Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xm2v-8rrw-w9pm

около 5 лет назад

Division by 0 in `Conv2DBackpropInput`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-xm2v-2mf7-36mm

11 месяцев назад

An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xm2r-rc6j-6pp4

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix VAS mm use after free The refcount on mm is dropped before the coprocessor is detached.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xm2r-9p7m-8c7h

больше 4 лет назад

An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xm2r-2g3f-xg38

около 4 лет назад

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm2q-h8v9-r8j8

около 1 месяца назад

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xm2p-w62m-c2hg

больше 4 лет назад

SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter.

EPSS: Низкий
github логотип

GHSA-xm2p-hxq8-xj3q

больше 2 лет назад

A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-xm2p-chx4-g658

около 4 лет назад

Package Managers Configurations Remote Code Execution Vulnerability

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xm2m-chg4-j873

больше 4 лет назад

ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory.

EPSS: Низкий
github логотип

GHSA-xm2m-2q6h-22jw

около 3 лет назад

Apache NiFi vulnerable to Code Injection

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xm2h-xmp5-3q8p

около 4 лет назад

The Radiohead fan (aka nl.jborsje.android.bandnews.radiohead) application 4.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xm2g-rgpw-75v4

больше 4 лет назад

SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.

EPSS: Низкий
github логотип

GHSA-xm2g-jw84-7vcv

около 4 лет назад

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Средний
github логотип

GHSA-xm2f-q4jm-fwpf

почти 3 года назад

In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xm2f-jc7r-hmhj

16 дней назад

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xm2f-hpv7-49w8

около 4 лет назад

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xm2c-q8p4-pp7f

почти 4 года назад

FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xm2c-mv2p-hffr

около 1 месяца назад

Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xm28-fw2x-fqv2

около 7 лет назад

Denial of Service in foreman

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xm2v-8rrw-w9pm

Division by 0 in `Conv2DBackpropInput`

CVSS3: 2.5
0%
Низкий
около 5 лет назад
github логотип
GHSA-xm2v-2mf7-36mm

An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-xm2r-rc6j-6pp4

In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix VAS mm use after free The refcount on mm is dropped before the coprocessor is detached.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xm2r-9p7m-8c7h

An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm2r-2g3f-xg38

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xm2q-h8v9-r8j8

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.

CVSS3: 3.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xm2p-w62m-c2hg

SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xm2p-hxq8-xj3q

A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter.

CVSS3: 6.5
41%
Средний
больше 2 лет назад
github логотип
GHSA-xm2p-chx4-g658

Package Managers Configurations Remote Code Execution Vulnerability

CVSS3: 8.4
2%
Низкий
около 4 лет назад
github логотип
GHSA-xm2m-chg4-j873

ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm2m-2q6h-22jw

Apache NiFi vulnerable to Code Injection

CVSS3: 8.8
64%
Средний
около 3 лет назад
github логотип
GHSA-xm2h-xmp5-3q8p

The Radiohead fan (aka nl.jborsje.android.bandnews.radiohead) application 4.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xm2g-rgpw-75v4

SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm2g-jw84-7vcv

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

60%
Средний
около 4 лет назад
github логотип
GHSA-xm2f-q4jm-fwpf

In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xm2f-jc7r-hmhj

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.

CVSS3: 8.1
1%
Низкий
16 дней назад
github логотип
GHSA-xm2f-hpv7-49w8

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xm2c-q8p4-pp7f

FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xm2c-mv2p-hffr

Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xm28-fw2x-fqv2

Denial of Service in foreman

CVSS3: 7.5
около 7 лет назад

Уязвимостей на страницу