xp7h-ghc6-47w2

почти 2 года назад

Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xp7h-368q-wc44

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

EPSS: Низкий
github логотип

GHSA-xp7g-78mw-jp2h

около 4 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, iCloud for Windows 7.14, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xp7f-xgjj-34wc

8 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xp7f-v245-w3w8

3 месяца назад

An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp79-9mxw-878j

6 месяцев назад

`finch-rst` was removed from crates.io for malicious code

EPSS: Низкий
github логотип

GHSA-xp79-5mx3-jx52

около 2 месяцев назад

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

EPSS: Низкий
github логотип

GHSA-xp78-rqf2-cf9c

около 4 лет назад

DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.

EPSS: Низкий
github логотип

GHSA-xp77-qrh7-8wvm

больше 3 лет назад

Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xp77-g88w-h7mg

больше 4 лет назад

Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xp77-7ppq-j5jg

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Callback Request allows Reflected XSS. This issue affects Callback Request: from n/a through 1.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xp76-357g-9wqq

больше 4 лет назад

SciPy creates insecure temporary directories

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp76-33m9-43ww

11 месяцев назад

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp75-w7vq-5x6j

больше 1 года назад

OpenDaylight SFC Insecure Shiro Cookie Configuration

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xp75-r577-cvhp

около 1 года назад

Privileged OpenBao Operator May Execute Code on the Underlying Host

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xp73-99p3-8q2g

около 4 лет назад

The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue.

EPSS: Низкий
github логотип

GHSA-xp6x-f75w-g3q7

больше 2 лет назад

An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp6x-8hgv-x5w5

больше 2 лет назад

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp6x-54qx-mg3m

6 месяцев назад

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp7j-9g27-rqpj

Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xp7h-ghc6-47w2

Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.

CVSS3: 6.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-xp7h-368q-wc44

Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xp7g-78mw-jp2h

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, iCloud for Windows 7.14, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xp7f-xgjj-34wc

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xp7f-v245-w3w8

An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components

CVSS3: 7.5
3%
Низкий
3 месяца назад
github логотип
GHSA-xp79-9mxw-878j

`finch-rst` was removed from crates.io for malicious code

6 месяцев назад
github логотип
GHSA-xp79-5mx3-jx52

Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xp78-rqf2-cf9c

DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xp77-qrh7-8wvm

Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xp77-g88w-h7mg

Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials.

CVSS3: 8.6
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xp77-7ppq-j5jg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Callback Request allows Reflected XSS. This issue affects Callback Request: from n/a through 1.4.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp76-357g-9wqq

SciPy creates insecure temporary directories

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xp76-33m9-43ww

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-xp75-w7vq-5x6j

OpenDaylight SFC Insecure Shiro Cookie Configuration

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp75-r577-cvhp

Privileged OpenBao Operator May Execute Code on the Underlying Host

CVSS3: 9.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xp73-99p3-8q2g

The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xp6x-f75w-g3q7

An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-xp6x-8hgv-x5w5

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

CVSS3: 7.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-xp6x-54qx-mg3m

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.

CVSS3: 4.3
0%
Низкий
6 месяцев назад

Уязвимостей на страницу