Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3mm6-vwmh-qm9c

больше 3 лет назад

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3mm6-mv5c-6hfv

почти 4 года назад

LastPass prior to 2.5.1 has an insecure PIN implementation.

EPSS: Низкий
github логотип

GHSA-3mm6-hc5r-p5rx

больше 3 лет назад

Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mm6-4hpm-pgrc

больше 3 лет назад

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mm5-rh7g-ph5j

около 4 лет назад

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mm5-fxrj-9334

больше 3 лет назад

SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.

EPSS: Низкий
github логотип

GHSA-3mm4-w7v6-4rhv

около 4 лет назад

android-gif-drawable vulerable to denial of service due to unrestricted comment length

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mm4-v52x-x9rw

больше 3 лет назад

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

EPSS: Низкий
github логотип

GHSA-3mm4-jwgr-q6c5

больше 3 лет назад

Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

EPSS: Низкий
github логотип

GHSA-3mm3-wfpv-q85g

3 месяца назад

Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mm3-c684-p47h

больше 3 лет назад

The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3mm2-hvqw-hxq3

больше 3 лет назад

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3mjx-h33f-j53j

12 месяцев назад

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3mjx-fvq9-8vm2

больше 3 лет назад

BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3mjw-wv6f-4q2v

почти 4 года назад

Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160.

EPSS: Низкий
github логотип

GHSA-3mjv-89c5-xc65

больше 2 лет назад

In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3mjr-8v4p-9qf4

больше 1 года назад

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3mjr-5fr9-2r8m

больше 3 лет назад

The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mjq-qmqc-xrrv

почти 4 года назад

Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.

EPSS: Низкий
github логотип

GHSA-3mjq-gr7r-h6x3

около 1 года назад

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mm6-vwmh-qm9c

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mm6-mv5c-6hfv

LastPass prior to 2.5.1 has an insecure PIN implementation.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3mm6-hc5r-p5rx

Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mm6-4hpm-pgrc

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mm5-rh7g-ph5j

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3mm5-fxrj-9334

SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mm4-w7v6-4rhv

android-gif-drawable vulerable to denial of service due to unrestricted comment length

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3mm4-v52x-x9rw

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3mm4-jwgr-q6c5

Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3mm3-wfpv-q85g

Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage

CVSS3: 7.5
3 месяца назад
github логотип
GHSA-3mm3-c684-p47h

The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mm2-hvqw-hxq3

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335.

CVSS3: 7.2
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3mjx-h33f-j53j

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-3mjx-fvq9-8vm2

BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mjw-wv6f-4q2v

Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3mjv-89c5-xc65

In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mjr-8v4p-9qf4

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.

CVSS3: 7.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-3mjr-5fr9-2r8m

The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mjq-qmqc-xrrv

Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3mjq-gr7r-h6x3

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

CVSS3: 6.5
8%
Низкий
около 1 года назад

Уязвимостей на страницу