Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3j8g-45hc-8h5f

почти 2 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3j8f-xvm3-ffx4

больше 3 лет назад

Authorization Bypass in parse-path

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3j89-v6qj-mgf2

больше 3 лет назад

LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different roles and privileges, intended to limit what data and services they can interact with. However, no access control is enforced for WebSocket-based communication to the PM application server, which will forward requests to any configured back-end server, regardless of whether the user's access rights should permit this. As a result, even the most low-privileged user can interact with any back-end component that has a LogRhythm agent installed.

EPSS: Низкий
github логотип

GHSA-3j89-mpwx-chrr

почти 4 года назад

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3j89-mgwv-f23v

7 месяцев назад

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tiktok_user_id’ parameter in all versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3j89-cv92-pv3w

около 4 лет назад

A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c. This vulnerability can lead to a Denial of Service (DoS).

EPSS: Низкий
github логотип

GHSA-3j88-h584-rq62

больше 3 лет назад

A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through the SNMP protocol.

EPSS: Низкий
github логотип

GHSA-3j88-7hxg-wjh6

больше 3 лет назад

Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.

EPSS: Низкий
github логотип

GHSA-3j87-xcp2-3mgf

больше 1 года назад

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3j87-859p-q82m

11 месяцев назад

An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j87-7wxc-hh89

больше 3 лет назад

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4934, and CVE-2015-4935.

EPSS: Средний
github логотип

GHSA-3j85-rwqm-2894

почти 4 года назад

Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j85-fggf-7m9p

больше 3 лет назад

Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.

EPSS: Низкий
github логотип

GHSA-3j85-7c4g-4f56

около 1 года назад

Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3j85-7795-mc66

3 месяца назад

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the frontend code to gain administrator privileges on the website.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j85-6864-55p3

около 3 лет назад

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-3j84-x8jq-q9c2

больше 3 лет назад

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j84-rjwj-29h2

почти 3 года назад

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3j84-m7p6-xr37

больше 3 лет назад

Tarantella Enterprise before 3.11 allows bypassing Access Control.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3j84-jghj-gqwg

больше 3 лет назад

Istio before 1.8.6 and 1.9.x before 1.9.5, when a gateway is using the AUTO_PASSTHROUGH routing configuration, allows attackers to bypass authorization checks and access unexpected services in the cluster.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3j8g-45hc-8h5f

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3.

CVSS3: 7.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3j8f-xvm3-ffx4

Authorization Bypass in parse-path

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j89-v6qj-mgf2

LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different roles and privileges, intended to limit what data and services they can interact with. However, no access control is enforced for WebSocket-based communication to the PM application server, which will forward requests to any configured back-end server, regardless of whether the user's access rights should permit this. As a result, even the most low-privileged user can interact with any back-end component that has a LogRhythm agent installed.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j89-mpwx-chrr

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

CVSS3: 8.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-3j89-mgwv-f23v

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tiktok_user_id’ parameter in all versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 4.7
3%
Низкий
7 месяцев назад
github логотип
GHSA-3j89-cv92-pv3w

A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c. This vulnerability can lead to a Denial of Service (DoS).

0%
Низкий
около 4 лет назад
github логотип
GHSA-3j88-h584-rq62

A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through the SNMP protocol.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j88-7hxg-wjh6

Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j87-xcp2-3mgf

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-3j87-859p-q82m

An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3j87-7wxc-hh89

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4934, and CVE-2015-4935.

23%
Средний
больше 3 лет назад
github логотип
GHSA-3j85-rwqm-2894

Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3j85-fggf-7m9p

Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j85-7c4g-4f56

Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3j85-7795-mc66

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the frontend code to gain administrator privileges on the website.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-3j85-6864-55p3

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVSS3: 9.8
73%
Высокий
около 3 лет назад
github логотип
GHSA-3j84-x8jq-q9c2

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j84-rjwj-29h2

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number.

CVSS3: 5.6
0%
Низкий
почти 3 года назад
github логотип
GHSA-3j84-m7p6-xr37

Tarantella Enterprise before 3.11 allows bypassing Access Control.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j84-jghj-gqwg

Istio before 1.8.6 and 1.9.x before 1.9.5, when a gateway is using the AUTO_PASSTHROUGH routing configuration, allows attackers to bypass authorization checks and access unexpected services in the cluster.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу