Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 360

Количество 324 360

github логотип

GHSA-xv45-qm36-h77q

больше 2 лет назад

ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a Toolbox user's context through the deserialization of an untrusted configuration file. Two CVSS scores have been provided to capture the differences between the two aforementioned attack vectors.  Customers are advised to update to ToolboxST 7.10 which can be found in ControlST 7.10. If unable to update at this time customers should ensure they are following the guidance laid out in GE Gas Power's Secure Deployment Guide (GEH-6839). Customers should ensure they are not running ToolboxST as an Administrative user. 

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv45-9768-g2mm

почти 4 года назад

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xv44-pg58-qmq3

8 месяцев назад

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xv44-cpqx-3w77

почти 4 года назад

AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.

EPSS: Низкий
github логотип

GHSA-xv44-4p65-mmrx

больше 2 лет назад

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xv3x-x36v-w2jp

почти 4 года назад

Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

EPSS: Низкий
github логотип

GHSA-xv3x-4h27-q4j5

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv3w-jq9v-7wvx

почти 4 года назад

Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.

EPSS: Низкий
github логотип

GHSA-xv3v-mrcp-v5qc

около 3 лет назад

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv3r-wcc2-gmq8

почти 4 года назад

Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.

EPSS: Низкий
github логотип

GHSA-xv3q-rp6x-hwhw

почти 4 года назад

An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x, 16.x, and 17.x, and Certified Asterisk 13.21, because of an incomplete fix for CVE-2019-18351. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a result. The only thing that needs to be known is the peer's name; authentication details such as passwords do not need to be known. This vulnerability is only exploitable when the nat option is set to the default, or auto_force_rport.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv3q-r363-84pg

почти 4 года назад

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The control logic (CL) the LOGO! 8 executes could be manipulated in a way that could cause the device executing the CL to improperly handle the manipulation and crash. After successful execution of the attack, the device needs to be manually reset.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv3q-jrmm-4fxv

почти 3 года назад

Authentication Bypass in @strapi/plugin-users-permissions

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xv3q-5p25-85h4

около 4 лет назад

Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

EPSS: Низкий
github логотип

GHSA-xv3p-f59j-cqjv

почти 4 года назад

lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.

EPSS: Низкий
github логотип

GHSA-xv3m-vvvg-7mcg

почти 4 года назад

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as demonstrated by the filename=*public*%25252Fadmin_OnlyRead.txt substring.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv3m-73qx-8fg5

почти 3 года назад

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xv3j-qc59-2c8j

почти 4 года назад

The Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware has "admin" as its default password for the "admin" account, which makes it easier for remote attackers to obtain access.

EPSS: Низкий
github логотип

GHSA-xv3j-m88m-58h7

почти 4 года назад

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb.

EPSS: Низкий
github логотип

GHSA-xv3j-5xmw-q95p

почти 4 года назад

ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv45-qm36-h77q

ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a Toolbox user's context through the deserialization of an untrusted configuration file. Two CVSS scores have been provided to capture the differences between the two aforementioned attack vectors.  Customers are advised to update to ToolboxST 7.10 which can be found in ControlST 7.10. If unable to update at this time customers should ensure they are following the guidance laid out in GE Gas Power's Secure Deployment Guide (GEH-6839). Customers should ensure they are not running ToolboxST as an Administrative user. 

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv45-9768-g2mm

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS3: 5.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv44-pg58-qmq3

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xv44-cpqx-3w77

AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xv44-4p65-mmrx

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv3x-x36v-w2jp

Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv3x-4h27-q4j5

Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xv3w-jq9v-7wvx

Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xv3v-mrcp-v5qc

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVSS3: 8.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-xv3r-wcc2-gmq8

Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv3q-rp6x-hwhw

An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x, 16.x, and 17.x, and Certified Asterisk 13.21, because of an incomplete fix for CVE-2019-18351. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a result. The only thing that needs to be known is the peer's name; authentication details such as passwords do not need to be known. This vulnerability is only exploitable when the nat option is set to the default, or auto_force_rport.

CVSS3: 6.5
7%
Низкий
почти 4 года назад
github логотип
GHSA-xv3q-r363-84pg

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The control logic (CL) the LOGO! 8 executes could be manipulated in a way that could cause the device executing the CL to improperly handle the manipulation and crash. After successful execution of the attack, the device needs to be manually reset.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv3q-jrmm-4fxv

Authentication Bypass in @strapi/plugin-users-permissions

CVSS3: 8.2
почти 3 года назад
github логотип
GHSA-xv3q-5p25-85h4

Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

0%
Низкий
около 4 лет назад
github логотип
GHSA-xv3p-f59j-cqjv

lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.

5%
Низкий
почти 4 года назад
github логотип
GHSA-xv3m-vvvg-7mcg

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as demonstrated by the filename=*public*%25252Fadmin_OnlyRead.txt substring.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xv3m-73qx-8fg5

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm.

CVSS3: 7.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-xv3j-qc59-2c8j

The Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware has "admin" as its default password for the "admin" account, which makes it easier for remote attackers to obtain access.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv3j-m88m-58h7

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv3j-5xmw-q95p

ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

CVSS3: 9.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу