Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-xvhx-jwjw-g589

почти 2 года назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to modify protected parts of the file system.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvhw-jxmj-rx78

больше 4 лет назад

An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an attacker can easily connect to the TELNET daemon using the default credentials if they have not been changed by the user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvhw-73xq-6w53

почти 4 года назад

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvhv-xwq7-mggv

13 дней назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xvhv-fm6p-g8q4

больше 4 лет назад

includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element.

EPSS: Низкий
github логотип

GHSA-xvhr-xr27-hpmq

больше 3 лет назад

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xvhr-qprg-rjpw

почти 5 лет назад

mruby is vulnerable to NULL Pointer Dereference

EPSS: Низкий
github логотип

GHSA-xvhr-84pp-9r87

11 месяцев назад

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvhr-7q4q-qjgp

больше 4 лет назад

thinkphp SQL Injection via the index.php s parameter

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvhr-5h5w-3gx4

больше 4 лет назад

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-xvhr-3rcv-j8f8

больше 2 лет назад

A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers to inject arbitrary SQL commands via the PmbOpac-LOGIN cookie value.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvhq-v5ww-mmhx

больше 4 лет назад

SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php.

EPSS: Низкий
github логотип

GHSA-xvhq-qx4p-j8j9

больше 4 лет назад

Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2099.

EPSS: Низкий
github логотип

GHSA-xvhq-qrmp-cx9w

8 месяцев назад

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvhq-9p7m-5c3c

больше 4 лет назад

Buffer underflow in redlight.sys in BufferZone 2.1 and 2.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by sending a small buffer size value to the FsSetVolumeInformation IOCTL handler code with a FsSetDirectoryInformation subcode containing a large buffer.

EPSS: Низкий
github логотип

GHSA-xvhq-4mp3-f354

больше 4 лет назад

SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.

EPSS: Низкий
github логотип

GHSA-xvhp-xj53-p6h7

больше 2 лет назад

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is resolved in version 1.2.7.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xvhp-cm9x-2m2h

больше 4 лет назад

A vulnerability in the web-based management interface for Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvhp-2844-v475

больше 2 лет назад

An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xvhm-h729-47f2

больше 4 лет назад

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality and integrity via vectors related to File Folders / URL Attachment.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvhx-jwjw-g589

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to modify protected parts of the file system.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-xvhw-jxmj-rx78

An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an attacker can easily connect to the TELNET daemon using the default credentials if they have not been changed by the user.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhw-73xq-6w53

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xvhv-xwq7-mggv

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
13 дней назад
github логотип
GHSA-xvhv-fm6p-g8q4

includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhr-xr27-hpmq

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
95%
Критический
больше 3 лет назад
github логотип
GHSA-xvhr-qprg-rjpw

mruby is vulnerable to NULL Pointer Dereference

2%
Низкий
почти 5 лет назад
github логотип
GHSA-xvhr-84pp-9r87

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-xvhr-7q4q-qjgp

thinkphp SQL Injection via the index.php s parameter

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhr-5h5w-3gx4

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

CVSS3: 5.5
58%
Средний
больше 4 лет назад
github логотип
GHSA-xvhr-3rcv-j8f8

A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers to inject arbitrary SQL commands via the PmbOpac-LOGIN cookie value.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xvhq-v5ww-mmhx

SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhq-qx4p-j8j9

Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2099.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhq-qrmp-cx9w

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

CVSS3: 9.8
1%
Низкий
8 месяцев назад
github логотип
GHSA-xvhq-9p7m-5c3c

Buffer underflow in redlight.sys in BufferZone 2.1 and 2.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by sending a small buffer size value to the FsSetVolumeInformation IOCTL handler code with a FsSetDirectoryInformation subcode containing a large buffer.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhq-4mp3-f354

SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhp-xj53-p6h7

An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projects within the organization. The issue is resolved in version 1.2.7.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvhp-cm9x-2m2h

A vulnerability in the web-based management interface for Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhp-2844-v475

An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvhm-h729-47f2

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality and integrity via vectors related to File Folders / URL Attachment.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу