Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-43vh-22m9-hr9x

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.

EPSS: Низкий
github логотип

GHSA-43vf-866m-gxw3

почти 4 года назад

Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

EPSS: Низкий
github логотип

GHSA-43vf-7f59-hwgm

больше 3 лет назад

UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43vf-2x6g-p2m5

больше 5 лет назад

Malicious Package in browserift

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43vf-262m-2h43

почти 4 года назад

Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.

EPSS: Низкий
github логотип

GHSA-43vc-pv65-hrhm

почти 4 года назад

The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43v9-vxgc-g477

больше 3 лет назад

Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

EPSS: Низкий
github логотип

GHSA-43v9-p898-p49x

больше 3 лет назад

An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43v9-5jqv-2894

больше 3 лет назад

Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors.

EPSS: Низкий
github логотип

GHSA-43v7-wxwq-5hp3

почти 4 года назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-43v6-mq3r-qmhx

8 месяцев назад

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43v5-w42f-65jx

почти 4 года назад

Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.

EPSS: Высокий
github логотип

GHSA-43v5-882w-9hpj

больше 2 лет назад

A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-43v5-5g9q-m394

больше 3 лет назад

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "GDI Information Disclosure Vulnerability."

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-43v3-5j9f-4vh2

больше 1 года назад

IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43v2-6grp-9pp9

больше 3 лет назад

Apache Tomcat does not enforce the maxHttpHeaderSize limit

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-43rr-x62x-q96w

22 дня назад

MineAdmin improperly refreshes tokens

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-43rr-wcj9-h45w

почти 4 года назад

Incorrect Authorization in PostgreSQL

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-43rr-vh89-fj97

больше 3 лет назад

An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-43rr-prv9-867f

почти 4 года назад

ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43vh-22m9-hr9x

Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-43vf-866m-gxw3

Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

0%
Низкий
почти 4 года назад
github логотип
GHSA-43vf-7f59-hwgm

UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-43vf-2x6g-p2m5

Malicious Package in browserift

CVSS3: 9.8
больше 5 лет назад
github логотип
GHSA-43vf-262m-2h43

Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-43vc-pv65-hrhm

The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-43v9-vxgc-g477

Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43v9-p898-p49x

An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-43v9-5jqv-2894

Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-43v7-wxwq-5hp3

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

2%
Низкий
почти 4 года назад
github логотип
GHSA-43v6-mq3r-qmhx

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-43v5-w42f-65jx

Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.

88%
Высокий
почти 4 года назад
github логотип
GHSA-43v5-882w-9hpj

A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-43v5-5g9q-m394

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "GDI Information Disclosure Vulnerability."

CVSS3: 3.3
6%
Низкий
больше 3 лет назад
github логотип
GHSA-43v3-5j9f-4vh2

IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-43v2-6grp-9pp9

Apache Tomcat does not enforce the maxHttpHeaderSize limit

CVSS3: 7.5
16%
Средний
больше 3 лет назад
github логотип
GHSA-43rr-x62x-q96w

MineAdmin improperly refreshes tokens

CVSS3: 5
0%
Низкий
22 дня назад
github логотип
GHSA-43rr-wcj9-h45w

Incorrect Authorization in PostgreSQL

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-43rr-vh89-fj97

An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.

CVSS3: 8.1
8%
Низкий
больше 3 лет назад
github логотип
GHSA-43rr-prv9-867f

ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.

CVSS3: 9.8
16%
Средний
почти 4 года назад

Уязвимостей на страницу