Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-xvhq-qrmp-cx9w

27 дней назад

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvhq-9p7m-5c3c

почти 4 года назад

Buffer underflow in redlight.sys in BufferZone 2.1 and 2.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by sending a small buffer size value to the FsSetVolumeInformation IOCTL handler code with a FsSetDirectoryInformation subcode containing a large buffer.

EPSS: Низкий
github логотип

GHSA-xvhq-4mp3-f354

почти 4 года назад

SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.

EPSS: Низкий
github логотип

GHSA-xvhp-xj53-p6h7

больше 1 года назад

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is resolved in version 1.2.7.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xvhp-cm9x-2m2h

больше 3 лет назад

A vulnerability in the web-based management interface for Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvhp-2844-v475

около 2 лет назад

An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xvhm-h729-47f2

больше 3 лет назад

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality and integrity via vectors related to File Folders / URL Attachment.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xvhj-83gv-vjmg

почти 4 года назад

Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.

EPSS: Низкий
github логотип

GHSA-xvhg-w6qc-m3qq

больше 2 лет назад

Yaklang Plugin's Fuzztag Component Allows Unauthorized Local File Reading

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvhg-pwg9-qp4r

больше 3 лет назад

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvhf-q744-5xm8

больше 3 лет назад

XXE vulnerability in NUnit Plugin

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xvhc-jj62-7h84

6 месяцев назад

The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

EPSS: Низкий
github логотип

GHSA-xvh9-mfm3-cvfq

больше 3 лет назад

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

EPSS: Низкий
github логотип

GHSA-xvh9-jpfj-m9hg

почти 4 года назад

Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

EPSS: Низкий
github логотип

GHSA-xvh8-gxxm-2h9g

почти 4 года назад

SQL injection vulnerability in Webmatic before 2.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvh8-g3fx-684w

почти 4 года назад

D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

EPSS: Низкий
github логотип

GHSA-xvh8-f5vg-49g2

5 месяцев назад

A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvh8-9h96-57r8

28 дней назад

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to access the application by impersonating any user, including those with administrative permissions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xvh8-95gq-687q

больше 3 лет назад

Huawei DP300, V500R002C00, RP200, V600R006C00, TE30, V100R001C10, V500R002C00,V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00,V600R006C00, TE60, V100R001C10, V500R002C00, V600R006C00, TX50,V500R002C00, V600R006C00 have a buffer overflow vulnerability. An attacker may send specially crafted HTTP messages to the affected products. Due insufficient input validation of three different parameters in the messages, successful exploit may cause some service abnormal.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xvh7-j354-hww5

больше 3 лет назад

An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvhq-qrmp-cx9w

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

CVSS3: 9.8
0%
Низкий
27 дней назад
github логотип
GHSA-xvhq-9p7m-5c3c

Buffer underflow in redlight.sys in BufferZone 2.1 and 2.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by sending a small buffer size value to the FsSetVolumeInformation IOCTL handler code with a FsSetDirectoryInformation subcode containing a large buffer.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvhq-4mp3-f354

SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvhp-xj53-p6h7

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is resolved in version 1.2.7.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvhp-cm9x-2m2h

A vulnerability in the web-based management interface for Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvhp-2844-v475

An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvhm-h729-47f2

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality and integrity via vectors related to File Folders / URL Attachment.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvhj-83gv-vjmg

Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.

8%
Низкий
почти 4 года назад
github логотип
GHSA-xvhg-w6qc-m3qq

Yaklang Plugin's Fuzztag Component Allows Unauthorized Local File Reading

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvhg-pwg9-qp4r

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvhf-q744-5xm8

XXE vulnerability in NUnit Plugin

CVSS3: 7.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvhc-jj62-7h84

The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

0%
Низкий
6 месяцев назад
github логотип
GHSA-xvh9-mfm3-cvfq

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvh9-jpfj-m9hg

Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvh8-gxxm-2h9g

SQL injection vulnerability in Webmatic before 2.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvh8-g3fx-684w

D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvh8-f5vg-49g2

A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
4%
Низкий
5 месяцев назад
github логотип
GHSA-xvh8-9h96-57r8

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to access the application by impersonating any user, including those with administrative permissions.

CVSS3: 8.1
0%
Низкий
28 дней назад
github логотип
GHSA-xvh8-95gq-687q

Huawei DP300, V500R002C00, RP200, V600R006C00, TE30, V100R001C10, V500R002C00,V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00,V600R006C00, TE60, V100R001C10, V500R002C00, V600R006C00, TX50,V500R002C00, V600R006C00 have a buffer overflow vulnerability. An attacker may send specially crafted HTTP messages to the affected products. Due insufficient input validation of three different parameters in the messages, successful exploit may cause some service abnormal.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvh7-j354-hww5

An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу