Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-xx88-rwrm-3468

больше 3 лет назад

Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx88-38jg-963j

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_default_path_quality We need to protect the reader reading sysctl_netrom_default_path_quality because the value can be changed concurrently.

EPSS: Низкий
github логотип

GHSA-xx87-pm67-fw3r

5 месяцев назад

Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Accessibility Checker by Equalize Digital: from n/a through 1.31.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx87-pj66-pfx7

3 дня назад

Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request to '/api/v1/user-avatar', which are then stored on the server and executed in the context of any user accessing the compromised resource.

EPSS: Низкий
github логотип

GHSA-xx87-hj55-x8cc

почти 4 года назад

Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.

EPSS: Низкий
github логотип

GHSA-xx86-qq8v-6h29

около 2 лет назад

Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx83-gq5v-8prv

больше 3 лет назад

An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1308.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx83-cxmq-x89m

около 1 года назад

Boundary Community Edition Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xx83-ccv6-7333

больше 3 лет назад

The web interface on Virtual Access GW6110A routers with software 9.00 before 9.09.27, 9.50 before 9.50.21, and 10.00 before 10.00.21 allows remote authenticated users to gain privileges via a modified JavaScript variable.

EPSS: Низкий
github логотип

GHSA-xx83-6gm8-xx8p

больше 1 года назад

In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx82-r4r9-35vq

больше 3 лет назад

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.56, 8.57 and 8.58. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-xx82-c2x3-7q3w

почти 4 года назад

Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.

EPSS: Низкий
github логотип

GHSA-xx7x-j7hm-xqvx

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a crafted zip file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx7x-j67h-66rj

больше 3 лет назад

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xx7w-qc27-vx8w

больше 3 лет назад

A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx7w-8884-5pcq

больше 3 лет назад

Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files.

EPSS: Низкий
github логотип

GHSA-xx7v-hqxh-cjr9

2 месяца назад

Apache Struts is Vulnerable to DoS via File Leak

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx7q-j5jr-xqjf

больше 3 лет назад

In avdt_scb_hdl_report of avdt_scb_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-111450156.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx7m-rfgv-w2gg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

EPSS: Средний
github логотип

GHSA-xx7m-8rq2-cw2v

больше 3 лет назад

TYPO3 CMS indexed search Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx88-rwrm-3468

Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx88-38jg-963j

In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_default_path_quality We need to protect the reader reading sysctl_netrom_default_path_quality because the value can be changed concurrently.

больше 1 года назад
github логотип
GHSA-xx87-pm67-fw3r

Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Accessibility Checker by Equalize Digital: from n/a through 1.31.0.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-xx87-pj66-pfx7

Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request to '/api/v1/user-avatar', which are then stored on the server and executed in the context of any user accessing the compromised resource.

0%
Низкий
3 дня назад
github логотип
GHSA-xx87-hj55-x8cc

Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xx86-qq8v-6h29

Adobe Photoshop versions 24.7.1 (and earlier) and 25.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xx83-gq5v-8prv

An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1308.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx83-cxmq-x89m

Boundary Community Edition Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-xx83-ccv6-7333

The web interface on Virtual Access GW6110A routers with software 9.00 before 9.09.27, 9.50 before 9.50.21, and 10.00 before 10.00.21 allows remote authenticated users to gain privileges via a modified JavaScript variable.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx83-6gm8-xx8p

In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx82-r4r9-35vq

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.56, 8.57 and 8.58. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx82-c2x3-7q3w

Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.

6%
Низкий
почти 4 года назад
github логотип
GHSA-xx7x-j7hm-xqvx

Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a crafted zip file.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx7x-j67h-66rj

The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx7w-qc27-vx8w

A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx7w-8884-5pcq

Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx7v-hqxh-cjr9

Apache Struts is Vulnerable to DoS via File Leak

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xx7q-j5jr-xqjf

In avdt_scb_hdl_report of avdt_scb_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-111450156.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx7m-rfgv-w2gg

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

52%
Средний
почти 4 года назад
github логотип
GHSA-xx7m-8rq2-cw2v

TYPO3 CMS indexed search Cross-site Scripting vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу