Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3q67-3qq4-p27f

5 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems Trade Ltd. Co. Saysis Web Portal allows Path Traversal.This issue affects Saysis Web Portal: from 3.1.9 & 3.2.0 before 3.2.1.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3q66-p66c-2vq4

больше 3 лет назад

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 6.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3q66-gj8f-4pff

больше 3 лет назад

Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.

EPSS: Низкий
github логотип

GHSA-3q63-vj3h-7j3f

больше 3 лет назад

A potential vulnerability in some Lenovo ThinkPads may allow an attacker to execute arbitrary code under SMM under certain circumstances.

EPSS: Низкий
github логотип

GHSA-3q63-c3mx-rfx6

больше 3 лет назад

An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripting (XSS) via a field in the traffic group interface.

EPSS: Низкий
github логотип

GHSA-3q62-wpc2-x57g

больше 3 лет назад

The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allows callers to select arbitrary files to send to an arbitrary email address.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q62-h7x3-478p

больше 3 лет назад

XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q62-89h6-6qhx

больше 3 лет назад

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_Key` and `WL_DefaultKeyID` configuration values in the function located at offset `0x1c7d28` of firmware 6.9Z , and even more specifically on the command execution occuring at offset `0x1c7f6c`.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3q5x-7mxp-rp6j

около 6 лет назад

Remote code execution via vulnerable Symphony dependecy injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3q5x-3fpw-pfv9

больше 3 лет назад

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q5v-jr96-99g5

почти 3 года назад

Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3q5v-cqrv-2527

больше 3 лет назад

Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

EPSS: Низкий
github логотип

GHSA-3q5v-35pc-2r23

больше 3 лет назад

Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3q5r-w7pw-96xm

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Kvvaradha Kv TinyMCE Editor Add Fonts plugin <= 1.1 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3q5r-g7hx-jv3c

почти 2 года назад

The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals, namely, Buffer.prototype.utf8Write, the application can modify the result of path.resolve(), which leads to a path traversal vulnerability. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-3q5r-87hx-pv77

больше 2 лет назад

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 29051.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3q5q-j6r6-cgv8

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to avoid crash [Why] In the case where a dml allocation fails for any reason, the current state's dml contexts would no longer be valid. Then subsequent calls dc_state_copy_internal would shallow copy invalid memory and if the new state was released, a double free would occur. [How] Reset dml pointers in new_state to NULL and avoid invalid pointer (cherry picked from commit bcafdc61529a48f6f06355d78eb41b3aeda5296c)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3q5q-f79q-7hr2

больше 7 лет назад

High severity vulnerability that affects rubyzip

EPSS: Низкий
github логотип

GHSA-3q5q-8rwq-gwp8

больше 2 лет назад

Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3q5q-2qvx-5cm7

больше 3 лет назад

HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q67-3qq4-p27f

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems Trade Ltd. Co. Saysis Web Portal allows Path Traversal.This issue affects Saysis Web Portal: from 3.1.9 & 3.2.0 before 3.2.1.

CVSS3: 8.6
0%
Низкий
5 месяцев назад
github логотип
GHSA-3q66-p66c-2vq4

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 6.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q66-gj8f-4pff

Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q63-vj3h-7j3f

A potential vulnerability in some Lenovo ThinkPads may allow an attacker to execute arbitrary code under SMM under certain circumstances.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q63-c3mx-rfx6

An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripting (XSS) via a field in the traffic group interface.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q62-wpc2-x57g

The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allows callers to select arbitrary files to send to an arbitrary email address.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q62-h7x3-478p

XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q62-89h6-6qhx

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_Key` and `WL_DefaultKeyID` configuration values in the function located at offset `0x1c7d28` of firmware 6.9Z , and even more specifically on the command execution occuring at offset `0x1c7f6c`.

CVSS3: 10
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q5x-7mxp-rp6j

Remote code execution via vulnerable Symphony dependecy injection

CVSS3: 9.8
1%
Низкий
около 6 лет назад
github логотип
GHSA-3q5x-3fpw-pfv9

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q5v-jr96-99g5

Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.

CVSS3: 8.1
5%
Низкий
почти 3 года назад
github логотип
GHSA-3q5v-cqrv-2527

Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3q5v-35pc-2r23

Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3q5r-w7pw-96xm

Cross-Site Request Forgery (CSRF) vulnerability in Kvvaradha Kv TinyMCE Editor Add Fonts plugin <= 1.1 versions.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3q5r-g7hx-jv3c

The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals, namely, Buffer.prototype.utf8Write, the application can modify the result of path.resolve(), which leads to a path traversal vulnerability. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 7.9
1%
Низкий
почти 2 года назад
github логотип
GHSA-3q5r-87hx-pv77

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 29051.

CVSS3: 5.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3q5q-j6r6-cgv8

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to avoid crash [Why] In the case where a dml allocation fails for any reason, the current state's dml contexts would no longer be valid. Then subsequent calls dc_state_copy_internal would shallow copy invalid memory and if the new state was released, a double free would occur. [How] Reset dml pointers in new_state to NULL and avoid invalid pointer (cherry picked from commit bcafdc61529a48f6f06355d78eb41b3aeda5296c)

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3q5q-f79q-7hr2

High severity vulnerability that affects rubyzip

больше 7 лет назад
github логотип
GHSA-3q5q-8rwq-gwp8

Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.

CVSS3: 8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3q5q-2qvx-5cm7

HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу