Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-37j8-qv27-g3fq

больше 3 лет назад

An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.

EPSS: Низкий
github логотип

GHSA-37j7-fg3j-429f

4 месяца назад

Happy DOM: VM Context Escape can lead to Remote Code Execution

EPSS: Низкий
github логотип

GHSA-37j6-8hw4-3hcr

больше 1 года назад

Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22831.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-37j6-767f-6qq3

6 месяцев назад

Missing Authorization vulnerability in hashthemes Easy Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Easy Elementor Addons: from n/a through 2.2.7.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37j5-q5w5-77x4

больше 3 лет назад

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or possible escalation of privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-37j5-mq9x-m493

8 месяцев назад

An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.

EPSS: Низкий
github логотип

GHSA-37j5-fv6r-vwgr

почти 3 года назад

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37j4-mqr6-6m6x

10 месяцев назад

HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37j4-jj4f-rgwh

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358.

EPSS: Низкий
github логотип

GHSA-37j3-8x65-gx72

больше 3 лет назад

Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP getEnvironmentString request, related to the local variable cache.

EPSS: Средний
github логотип

GHSA-37j2-h4x2-rp3v

около 2 лет назад

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37j2-87p9-cj66

больше 3 лет назад

Vulnerability in the Oracle Integrated Lights Out Manager (ILOM) component of Oracle Sun Systems Products Suite (subcomponent: System Management). The supported version that is affected is Prior to 3.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Integrated Lights Out Manager (ILOM). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Integrated Lights Out Manager (ILOM) accessible data as well as unauthorized read access to a subset of Oracle Integrated Lights Out Manager (ILOM) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Integrated Lights Out Manager (ILOM). CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-37j2-4mf7-p7r4

больше 3 лет назад

Unspecified vulnerability on the La Fonera+ router with firmware before 1.7.0.1 allows remote attackers to cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-37hx-4mcq-wc3h

больше 4 лет назад

Weak Password Recovery Mechanism for Forgotten Password in Strapi

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-37hw-m3rc-6ww4

больше 3 лет назад

A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37hw-37wh-562h

больше 3 лет назад

In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37hv-5w7w-hhjw

почти 4 года назад

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-37hv-4cjv-mxqq

больше 3 лет назад

Windows Kernel Memory Information Disclosure Vulnerability

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-37hr-rhw9-q43g

почти 4 года назад

Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument.

EPSS: Низкий
github логотип

GHSA-37hr-r96j-6hcx

больше 2 лет назад

A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross site scripting. It is possible to launch the attack remotely. VDB-234426 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37j8-qv27-g3fq

An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-37j7-fg3j-429f

Happy DOM: VM Context Escape can lead to Remote Code Execution

0%
Низкий
4 месяца назад
github логотип
GHSA-37j6-8hw4-3hcr

Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22831.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-37j6-767f-6qq3

Missing Authorization vulnerability in hashthemes Easy Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Easy Elementor Addons: from n/a through 2.2.7.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-37j5-q5w5-77x4

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or possible escalation of privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-37j5-mq9x-m493

An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.

1%
Низкий
8 месяцев назад
github логотип
GHSA-37j5-fv6r-vwgr

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-37j4-mqr6-6m6x

HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-37j4-jj4f-rgwh

Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358.

0%
Низкий
почти 4 года назад
github логотип
GHSA-37j3-8x65-gx72

Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP getEnvironmentString request, related to the local variable cache.

11%
Средний
больше 3 лет назад
github логотип
GHSA-37j2-h4x2-rp3v

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-37j2-87p9-cj66

Vulnerability in the Oracle Integrated Lights Out Manager (ILOM) component of Oracle Sun Systems Products Suite (subcomponent: System Management). The supported version that is affected is Prior to 3.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Integrated Lights Out Manager (ILOM). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Integrated Lights Out Manager (ILOM) accessible data as well as unauthorized read access to a subset of Oracle Integrated Lights Out Manager (ILOM) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Integrated Lights Out Manager (ILOM). CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-37j2-4mf7-p7r4

Unspecified vulnerability on the La Fonera+ router with firmware before 1.7.0.1 allows remote attackers to cause a denial of service via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-37hx-4mcq-wc3h

Weak Password Recovery Mechanism for Forgotten Password in Strapi

CVSS3: 8.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-37hw-m3rc-6ww4

A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-37hw-37wh-562h

In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-37hv-5w7w-hhjw

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.

CVSS3: 6
0%
Низкий
почти 4 года назад
github логотип
GHSA-37hv-4cjv-mxqq

Windows Kernel Memory Information Disclosure Vulnerability

CVSS3: 6.3
3%
Низкий
больше 3 лет назад
github логотип
GHSA-37hr-rhw9-q43g

Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-37hr-r96j-6hcx

A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross site scripting. It is possible to launch the attack remotely. VDB-234426 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу