Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 543

Количество 289 543

github логотип

GHSA-xx2h-vg66-mpr3

около 3 лет назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901, CVE-2019-0902.

EPSS: Средний
github логотип

GHSA-xx2h-qwcv-vv5w

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: arm64/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array was used outside of its scope.

EPSS: Низкий
github логотип

GHSA-xx2h-39g7-5x2c

больше 3 лет назад

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

EPSS: Средний
github логотип

GHSA-xx2h-2hf5-v7vv

около 3 лет назад

Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xx2g-w5xg-2w3f

почти 3 года назад

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-xx2f-m35m-cqwx

около 3 лет назад

In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9Android ID: A-172322502

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx29-p5f4-mwr8

около 3 лет назад

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

CVSS3: 7.8
EPSS: Критический
github логотип

GHSA-xx29-5p54-f7qq

около 3 лет назад

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112892194

EPSS: Низкий
github логотип

GHSA-xx28-hqvc-mm7j

9 месяцев назад

Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xx28-7x9q-6ch2

больше 3 лет назад

index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.

EPSS: Низкий
github логотип

GHSA-xx27-x5jh-mcrm

около 3 лет назад

In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150371903

EPSS: Низкий
github логотип

GHSA-xx27-vcf5-wm84

около 3 лет назад

Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, QM215, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDX20

EPSS: Низкий
github логотип

GHSA-xx25-w9gj-928r

больше 3 лет назад

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xx24-r484-7p82

8 месяцев назад

There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability ID: HWPSIRT-2020-05103) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9211.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xx24-pg44-2jhw

почти 3 года назад

This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to perform session fixation on the targeted device.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx24-9f8q-xh6x

около 3 лет назад

Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.

EPSS: Низкий
github логотип

GHSA-xx23-56cx-3ggr

около 3 лет назад

Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.

EPSS: Низкий
github логотип

GHSA-xwxx-v4g2-q5p4

4 месяца назад

The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xwxx-8397-833r

около 3 лет назад

Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-xwxw-ph5c-h3rg

больше 3 лет назад

Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1; EM Plugin for DB 12.1.0.5, 12.1.0.6, 12.1.0.7; and EM DB Control 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Management.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx2h-vg66-mpr3

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901, CVE-2019-0902.

28%
Средний
около 3 лет назад
github логотип
GHSA-xx2h-qwcv-vv5w

In the Linux kernel, the following vulnerability has been resolved: arm64/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array was used outside of its scope.

0%
Низкий
4 месяца назад
github логотип
GHSA-xx2h-39g7-5x2c

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

38%
Средний
больше 3 лет назад
github логотип
GHSA-xx2h-2hf5-v7vv

Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx2g-w5xg-2w3f

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

CVSS3: 6.1
49%
Средний
почти 3 года назад
github логотип
GHSA-xx2f-m35m-cqwx

In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9Android ID: A-172322502

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx29-p5f4-mwr8

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

CVSS3: 7.8
94%
Критический
около 3 лет назад
github логотип
GHSA-xx29-5p54-f7qq

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112892194

0%
Низкий
около 3 лет назад
github логотип
GHSA-xx28-hqvc-mm7j

Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.

CVSS3: 4.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xx28-7x9q-6ch2

index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx27-x5jh-mcrm

In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150371903

0%
Низкий
около 3 лет назад
github логотип
GHSA-xx27-vcf5-wm84

Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, QM215, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDX20

0%
Низкий
около 3 лет назад
github логотип
GHSA-xx25-w9gj-928r

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

CVSS3: 8.8
26%
Средний
больше 3 лет назад
github логотип
GHSA-xx24-r484-7p82

There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability ID: HWPSIRT-2020-05103) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9211.

CVSS3: 6.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xx24-pg44-2jhw

This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to perform session fixation on the targeted device.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xx24-9f8q-xh6x

Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.

1%
Низкий
около 3 лет назад
github логотип
GHSA-xx23-56cx-3ggr

Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xwxx-v4g2-q5p4

The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xwxx-8397-833r

Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xwxw-ph5c-h3rg

Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1; EM Plugin for DB 12.1.0.5, 12.1.0.6, 12.1.0.7; and EM DB Control 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Management.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу