Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-4274-f6v9-qg7w

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4273-vg8f-3qj2

больше 3 лет назад

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by loading malicious Tcl code on an affected device. A successful exploit could allow the attacker to cause memory corruption or execute the code with root privileges on the underlying OS of the affected device.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4273-ccpv-pfm8

больше 1 года назад

i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a tunneled, replayed message has a behavior discrepancy (it may be dropped, or may result in a Wrong Destination response). An attack would take days to complete.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4272-8494-h23x

почти 2 года назад

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-426w-g76x-326w

больше 3 лет назад

Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-426w-795m-hg3h

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Show Stats allows Cross Site Request Forgery. This issue affects WP Show Stats: from n/a through 1.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-426v-3j6g-3rj5

больше 3 лет назад

The Pegasus Airlines (aka com.wPegasusAirlines) application 0.84.13503.96707 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-426r-76c6-x67x

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-426q-975p-w5cr

больше 3 лет назад

phpMyAdmin Denial of service (DOS) attack with dbase extension

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-426p-c3p2-xqhp

больше 2 лет назад

Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-426p-74fr-m2wx

больше 2 лет назад

Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-426p-4cj4-4gwx

больше 3 лет назад

Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-426m-8vmg-c647

больше 1 года назад

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-426m-7hx7-xvph

5 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-426m-724x-9cm6

почти 4 года назад

Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters.

EPSS: Низкий
github логотип

GHSA-426j-23c4-55m8

почти 2 года назад

Ashlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B or X_T files. The issue results from the lack of proper validation of user-supplied data, which can result in a write before the start of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18552.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-426h-v87f-gxvw

больше 2 лет назад

Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-426h-mq34-gjcg

около 1 года назад

IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-426h-24vj-qwxf

почти 6 лет назад

Command Injection in npm-programmatic

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-426g-wxf4-8rhw

больше 3 лет назад

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service in the context of the current user.

CVSS3: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4274-f6v9-qg7w

Multiple cross-site scripting (XSS) vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4273-vg8f-3qj2

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter. An attacker could exploit this vulnerability by loading malicious Tcl code on an affected device. A successful exploit could allow the attacker to cause memory corruption or execute the code with root privileges on the underlying OS of the affected device.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4273-ccpv-pfm8

i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a tunneled, replayed message has a behavior discrepancy (it may be dropped, or may result in a Wrong Destination response). An attack would take days to complete.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4272-8494-h23x

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-426w-g76x-326w

Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-426w-795m-hg3h

Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Show Stats allows Cross Site Request Forgery. This issue affects WP Show Stats: from n/a through 1.5.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-426v-3j6g-3rj5

The Pegasus Airlines (aka com.wPegasusAirlines) application 0.84.13503.96707 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-426r-76c6-x67x

Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-426q-975p-w5cr

phpMyAdmin Denial of service (DOS) attack with dbase extension

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-426p-c3p2-xqhp

Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO's devices.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-426p-74fr-m2wx

Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-426p-4cj4-4gwx

Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-426m-8vmg-c647

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-426m-7hx7-xvph

Rejected reason: Not used

5 месяцев назад
github логотип
GHSA-426m-724x-9cm6

Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters.

2%
Низкий
почти 4 года назад
github логотип
GHSA-426j-23c4-55m8

Ashlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B or X_T files. The issue results from the lack of proper validation of user-supplied data, which can result in a write before the start of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18552.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-426h-v87f-gxvw

Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application.

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-426h-mq34-gjcg

IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-426h-24vj-qwxf

Command Injection in npm-programmatic

CVSS3: 9.8
1%
Низкий
почти 6 лет назад
github логотип
GHSA-426g-wxf4-8rhw

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service in the context of the current user.

CVSS3: 4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу