Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-xv34-vpcm-23p2

около 1 года назад

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.

CVSS3: 7.1
EPSS: Средний
github логотип

GHSA-xv34-39fc-6ghr

около 4 лет назад

There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv33-m47j-6p6j

около 4 лет назад

Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.

EPSS: Низкий
github логотип

GHSA-xv33-44vw-w3qg

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to inject arbitrary web script or HTML via (1) the v, show, or sec_name parameters to main.php, (2) the inadmin, newsev, or postid parameters to 5.php, or (3) the id parameter to 0.php.

EPSS: Низкий
github логотип

GHSA-xv32-q7h7-g7hp

около 4 лет назад

Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request.

EPSS: Низкий
github логотип

GHSA-xv32-hwgf-r7x9

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Hotel Listing hotel-listing allows Reflected XSS.This issue affects Hotel Listing: from n/a through <= 1.4.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xv32-fpqh-v67r

около 1 года назад

An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xv32-4rjr-hg8q

около 4 лет назад

An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.

EPSS: Средний
github логотип

GHSA-xv2x-75x9-84vr

около 4 лет назад

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

EPSS: Низкий
github логотип

GHSA-xv2w-x5xm-9j74

больше 3 лет назад

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv2w-qq3v-j35x

больше 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On Line plugin <= 4.6.1 versions.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xv2w-5rg6-j3gc

около 3 лет назад

Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xv2w-3fww-7hvf

около 2 лет назад

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv2v-3fj4-g6xm

больше 4 лет назад

send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.

EPSS: Низкий
github логотип

GHSA-xv2q-j99p-j42f

больше 3 лет назад

Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv2q-4cq2-h5pc

около 1 года назад

A logic error was addressed with improved error handling. This issue is fixed in macOS Sequoia 15.6. iCloud Private Relay may not activate when more than one user is logged in at the same time.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xv2p-wchj-qjhp

5 месяцев назад

Mattermost fails to bound memory allocation when processing DOC files

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv2p-554f-pwcf

около 2 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-xv2m-p78g-cm3m

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: idpf: fix double free and use-after-free in aux device error paths When auxiliary_device_add() fails in idpf_plug_vport_aux_dev() or idpf_plug_core_aux_dev(), the err_aux_dev_add label calls auxiliary_device_uninit() and falls through to err_aux_dev_init. The uninit call will trigger put_device(), which invokes the release callback (idpf_vport_adev_release / idpf_core_adev_release) that frees iadev. The fall-through then reads adev->id from the freed iadev for ida_free() and double-frees iadev with kfree(). Free the IDA slot and clear the back-pointer before uninit, while adev is still valid, then return immediately. Commit 65637c3a1811 ("idpf: fix UAF in RDMA core aux dev deinitialization") fixed the same use-after-free in the matching unplug path in this file but missed both probe error paths.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv2m-fg2f-xrrw

больше 4 лет назад

The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv34-vpcm-23p2

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.

CVSS3: 7.1
32%
Средний
около 1 года назад
github логотип
GHSA-xv34-39fc-6ghr

There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xv33-m47j-6p6j

Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xv33-44vw-w3qg

Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to inject arbitrary web script or HTML via (1) the v, show, or sec_name parameters to main.php, (2) the inadmin, newsev, or postid parameters to 5.php, or (3) the id parameter to 0.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv32-q7h7-g7hp

Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xv32-hwgf-r7x9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Hotel Listing hotel-listing allows Reflected XSS.This issue affects Hotel Listing: from n/a through <= 1.4.0.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-xv32-fpqh-v67r

An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise.

CVSS3: 9.8
12%
Средний
около 1 года назад
github логотип
GHSA-xv32-4rjr-hg8q

An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.

45%
Средний
около 4 лет назад
github логотип
GHSA-xv2x-75x9-84vr

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

6%
Низкий
около 4 лет назад
github логотип
GHSA-xv2w-x5xm-9j74

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xv2w-qq3v-j35x

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On Line plugin <= 4.6.1 versions.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv2w-5rg6-j3gc

Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-xv2w-3fww-7hvf

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1.

CVSS3: 7.5
2%
Низкий
около 2 лет назад
github логотип
GHSA-xv2v-3fj4-g6xm

send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xv2q-j99p-j42f

Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xv2q-4cq2-h5pc

A logic error was addressed with improved error handling. This issue is fixed in macOS Sequoia 15.6. iCloud Private Relay may not activate when more than one user is logged in at the same time.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xv2p-wchj-qjhp

Mattermost fails to bound memory allocation when processing DOC files

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xv2p-554f-pwcf

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 2 месяцев назад
github логотип
GHSA-xv2m-p78g-cm3m

In the Linux kernel, the following vulnerability has been resolved: idpf: fix double free and use-after-free in aux device error paths When auxiliary_device_add() fails in idpf_plug_vport_aux_dev() or idpf_plug_core_aux_dev(), the err_aux_dev_add label calls auxiliary_device_uninit() and falls through to err_aux_dev_init. The uninit call will trigger put_device(), which invokes the release callback (idpf_vport_adev_release / idpf_core_adev_release) that frees iadev. The fall-through then reads adev->id from the freed iadev for ida_free() and double-frees iadev with kfree(). Free the IDA slot and clear the back-pointer before uninit, while adev is still valid, then return immediately. Commit 65637c3a1811 ("idpf: fix UAF in RDMA core aux dev deinitialization") fixed the same use-after-free in the matching unplug path in this file but missed both probe error paths.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xv2m-fg2f-xrrw

The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу