Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 293 598

Количество 293 598

github логотип

GHSA-233g-c3hw-rh55

10 месяцев назад

In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-233f-69cg-rpgm

больше 3 лет назад

SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page.

EPSS: Низкий
github логотип

GHSA-2339-wm5r-x92c

больше 3 лет назад

SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.php. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

EPSS: Низкий
github логотип

GHSA-2339-f8x6-mhv4

больше 3 лет назад

nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2339-4jw5-35vw

больше 3 лет назад

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

EPSS: Низкий
github логотип

GHSA-2337-r63v-x38x

больше 3 лет назад

An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: Android Kernel. Android ID: A-35764875. References: QC-CR#2029798.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2337-9jrr-74j5

больше 3 лет назад

Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2334-74rr-746w

больше 3 лет назад

Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-2334-4qc6-g6xv

больше 3 лет назад

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not encrypt multicast traffic, which might allow remote attackers to read sensitive cluster synchronization messages by sniffing the multicast traffic.

EPSS: Низкий
github логотип

GHSA-2332-v8xq-hpvx

около 2 лет назад

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search [bypass SPL safeguards for risky commands](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards). The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2332-q5x7-f8c3

больше 3 лет назад

This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted image may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2332-hcww-wjmr

больше 3 лет назад

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.

EPSS: Низкий
github логотип

GHSA-232x-fx5w-m6mj

10 месяцев назад

Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cohesive Networks VNS3. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 8000 by default. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24176.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-232w-p9jf-7fx8

больше 3 лет назад

SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.

EPSS: Низкий
github логотип

GHSA-232w-9qhw-4pxx

около 3 лет назад

A vulnerability, which was classified as problematic, has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. This issue affects some unknown processing. The manipulation leads to backdoor. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-232w-33h3-9wp7

больше 3 лет назад

The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-232v-xqxf-3rrg

больше 2 лет назад

In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-228523213

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-232r-9jvp-5ffj

больше 3 лет назад

European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-232r-6v76-wgpq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-232r-66cg-79px

около 7 лет назад

Paramiko not properly checking authentication before processing other requests

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-233g-c3hw-rh55

In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 8.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-233f-69cg-rpgm

SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2339-wm5r-x92c

SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.php. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2339-f8x6-mhv4

nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2339-4jw5-35vw

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2337-r63v-x38x

An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: Android Kernel. Android ID: A-35764875. References: QC-CR#2029798.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2337-9jrr-74j5

Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.

CVSS3: 5.9
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2334-74rr-746w

Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2334-4qc6-g6xv

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not encrypt multicast traffic, which might allow remote attackers to read sensitive cluster synchronization messages by sniffing the multicast traffic.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2332-v8xq-hpvx

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search [bypass SPL safeguards for risky commands](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards). The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2332-q5x7-f8c3

This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted image may lead to arbitrary code execution.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2332-hcww-wjmr

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-232x-fx5w-m6mj

Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cohesive Networks VNS3. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 8000 by default. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24176.

CVSS3: 9.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-232w-p9jf-7fx8

SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-232w-9qhw-4pxx

A vulnerability, which was classified as problematic, has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. This issue affects some unknown processing. The manipulation leads to backdoor. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-232w-33h3-9wp7

The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-232v-xqxf-3rrg

In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-228523213

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-232r-9jvp-5ffj

European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-232r-6v76-wgpq

Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-232r-66cg-79px

Paramiko not properly checking authentication before processing other requests

CVSS3: 9.8
17%
Средний
около 7 лет назад

Уязвимостей на страницу