Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 322 267

Количество 322 267

github логотип

GHSA-xxvv-rw24-p2j6

11 месяцев назад

In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xxvq-wr93-6r58

больше 2 лет назад

Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-xxvq-27rc-4q93

9 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xxvp-3855-w9fv

почти 4 года назад

Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.

EPSS: Низкий
github логотип

GHSA-xxvm-h45q-hvv9

почти 4 года назад

CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.

EPSS: Низкий
github логотип

GHSA-xxvm-h2mx-9mwj

больше 2 лет назад

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxvm-gxxx-r9pg

9 месяцев назад

A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the function amf_state_operational of the file src/amf/amf-sm.c of the component AMF Service. The manipulation leads to reachable assertion. It is possible to launch the attack on the local host. The identifier of the patch is 53e9e059ed96b940f7ddcd9a2b68cb512524d5db. It is recommended to apply a patch to fix this issue.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xxvj-8g5m-4qgw

почти 4 года назад

SaltStack Salt Directory traversal vulnerability in minion id validation

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxvh-jcpq-95qv

около 2 лет назад

File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xxvh-8h9p-mpwj

больше 1 года назад

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxvh-7q9r-8cf8

3 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-xxvh-5hwj-42pp

около 1 месяца назад

OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation

EPSS: Низкий
github логотип

GHSA-xxvg-9x33-93vm

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxvf-6jpw-pp5x

больше 1 года назад

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.2-beta-1 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xxvc-c328-56m6

около 1 года назад

A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.

EPSS: Низкий
github логотип

GHSA-xxvc-6xwm-7prp

10 месяцев назад

A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate their privileges via a vulnerable COM interface in the target service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxvc-26j5-3mg9

почти 4 года назад

Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.

EPSS: Низкий
github логотип

GHSA-xxv9-w5hm-328j

около 2 лет назад

Jenkins AppSpider Plugin missing permission checks

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxv9-fp7w-qg3h

почти 4 года назад

Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected.

EPSS: Низкий
github логотип

GHSA-xxv9-73gc-96fm

около 1 месяца назад

LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can send a crafted payload to achieve arbitrary code execution.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxvv-rw24-p2j6

In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible

CVSS3: 8.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxvq-wr93-6r58

Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxvq-27rc-4q93

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-xxvp-3855-w9fv

Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xxvm-h45q-hvv9

CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxvm-h2mx-9mwj

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxvm-gxxx-r9pg

A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the function amf_state_operational of the file src/amf/amf-sm.c of the component AMF Service. The manipulation leads to reachable assertion. It is possible to launch the attack on the local host. The identifier of the patch is 53e9e059ed96b940f7ddcd9a2b68cb512524d5db. It is recommended to apply a patch to fix this issue.

CVSS3: 3.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xxvj-8g5m-4qgw

SaltStack Salt Directory traversal vulnerability in minion id validation

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxvh-jcpq-95qv

File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.

CVSS3: 9.8
17%
Средний
около 2 лет назад
github логотип
GHSA-xxvh-8h9p-mpwj

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxvh-7q9r-8cf8

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

3 месяца назад
github логотип
GHSA-xxvh-5hwj-42pp

OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation

0%
Низкий
около 1 месяца назад
github логотип
GHSA-xxvg-9x33-93vm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxvf-6jpw-pp5x

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.2-beta-1 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxvc-c328-56m6

A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.

0%
Низкий
около 1 года назад
github логотип
GHSA-xxvc-6xwm-7prp

A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate their privileges via a vulnerable COM interface in the target service.

CVSS3: 7.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-xxvc-26j5-3mg9

Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxv9-w5hm-328j

Jenkins AppSpider Plugin missing permission checks

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxv9-fp7w-qg3h

Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev 1.1.2), which could allow remote attackers to stay connected.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxv9-73gc-96fm

LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can send a crafted payload to achieve arbitrary code execution.

2%
Низкий
около 1 месяца назад

Уязвимостей на страницу