Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-426p-c3p2-xqhp

больше 2 лет назад

Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-426p-74fr-m2wx

больше 2 лет назад

Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-426p-4cj4-4gwx

больше 3 лет назад

Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-426m-8vmg-c647

больше 1 года назад

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-426m-7hx7-xvph

5 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-426m-724x-9cm6

почти 4 года назад

Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters.

EPSS: Низкий
github логотип

GHSA-426j-23c4-55m8

почти 2 года назад

Ashlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B or X_T files. The issue results from the lack of proper validation of user-supplied data, which can result in a write before the start of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18552.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-426h-v87f-gxvw

больше 2 лет назад

Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-426h-mq34-gjcg

около 1 года назад

IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-426h-24vj-qwxf

почти 6 лет назад

Command Injection in npm-programmatic

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-426g-wxf4-8rhw

больше 3 лет назад

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service in the context of the current user.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-426g-4c29-jjpr

8 месяцев назад

A vulnerability classified as critical was found in 1000projects Online Notice Board 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-426f-2r7q-j2xm

10 месяцев назад

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - HTML Tags allows Cross-Site Scripting (XSS).This issue affects Mediawiki - HTML Tags: from 1.39 through 1.43.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4269-qr56-7rgx

больше 3 лет назад

Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4269-mcfh-cp7q

5 месяцев назад

Indico may disclose unauthorized user details access via legacy API

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4269-gch5-8w3c

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.

EPSS: Низкий
github логотип

GHSA-4269-36rj-fxq8

больше 2 лет назад

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37556.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4268-mm99-gpjc

2 месяца назад

A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_book.php. Performing manipulation of the argument book_id results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4268-53h5-jjpj

больше 3 лет назад

Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4267-v6qh-xchc

больше 3 лет назад

** DISPUTED ** The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-426p-c3p2-xqhp

Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-426p-74fr-m2wx

Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-426p-4cj4-4gwx

Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-426m-8vmg-c647

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-426m-7hx7-xvph

Rejected reason: Not used

5 месяцев назад
github логотип
GHSA-426m-724x-9cm6

Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters.

2%
Низкий
почти 4 года назад
github логотип
GHSA-426j-23c4-55m8

Ashlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B or X_T files. The issue results from the lack of proper validation of user-supplied data, which can result in a write before the start of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18552.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-426h-v87f-gxvw

Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application.

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-426h-mq34-gjcg

IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-426h-24vj-qwxf

Command Injection in npm-programmatic

CVSS3: 9.8
1%
Низкий
почти 6 лет назад
github логотип
GHSA-426g-wxf4-8rhw

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service in the context of the current user.

CVSS3: 4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-426g-4c29-jjpr

A vulnerability classified as critical was found in 1000projects Online Notice Board 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-426f-2r7q-j2xm

Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - HTML Tags allows Cross-Site Scripting (XSS).This issue affects Mediawiki - HTML Tags: from 1.39 through 1.43.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-4269-qr56-7rgx

Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4269-mcfh-cp7q

Indico may disclose unauthorized user details access via legacy API

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-4269-gch5-8w3c

Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/download_file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4269-36rj-fxq8

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37556.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4268-mm99-gpjc

A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_book.php. Performing manipulation of the argument book_id results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-4268-53h5-jjpj

Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4267-v6qh-xchc

** DISPUTED ** The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. NOTE: The vendor states that the sample had specifically used a flag to bypass the DN check.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу