Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3j89-mpwx-chrr

почти 4 года назад

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3j89-mgwv-f23v

7 месяцев назад

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tiktok_user_id’ parameter in all versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3j89-cv92-pv3w

около 4 лет назад

A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c. This vulnerability can lead to a Denial of Service (DoS).

EPSS: Низкий
github логотип

GHSA-3j88-h584-rq62

больше 3 лет назад

A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through the SNMP protocol.

EPSS: Низкий
github логотип

GHSA-3j88-7hxg-wjh6

больше 3 лет назад

Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.

EPSS: Низкий
github логотип

GHSA-3j87-xcp2-3mgf

больше 1 года назад

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3j87-859p-q82m

11 месяцев назад

An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j87-7wxc-hh89

больше 3 лет назад

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4934, and CVE-2015-4935.

EPSS: Средний
github логотип

GHSA-3j85-rwqm-2894

почти 4 года назад

Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j85-fggf-7m9p

больше 3 лет назад

Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.

EPSS: Низкий
github логотип

GHSA-3j85-7c4g-4f56

около 1 года назад

Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3j85-7795-mc66

3 месяца назад

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the frontend code to gain administrator privileges on the website.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j85-6864-55p3

около 3 лет назад

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-3j84-x8jq-q9c2

больше 3 лет назад

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j84-rjwj-29h2

почти 3 года назад

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3j84-m7p6-xr37

больше 3 лет назад

Tarantella Enterprise before 3.11 allows bypassing Access Control.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3j84-jghj-gqwg

больше 3 лет назад

Istio before 1.8.6 and 1.9.x before 1.9.5, when a gateway is using the AUTO_PASSTHROUGH routing configuration, allows attackers to bypass authorization checks and access unexpected services in the cluster.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j83-vjvj-964q

9 месяцев назад

A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the component Sign In. The manipulation of the argument password2 leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3j83-v84m-h6f2

почти 4 года назад

Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.

EPSS: Низкий
github логотип

GHSA-3j83-m58c-vrr9

больше 3 лет назад

Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3j89-mpwx-chrr

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

CVSS3: 8.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-3j89-mgwv-f23v

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tiktok_user_id’ parameter in all versions up to, and including, 7.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 4.7
3%
Низкий
7 месяцев назад
github логотип
GHSA-3j89-cv92-pv3w

A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c. This vulnerability can lead to a Denial of Service (DoS).

0%
Низкий
около 4 лет назад
github логотип
GHSA-3j88-h584-rq62

A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through the SNMP protocol.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j88-7hxg-wjh6

Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j87-xcp2-3mgf

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-3j87-859p-q82m

An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3j87-7wxc-hh89

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4934, and CVE-2015-4935.

23%
Средний
больше 3 лет назад
github логотип
GHSA-3j85-rwqm-2894

Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3j85-fggf-7m9p

Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j85-7c4g-4f56

Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the set action rules function via unspecified vectors.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3j85-7795-mc66

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the frontend code to gain administrator privileges on the website.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-3j85-6864-55p3

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVSS3: 9.8
73%
Высокий
около 3 лет назад
github логотип
GHSA-3j84-x8jq-q9c2

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j84-rjwj-29h2

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number.

CVSS3: 5.6
0%
Низкий
почти 3 года назад
github логотип
GHSA-3j84-m7p6-xr37

Tarantella Enterprise before 3.11 allows bypassing Access Control.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j84-jghj-gqwg

Istio before 1.8.6 and 1.9.x before 1.9.5, when a gateway is using the AUTO_PASSTHROUGH routing configuration, allows attackers to bypass authorization checks and access unexpected services in the cluster.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j83-vjvj-964q

A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the component Sign In. The manipulation of the argument password2 leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3j83-v84m-h6f2

Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3j83-m58c-vrr9

Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу