Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-42fv-jxfg-2qh3

больше 3 лет назад

Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42fr-vpc6-8qj6

6 месяцев назад

A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /visitor/addvisitor.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-42fr-8xjf-ghxh

почти 4 года назад

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

EPSS: Средний
github логотип

GHSA-42fr-746c-5m55

больше 3 лет назад

The Lagu POP Indonesia (aka com.lagu.pop.indonesia.xygwphqpuomclljvaa) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-42fq-x79v-5vv5

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: udmabuf: fix a buf size overflow issue during udmabuf creation by casting size_limit_mb to u64 when calculate pglimit.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42fp-75cg-7jf8

больше 3 лет назад

Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the tmp directory under the document root.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42fp-4qf3-rqhj

почти 4 года назад

Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.

EPSS: Низкий
github логотип

GHSA-42fp-4hm3-j8r7

около 7 лет назад

Moderate severity vulnerability that affects moin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42fm-7h9g-phq7

больше 3 лет назад

An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST parameter filename. This can be used to place attacker controlled code on the file system that can then be executed. Further, the filename parameter is vulnerable to path traversal and allows the attacker to place the file anywhere on the system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42fj-5wgr-vp3x

больше 3 лет назад

Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 MVPN (aka MVPNv6) packets, aka Bug ID CSCub34945, a different vulnerability than CVE-2013-1164.

EPSS: Низкий
github логотип

GHSA-42fh-xcj5-fxwg

около 2 лет назад

Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows Upload a Web Shell to a Web Server.This issue affects CyberMath: from v.1.4 before v.1.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42fh-pvvh-999x

10 месяцев назад

Unregistered users can see "public" messages from a closed wiki via notifications from a different wiki

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-42fh-m3g3-79wr

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the quickppr_redirects[request][] parameter in the redirect-updates page to wp-admin/admin.php.

EPSS: Низкий
github логотип

GHSA-42fh-f837-4fj4

почти 4 года назад

misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-42fg-q2m2-v999

почти 4 года назад

IBM Aspera High-Speed Transfer 4.3.1 and earlier could allow an authenticated user to obtain information from non sensitive operating system files that they should not have access to. IBM X-Force ID: 222059.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-42fg-gx44-hcxv

3 месяца назад

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta Disclosure in versions up to and including 1.3.2. This is due to missing object-level authorization checks in the resolve_variables() AJAX handler. This makes it possible for authenticated attackers with the siteseo_manage capability (e.g., Author-level users who have been granted SiteSEO access by an administrator) to read arbitrary post metadata from any post, page, attachment, or WooCommerce order they cannot edit, via the custom field variable resolution feature granted they have been given access to SiteSEO by an administrator and legacy storage is enabled. In affected WooCommerce installations, this exposes sensitive customer billing information including names, email addresses, phone numbers, physical addresses, and payment methods.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-42fg-866w-8hxj

почти 4 года назад

Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.

EPSS: Средний
github логотип

GHSA-42ff-q9r4-9fgc

больше 3 лет назад

The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."

EPSS: Средний
github логотип

GHSA-42ff-q6fw-hf6c

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <= 3.5 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-42ff-p6q5-g8pg

больше 2 лет назад

In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.  

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42fv-jxfg-2qh3

Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-42fr-vpc6-8qj6

A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /visitor/addvisitor.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-42fr-8xjf-ghxh

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

67%
Средний
почти 4 года назад
github логотип
GHSA-42fr-746c-5m55

The Lagu POP Indonesia (aka com.lagu.pop.indonesia.xygwphqpuomclljvaa) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42fq-x79v-5vv5

In the Linux kernel, the following vulnerability has been resolved: udmabuf: fix a buf size overflow issue during udmabuf creation by casting size_limit_mb to u64 when calculate pglimit.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-42fp-75cg-7jf8

Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the tmp directory under the document root.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-42fp-4qf3-rqhj

Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.

1%
Низкий
почти 4 года назад
github логотип
GHSA-42fp-4hm3-j8r7

Moderate severity vulnerability that affects moin

CVSS3: 6.1
1%
Низкий
около 7 лет назад
github логотип
GHSA-42fm-7h9g-phq7

An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST parameter filename. This can be used to place attacker controlled code on the file system that can then be executed. Further, the filename parameter is vulnerable to path traversal and allows the attacker to place the file anywhere on the system.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42fj-5wgr-vp3x

Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 MVPN (aka MVPNv6) packets, aka Bug ID CSCub34945, a different vulnerability than CVE-2013-1164.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42fh-xcj5-fxwg

Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows Upload a Web Shell to a Web Server.This issue affects CyberMath: from v.1.4 before v.1.5.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-42fh-pvvh-999x

Unregistered users can see "public" messages from a closed wiki via notifications from a different wiki

CVSS3: 4.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-42fh-m3g3-79wr

Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the quickppr_redirects[request][] parameter in the redirect-updates page to wp-admin/admin.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-42fh-f837-4fj4

misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-42fg-q2m2-v999

IBM Aspera High-Speed Transfer 4.3.1 and earlier could allow an authenticated user to obtain information from non sensitive operating system files that they should not have access to. IBM X-Force ID: 222059.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-42fg-gx44-hcxv

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta Disclosure in versions up to and including 1.3.2. This is due to missing object-level authorization checks in the resolve_variables() AJAX handler. This makes it possible for authenticated attackers with the siteseo_manage capability (e.g., Author-level users who have been granted SiteSEO access by an administrator) to read arbitrary post metadata from any post, page, attachment, or WooCommerce order they cannot edit, via the custom field variable resolution feature granted they have been given access to SiteSEO by an administrator and legacy storage is enabled. In affected WooCommerce installations, this exposes sensitive customer billing information including names, email addresses, phone numbers, physical addresses, and payment methods.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-42fg-866w-8hxj

Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.

50%
Средний
почти 4 года назад
github логотип
GHSA-42ff-q9r4-9fgc

The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."

45%
Средний
больше 3 лет назад
github логотип
GHSA-42ff-q6fw-hf6c

Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <= 3.5 versions.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42ff-p6q5-g8pg

In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.  

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу