Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xj72-wvfv-8985

больше 3 лет назад

vm2 Sandbox Escape vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj72-m52w-529q

больше 4 лет назад

Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj72-8cc7-64m7

6 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-xj72-54x6-jmcv

больше 3 лет назад

Microsoft SQL Server Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xj72-54ch-xhfx

около 4 лет назад

Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj6x-54xc-64j5

4 дня назад

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-xj6x-4fwp-9v78

около 4 лет назад

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of EXIF metadata. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-xj6v-rj9r-jrjq

около 2 лет назад

The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xj6v-gwfp-883r

около 4 лет назад

Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xj6v-gr3v-5fpq

11 месяцев назад

A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs of the component Event Action System. Such manipulation of the argument Data leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xj6v-38m3-64p9

8 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xj6v-33q6-wvxj

25 дней назад

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj6r-wv4q-mrm6

больше 4 лет назад

In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.

EPSS: Низкий
github логотип

GHSA-xj6r-wgr5-8rxc

больше 1 года назад

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-xj6r-gmjj-ghvc

больше 4 лет назад

Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via the filename parameter.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xj6r-2jpm-qvxp

почти 5 лет назад

Code injection issue for java-spring-cloud-stream-template

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-xj6q-9hx8-mm7f

почти 6 лет назад

Directory Traversal in liuyaserver

EPSS: Низкий
github логотип

GHSA-xj6q-8x83-jv6g

26 дней назад

Axios: Prototype pollution auth subfields can inject Basic auth

EPSS: Низкий
github логотип

GHSA-xj6q-3qm4-vg6w

около 4 лет назад

An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1470, CVE-2020-1516.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj6m-g8xh-h3xc

больше 4 лет назад

In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-198291476References: N/A

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xj72-wvfv-8985

vm2 Sandbox Escape vulnerability

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-xj72-m52w-529q

Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj72-8cc7-64m7

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

6 месяцев назад
github логотип
GHSA-xj72-54x6-jmcv

Microsoft SQL Server Remote Code Execution Vulnerability

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xj72-54ch-xhfx

Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xj6x-54xc-64j5

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

CVSS3: 5.7
0%
Низкий
4 дня назад
github логотип
GHSA-xj6x-4fwp-9v78

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of EXIF metadata. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
19%
Средний
около 4 лет назад
github логотип
GHSA-xj6v-rj9r-jrjq

The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xj6v-gwfp-883r

Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xj6v-gr3v-5fpq

A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs of the component Event Action System. Such manipulation of the argument Data leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xj6v-38m3-64p9

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xj6v-33q6-wvxj

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

CVSS3: 9.8
0%
Низкий
25 дней назад
github логотип
GHSA-xj6r-wv4q-mrm6

In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj6r-wgr5-8rxc

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

CVSS3: 4.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-xj6r-gmjj-ghvc

Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via the filename parameter.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xj6r-2jpm-qvxp

Code injection issue for java-spring-cloud-stream-template

CVSS3: 8.7
1%
Низкий
почти 5 лет назад
github логотип
GHSA-xj6q-9hx8-mm7f

Directory Traversal in liuyaserver

2%
Низкий
почти 6 лет назад
github логотип
GHSA-xj6q-8x83-jv6g

Axios: Prototype pollution auth subfields can inject Basic auth

0%
Низкий
26 дней назад
github логотип
GHSA-xj6q-3qm4-vg6w

An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1470, CVE-2020-1516.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xj6m-g8xh-h3xc

In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to local escalation of privilege with physical access to device internals with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-198291476References: N/A

CVSS3: 6.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу