Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 282 212

Количество 282 212

github логотип

GHSA-xxxw-3j6h-q7h6

9 месяцев назад

Grafana plugin SDK Information Leakage

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxxv-ffhq-jc78

больше 1 года назад

** DISPUTED ** Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxxv-8qg4-6qv9

около 3 лет назад

Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-xxxv-6j6h-6fqv

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account. NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface.

EPSS: Низкий
github логотип

GHSA-xxxq-m57r-j966

около 3 лет назад

P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an application transports to kernel. An attacker tricks the user to install a malicious application, successful exploit could cause malicious code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxxq-chmp-67g4

почти 5 лет назад

RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxxp-8x92-f69v

почти 2 года назад

An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxxm-q6xf-58pf

около 3 лет назад

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-xxxm-cq2q-5v69

почти 2 года назад

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxxj-4ccj-cfw9

около 3 лет назад

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

EPSS: Низкий
github логотип

GHSA-xxxh-xcx8-7g7r

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Twitter Search (twittersearch) extension before 0.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xxxh-8gvj-6w39

около 3 лет назад

Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a PDF document with a crafted TrueType font.

EPSS: Средний
github логотип

GHSA-xxxf-qw8j-6rfv

больше 3 лет назад

Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxxf-8fjp-59qv

около 3 лет назад

An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.

EPSS: Средний
github логотип

GHSA-xxxc-2fjg-mprw

около 1 месяца назад

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxx9-8q88-3qrf

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: from n/a through 3.1.40.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxx9-446j-m3xj

около 3 лет назад

Unspecified vulnerability in Kismet before 2005-08-R1 allows remote attackers to have an unknown impact via unprintable characters in the SSID.

EPSS: Низкий
github логотип

GHSA-xxx9-3xcr-gjj3

около 3 лет назад

XML Injection in Xerces Java affects Nokogiri

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxx8-w7mj-hmgq

около 3 лет назад

hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxx6-f4cg-v662

больше 2 лет назад

Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxxw-3j6h-q7h6

Grafana plugin SDK Information Leakage

CVSS3: 5.9
0%
Низкий
9 месяцев назад
github логотип
GHSA-xxxv-ffhq-jc78

** DISPUTED ** Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxxv-8qg4-6qv9

Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxxv-6j6h-6fqv

Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account. NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface.

2%
Низкий
около 3 лет назад
github логотип
GHSA-xxxq-m57r-j966

P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an application transports to kernel. An attacker tricks the user to install a malicious application, successful exploit could cause malicious code execution.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxxq-chmp-67g4

RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign

CVSS3: 9.8
1%
Низкий
почти 5 лет назад
github логотип
GHSA-xxxp-8x92-f69v

An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxxm-q6xf-58pf

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

CVSS3: 8.8
70%
Высокий
около 3 лет назад
github логотип
GHSA-xxxm-cq2q-5v69

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxxj-4ccj-cfw9

The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxxh-xcx8-7g7r

Cross-site scripting (XSS) vulnerability in the Twitter Search (twittersearch) extension before 0.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxxh-8gvj-6w39

Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a PDF document with a crafted TrueType font.

10%
Средний
около 3 лет назад
github логотип
GHSA-xxxf-qw8j-6rfv

Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxxf-8fjp-59qv

An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.

13%
Средний
около 3 лет назад
github логотип
GHSA-xxxc-2fjg-mprw

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xxx9-8q88-3qrf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: from n/a through 3.1.40.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxx9-446j-m3xj

Unspecified vulnerability in Kismet before 2005-08-R1 allows remote attackers to have an unknown impact via unprintable characters in the SSID.

4%
Низкий
около 3 лет назад
github логотип
GHSA-xxx9-3xcr-gjj3

XML Injection in Xerces Java affects Nokogiri

CVSS3: 6.5
около 3 лет назад
github логотип
GHSA-xxx8-w7mj-hmgq

hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxx6-f4cg-v662

Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу