Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-xx4g-62m6-v2w7

11 месяцев назад

In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xx4c-xhpg-hcw2

больше 2 лет назад

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx4c-ww79-386v

4 месяца назад

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx4c-jj58-r7x6

около 4 лет назад

Inefficient Regular Expression Complexity in Validator.js

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx49-hmrj-2wm5

больше 3 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx49-8f9w-5r74

почти 4 года назад

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

EPSS: Низкий
github логотип

GHSA-xx49-72mm-f757

почти 4 года назад

Windows NT 4.0 beta allows users to read and delete shares.

EPSS: Средний
github логотип

GHSA-xx48-fp29-wh9j

больше 3 лет назад

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx47-vfr9-x3x7

16 дней назад

OKI Print Job Accounting 4.4.10 contains an unquoted service path vulnerability in the OkiJaSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Print Job Accounting\' to inject malicious executables and escalate privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx47-qq34-9xqq

почти 4 года назад

Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

EPSS: Низкий
github логотип

GHSA-xx46-fhm6-qw2q

больше 3 лет назад

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2487.

EPSS: Низкий
github логотип

GHSA-xx46-cq25-6hgf

больше 3 лет назад

An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx45-rh3m-ccvq

больше 3 лет назад

Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.

EPSS: Низкий
github логотип

GHSA-xx45-f7pv-xj5x

почти 4 года назад

SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter.

EPSS: Низкий
github логотип

GHSA-xx44-m54v-4pwc

больше 3 лет назад

An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Depending on the vector chosen, an attacker can overwrite service executables and execute arbitrary code with privileges of user set to run the service or replace other files within the installation folder, which would allow for local privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx44-254w-m8vr

больше 3 лет назад

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx43-h94m-wj64

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx43-6j8m-vx2f

3 месяца назад

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx42-xvv9-8p8p

больше 3 лет назад

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xx3v-pjx9-qmj7

больше 3 лет назад

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx4g-62m6-v2w7

In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.

CVSS3: 4.6
0%
Низкий
11 месяцев назад
github логотип
GHSA-xx4c-xhpg-hcw2

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx4c-ww79-386v

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xx4c-jj58-r7x6

Inefficient Regular Expression Complexity in Validator.js

CVSS3: 5.3
около 4 лет назад
github логотип
GHSA-xx49-hmrj-2wm5

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx49-8f9w-5r74

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx49-72mm-f757

Windows NT 4.0 beta allows users to read and delete shares.

12%
Средний
почти 4 года назад
github логотип
GHSA-xx48-fp29-wh9j

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx47-vfr9-x3x7

OKI Print Job Accounting 4.4.10 contains an unquoted service path vulnerability in the OkiJaSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Print Job Accounting\' to inject malicious executables and escalate privileges.

CVSS3: 7.8
0%
Низкий
16 дней назад
github логотип
GHSA-xx47-qq34-9xqq

Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xx46-fhm6-qw2q

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2487.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx46-cq25-6hgf

An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx45-rh3m-ccvq

Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xx45-f7pv-xj5x

SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xx44-m54v-4pwc

An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Depending on the vector chosen, an attacker can overwrite service executables and execute arbitrary code with privileges of user set to run the service or replace other files within the installation folder, which would allow for local privilege escalation.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx44-254w-m8vr

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx43-h94m-wj64

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xx43-6j8m-vx2f

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xx42-xvv9-8p8p

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3v-pjx9-qmj7

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу