Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 567

Количество 288 567

github логотип

GHSA-27q4-qvjw-mjxw

4 месяца назад

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27q4-qhjq-3v56

около 3 лет назад

SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting vulnerability.

EPSS: Низкий
github логотип

GHSA-27q4-38qf-m25h

около 3 лет назад

OpenStack Compute Nova Improper Access Control

EPSS: Низкий
github логотип

GHSA-27q3-p62g-44fr

около 3 лет назад

Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory regions. An attacker can manipulate API functions by writing arbitrary data into the resolved address of a raw pointer.

EPSS: Низкий
github логотип

GHSA-27q3-ffrp-2fr5

больше 3 лет назад

SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.

EPSS: Низкий
github логотип

GHSA-27q3-cvqp-pf2m

больше 3 лет назад

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function CloudACMunualUpdate, via the deviceMac and deviceName parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-27q3-84pw-qmf2

больше 2 лет назад

A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo SCADA Expert 2021(All Versions prior to October 2022), ClearSCADA (All Versions)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27q3-764f-92x3

около 3 лет назад

WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

EPSS: Низкий
github логотип

GHSA-27q3-69pg-c92r

около 3 лет назад

stalin 0.11-5 allows local users to write to arbitrary files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27q2-gvv9-2h9v

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. Crafted data in a J2K file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15095.

EPSS: Низкий
github логотип

GHSA-27q2-f57c-rgmr

около 3 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

EPSS: Низкий
github логотип

GHSA-27q2-f36g-hmv6

больше 2 лет назад

Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27px-qpmj-qg38

около 3 лет назад

Paste Script has improper group memberships permissions

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27px-4rjc-4chg

больше 3 лет назад

The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27pw-7wxg-pvx9

больше 1 года назад

Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27pw-27h4-97mx

около 3 лет назад

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.

EPSS: Низкий
github логотип

GHSA-27pv-q55r-222g

около 4 лет назад

Path traversal in github.com/ipfs/go-ipfs

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-27pv-p83w-4xp4

около 3 лет назад

Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.

EPSS: Низкий
github логотип

GHSA-27pv-9qxj-gfj6

около 3 лет назад

In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123700383

EPSS: Низкий
github логотип

GHSA-27pv-53mj-ff4j

больше 3 лет назад

PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27q4-qvjw-mjxw

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command execution.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-27q4-qhjq-3v56

SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting vulnerability.

0%
Низкий
около 3 лет назад
github логотип
GHSA-27q4-38qf-m25h

OpenStack Compute Nova Improper Access Control

0%
Низкий
около 3 лет назад
github логотип
GHSA-27q3-p62g-44fr

Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory regions. An attacker can manipulate API functions by writing arbitrary data into the resolved address of a raw pointer.

0%
Низкий
около 3 лет назад
github логотип
GHSA-27q3-ffrp-2fr5

SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27q3-cvqp-pf2m

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function CloudACMunualUpdate, via the deviceMac and deviceName parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
18%
Средний
больше 3 лет назад
github логотип
GHSA-27q3-84pw-qmf2

A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo SCADA Expert 2021(All Versions prior to October 2022), ClearSCADA (All Versions)

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27q3-764f-92x3

WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.

1%
Низкий
около 3 лет назад
github логотип
GHSA-27q3-69pg-c92r

stalin 0.11-5 allows local users to write to arbitrary files.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-27q2-gvv9-2h9v

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.7.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. Crafted data in a J2K file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15095.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-27q2-f57c-rgmr

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

0%
Низкий
около 3 лет назад
github логотип
GHSA-27q2-f36g-hmv6

Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27px-qpmj-qg38

Paste Script has improper group memberships permissions

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-27px-4rjc-4chg

The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27pw-7wxg-pvx9

Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-27pw-27h4-97mx

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.

5%
Низкий
около 3 лет назад
github логотип
GHSA-27pv-q55r-222g

Path traversal in github.com/ipfs/go-ipfs

CVSS3: 7.7
2%
Низкий
около 4 лет назад
github логотип
GHSA-27pv-p83w-4xp4

Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.

3%
Низкий
около 3 лет назад
github логотип
GHSA-27pv-9qxj-gfj6

In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123700383

0%
Низкий
около 3 лет назад
github логотип
GHSA-27pv-53mj-ff4j

PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.

5%
Низкий
больше 3 лет назад

Уязвимостей на страницу