Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 308

Количество 288 308

github логотип

GHSA-23mj-f5f2-4h46

8 месяцев назад

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23mh-p5gr-48gh

больше 3 лет назад

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-23mh-jxf4-vm3h

около 3 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

EPSS: Низкий
github логотип

GHSA-23mg-qphc-9fg5

больше 3 лет назад

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

EPSS: Низкий
github логотип

GHSA-23mg-57wx-h29h

около 3 лет назад

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

EPSS: Низкий
github логотип

GHSA-23mf-2ffr-xmv9

больше 3 лет назад

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-23mc-xgfq-qhjf

около 3 лет назад

The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.

EPSS: Низкий
github логотип

GHSA-23mc-xgfj-48f2

больше 2 лет назад

Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23m7-v83h-jpr5

около 2 лет назад

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23m7-7w92-xgf9

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.

EPSS: Низкий
github логотип

GHSA-23m7-3cfp-h2gf

больше 3 лет назад

Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.

EPSS: Низкий
github логотип

GHSA-23m7-29g3-3g89

больше 1 года назад

D-Link G416 cfgsave upusb Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP service listening on TCP port 80. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21289.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23m6-v988-fw9r

около 3 лет назад

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. The SEC_FR trustlet has an out of bounds write. The Samsung ID is SVE-2019-15272 (October 2019).

EPSS: Низкий
github логотип

GHSA-23m6-m56p-vrhp

около 3 лет назад

An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Authentication header. However, when copying this header to parse, it does not check the size of the header, leading to a stack-based buffer overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23m5-7wvw-4c3f

около 2 лет назад

The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_deactivate_product function. This makes it possible for unauthenticated attackers to bulk deactivate products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23m5-7mv6-592m

больше 1 года назад

A vulnerability classified as critical was found in CXBSoft Url-shorting up to 1.3.1. This vulnerability affects unknown code of the file /pages/short_to_long.php of the component HTTP POST Request Handler. The manipulation of the argument shorturl leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250696. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23m4-p6hq-h69h

около 3 лет назад

airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23m4-7vqv-gc3v

около 3 лет назад

HGiga C&Cmail contains a SQL Injection vulnerability which allows attackers to injecting SQL commands in the URL parameter to execute unauthorized commands.

EPSS: Низкий
github логотип

GHSA-23m3-jp2w-3vpp

около 3 лет назад

The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

CVSS3: 7.3
EPSS: Средний
github логотип

GHSA-23m2-2fch-phwm

больше 3 лет назад

IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23mj-f5f2-4h46

An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input.

CVSS3: 8.8
3%
Низкий
8 месяцев назад
github логотип
GHSA-23mh-p5gr-48gh

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23mh-jxf4-vm3h

Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

9%
Низкий
около 3 лет назад
github логотип
GHSA-23mg-qphc-9fg5

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-23mg-57wx-h29h

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

3%
Низкий
около 3 лет назад
github логотип
GHSA-23mf-2ffr-xmv9

Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

CVSS3: 9.8
12%
Средний
больше 3 лет назад
github логотип
GHSA-23mc-xgfq-qhjf

The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.

0%
Низкий
около 3 лет назад
github логотип
GHSA-23mc-xgfj-48f2

Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-23m7-v83h-jpr5

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-23m7-7w92-xgf9

Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.

0%
Низкий
около 3 лет назад
github логотип
GHSA-23m7-3cfp-h2gf

Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-23m7-29g3-3g89

D-Link G416 cfgsave upusb Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP service listening on TCP port 80. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21289.

CVSS3: 8.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-23m6-v988-fw9r

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. The SEC_FR trustlet has an out of bounds write. The Samsung ID is SVE-2019-15272 (October 2019).

0%
Низкий
около 3 лет назад
github логотип
GHSA-23m6-m56p-vrhp

An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Authentication header. However, when copying this header to parse, it does not check the size of the header, leading to a stack-based buffer overflow.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-23m5-7wvw-4c3f

The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_deactivate_product function. This makes it possible for unauthenticated attackers to bulk deactivate products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-23m5-7mv6-592m

A vulnerability classified as critical was found in CXBSoft Url-shorting up to 1.3.1. This vulnerability affects unknown code of the file /pages/short_to_long.php of the component HTTP POST Request Handler. The manipulation of the argument shorturl leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250696. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-23m4-p6hq-h69h

airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-23m4-7vqv-gc3v

HGiga C&Cmail contains a SQL Injection vulnerability which allows attackers to injecting SQL commands in the URL parameter to execute unauthorized commands.

0%
Низкий
около 3 лет назад
github логотип
GHSA-23m3-jp2w-3vpp

The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

CVSS3: 7.3
24%
Средний
около 3 лет назад
github логотип
GHSA-23m2-2fch-phwm

IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу