Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-xvgg-cwcr-cr95

9 месяцев назад

Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvgg-9h29-4g34

11 месяцев назад

Liferay Portal has Improper Validation of Specified Quantity in Input

EPSS: Низкий
github логотип

GHSA-xvgf-q2mq-jv66

около 4 лет назад

In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.

EPSS: Низкий
github логотип

GHSA-xvgf-4x2w-f753

около 4 лет назад

A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a partial denial of service (DoS) to Cisco Meetings application users who are paired with a Session Initiation Protocol (SIP) endpoint. The vulnerability is due to improper validation of coSpaces configuration parameters. An attacker could exploit this vulnerability by inserting crafted strings in specific coSpace parameters. An exploit could allow the attacker to prevent clients from joining a conference call in the affected coSpace. Versions prior to 2.4.3 are affected.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvgc-v9fj-5m69

больше 4 лет назад

vim is vulnerable to Out-of-bounds Read

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvgc-j98h-3v9x

почти 2 года назад

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xvgc-c4mc-v8qh

около 4 лет назад

Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to page unload.

EPSS: Средний
github логотип

GHSA-xvgc-9v79-whg9

почти 4 года назад

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvg9-fp4q-jq9w

3 месяца назад

CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xvg8-m4x3-w6xr

больше 1 года назад

matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal

EPSS: Низкий
github логотип

GHSA-xvg8-8xmq-7xcx

около 4 лет назад

The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain sensitive information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-xvg7-vc3x-xhhw

около 4 лет назад

The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS: Низкий
github логотип

GHSA-xvg7-rj7x-j6gm

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Yonatan Reinberg of Social Ink Sinking Dropdowns allows Privilege Escalation.This issue affects Sinking Dropdowns: from n/a through 1.25.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvg7-pm76-82w3

около 4 лет назад

admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.

EPSS: Средний
github логотип

GHSA-xvg6-w59c-3823

около 2 лет назад

Missing Authorization vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.4.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xvg5-c6vg-6mfp

около 4 лет назад

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.

EPSS: Низкий
github логотип

GHSA-xvg5-76pr-547q

2 месяца назад

A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin Gateway. This manipulation causes improper privilege management. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project tagged the reported issue as bug.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xvg4-9wrh-3mc2

около 4 лет назад

Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.

EPSS: Низкий
github логотип

GHSA-xvg3-v23f-88p6

10 месяцев назад

A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For more information, please refer to section 'Security Update for Armoury Crate App' in the ASUS Security Advisory.

EPSS: Низкий
github логотип

GHSA-xvg3-q6r5-8fhf

больше 3 лет назад

Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.

CVSS3: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvgg-cwcr-cr95

Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xvgg-9h29-4g34

Liferay Portal has Improper Validation of Specified Quantity in Input

0%
Низкий
11 месяцев назад
github логотип
GHSA-xvgf-q2mq-jv66

In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xvgf-4x2w-f753

A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a partial denial of service (DoS) to Cisco Meetings application users who are paired with a Session Initiation Protocol (SIP) endpoint. The vulnerability is due to improper validation of coSpaces configuration parameters. An attacker could exploit this vulnerability by inserting crafted strings in specific coSpace parameters. An exploit could allow the attacker to prevent clients from joining a conference call in the affected coSpace. Versions prior to 2.4.3 are affected.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvgc-v9fj-5m69

vim is vulnerable to Out-of-bounds Read

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvgc-j98h-3v9x

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.

CVSS3: 6.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvgc-c4mc-v8qh

Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to page unload.

13%
Средний
около 4 лет назад
github логотип
GHSA-xvgc-9v79-whg9

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xvg9-fp4q-jq9w

CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.

CVSS3: 9.1
1%
Низкий
3 месяца назад
github логотип
GHSA-xvg8-m4x3-w6xr

matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal

1%
Низкий
больше 1 года назад
github логотип
GHSA-xvg8-8xmq-7xcx

The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain sensitive information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."

CVSS3: 5.5
40%
Средний
около 4 лет назад
github логотип
GHSA-xvg7-vc3x-xhhw

The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xvg7-rj7x-j6gm

Cross-Site Request Forgery (CSRF) vulnerability in Yonatan Reinberg of Social Ink Sinking Dropdowns allows Privilege Escalation.This issue affects Sinking Dropdowns: from n/a through 1.25.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvg7-pm76-82w3

admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.

53%
Средний
около 4 лет назад
github логотип
GHSA-xvg6-w59c-3823

Missing Authorization vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.4.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvg5-c6vg-6mfp

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.

5%
Низкий
около 4 лет назад
github логотип
GHSA-xvg5-76pr-547q

A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin Gateway. This manipulation causes improper privilege management. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project tagged the reported issue as bug.

CVSS3: 6.3
0%
Низкий
2 месяца назад
github логотип
GHSA-xvg4-9wrh-3mc2

Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xvg3-v23f-88p6

A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For more information, please refer to section 'Security Update for Armoury Crate App' in the ASUS Security Advisory.

0%
Низкий
10 месяцев назад
github логотип
GHSA-xvg3-q6r5-8fhf

Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.

CVSS3: 10
17%
Средний
больше 3 лет назад

Уязвимостей на страницу