Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-xw64-mvx9-6946

11 месяцев назад

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xw63-wh8f-q2fm

12 месяцев назад

A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted is an unknown function of the file /Profilers/PriProfile/COUNT3s7.php. The manipulation of the argument cbe leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xw63-m43m-c93h

больше 4 лет назад

MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xw62-w8g4-hmhx

больше 4 лет назад

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xw62-rx45-hvr3

11 месяцев назад

The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials.

EPSS: Низкий
github логотип

GHSA-xw62-fv8f-gc9h

больше 4 лет назад

Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial of service (application crash) via a crafted speed (aka rate) value.

EPSS: Низкий
github логотип

GHSA-xw5x-xgqj-5wfc

5 месяцев назад

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. A low-privileged local attacker could have exploited this vulnerability by manipulating the search path used by the application to locate critical resources, potentially causing unauthorized code execution. Exploitation of this issue required user interaction in that a user had to be running the installer.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xw5w-xhjv-gf29

5 месяцев назад

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-xw5w-5r82-mf3j

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xw5v-rpqc-44jg

около 3 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection.This issue affects Scienta: before 20230630.1953.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xw5r-6r86-qg74

больше 4 лет назад

LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port" sequence; or (2) a malformed Range header, which triggers misparsing in parse_play_time_range in RTSP_Play, as demonstrated by an empty Range header.

EPSS: Низкий
github логотип

GHSA-xw5r-2555-jwfv

больше 4 лет назад

Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Низкий
github логотип

GHSA-xw5q-w7ff-jgm4

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: media: solo6x10: Check for out of bounds chip_id Clang with CONFIG_UBSAN_SHIFT=y noticed a condition where a signed type (literal "1" is an "int") could end up being shifted beyond 32 bits, so instrumentation was added (and due to the double is_tw286x() call seen via inlining), Clang decides the second one must now be undefined behavior and elides the rest of the function[1]. This is a known problem with Clang (that is still being worked on), but we can avoid the entire problem by actually checking the existing max chip ID, and now there is no runtime instrumentation added at all since everything is known to be within bounds. Additionally use an unsigned value for the shift to remove the instrumentation even without the explicit bounds checking. [hverkuil: fix checkpatch warning for is_tw286x]

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xw5q-g62x-2qjc

около 1 года назад

electron ASAR Integrity bypass by just modifying the content

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xw5q-f9x8-g7pf

17 дней назад

Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw5q-6mjm-826q

больше 4 лет назад

SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-xw5p-hw8j-xg4q

больше 3 лет назад

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw5p-hw6r-2j98

около 6 лет назад

Denial of service in fastify

EPSS: Низкий
github логотип

GHSA-xw5m-v83c-xc7p

почти 2 года назад

A vulnerability classified as critical was found in code-projects Hospital Management System 1.0. This vulnerability affects unknown code of the file change-password.php. The manipulation of the argument cpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xw5m-hf8v-47cw

больше 2 лет назад

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw64-mvx9-6946

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 2.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-xw63-wh8f-q2fm

A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted is an unknown function of the file /Profilers/PriProfile/COUNT3s7.php. The manipulation of the argument cbe leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-xw63-m43m-c93h

MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.

CVSS3: 9.8
10%
Низкий
больше 4 лет назад
github логотип
GHSA-xw62-w8g4-hmhx

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw62-rx45-hvr3

The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials.

1%
Низкий
11 месяцев назад
github логотип
GHSA-xw62-fv8f-gc9h

Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial of service (application crash) via a crafted speed (aka rate) value.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5x-xgqj-5wfc

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. A low-privileged local attacker could have exploited this vulnerability by manipulating the search path used by the application to locate critical resources, potentially causing unauthorized code execution. Exploitation of this issue required user interaction in that a user had to be running the installer.

CVSS3: 8.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-xw5w-xhjv-gf29

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

CVSS3: 2.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-xw5w-5r82-mf3j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-xw5v-rpqc-44jg

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection.This issue affects Scienta: before 20230630.1953.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xw5r-6r86-qg74

LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port" sequence; or (2) a malformed Range header, which triggers misparsing in parse_play_time_range in RTSP_Play, as demonstrated by an empty Range header.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5r-2555-jwfv

Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5q-w7ff-jgm4

In the Linux kernel, the following vulnerability has been resolved: media: solo6x10: Check for out of bounds chip_id Clang with CONFIG_UBSAN_SHIFT=y noticed a condition where a signed type (literal "1" is an "int") could end up being shifted beyond 32 bits, so instrumentation was added (and due to the double is_tw286x() call seen via inlining), Clang decides the second one must now be undefined behavior and elides the rest of the function[1]. This is a known problem with Clang (that is still being worked on), but we can avoid the entire problem by actually checking the existing max chip ID, and now there is no runtime instrumentation added at all since everything is known to be within bounds. Additionally use an unsigned value for the shift to remove the instrumentation even without the explicit bounds checking. [hverkuil: fix checkpatch warning for is_tw286x]

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xw5q-g62x-2qjc

electron ASAR Integrity bypass by just modifying the content

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xw5q-f9x8-g7pf

Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.

CVSS3: 6.5
0%
Низкий
17 дней назад
github логотип
GHSA-xw5q-6mjm-826q

SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5p-hw8j-xg4q

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
9%
Низкий
больше 3 лет назад
github логотип
GHSA-xw5p-hw6r-2j98

Denial of service in fastify

1%
Низкий
около 6 лет назад
github логотип
GHSA-xw5m-v83c-xc7p

A vulnerability classified as critical was found in code-projects Hospital Management System 1.0. This vulnerability affects unknown code of the file change-password.php. The manipulation of the argument cpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-xw5m-hf8v-47cw

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу