Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3996-4m5r-mmwf

10 месяцев назад

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3995-cwrc-82pq

10 месяцев назад

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-3993-w4q6-qwmf

почти 4 года назад

Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-3993-q22g-mw33

больше 3 лет назад

A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3993-mq32-jgqq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.

EPSS: Низкий
github логотип

GHSA-3993-5r92-h3rg

около 2 лет назад

An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows attacker to cause out-of-bounds read and write.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3992-5mfp-43q5

больше 2 лет назад

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-398x-qm59-5hfg

почти 4 года назад

Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398x-j3p9-ffhp

около 1 года назад

Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-398w-ffjm-vc8f

почти 4 года назад

websitebaker prior to and including 2.8.1 has an authentication error in backup module.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398w-8vvx-7rh5

больше 3 лет назад

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398v-cx4g-hhxc

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: Fix memory leak Fix leaking buffer allocated to send MSFT_OP_LE_MONITOR_ADVERTISEMENT.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-398v-9vhq-3gg5

больше 3 лет назад

Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via network access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398v-9qw7-49xj

почти 4 года назад

SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.

EPSS: Низкий
github логотип

GHSA-398v-5g69-w972

больше 3 лет назад

IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-398r-g5cv-mwh7

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering.This issue affects Satos Mobile: before 20230607.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-398r-735q-g9wg

около 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nasirahmed Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms.This issue affects Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms: from n/a through 1.75.0.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-398r-4xmm-8gch

почти 4 года назад

WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."

EPSS: Низкий
github логотип

GHSA-398q-xwvh-4mpj

около 1 года назад

In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-398q-w43p-26hx

больше 2 лет назад

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3996-4m5r-mmwf

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function.

CVSS3: 7.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-3995-cwrc-82pq

IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVSS3: 3.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-3993-w4q6-qwmf

Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3993-q22g-mw33

A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3993-mq32-jgqq

Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3993-5r92-h3rg

An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows attacker to cause out-of-bounds read and write.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3992-5mfp-43q5

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-398x-qm59-5hfg

Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-398x-j3p9-ffhp

Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-398w-ffjm-vc8f

websitebaker prior to and including 2.8.1 has an authentication error in backup module.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-398w-8vvx-7rh5

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-398v-cx4g-hhxc

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: Fix memory leak Fix leaking buffer allocated to send MSFT_OP_LE_MONITOR_ADVERTISEMENT.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-398v-9vhq-3gg5

Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via network access.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-398v-9qw7-49xj

SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.

1%
Низкий
почти 4 года назад
github логотип
GHSA-398v-5g69-w972

IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-398r-g5cv-mwh7

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering.This issue affects Satos Mobile: before 20230607.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-398r-735q-g9wg

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nasirahmed Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms.This issue affects Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms: from n/a through 1.75.0.

CVSS3: 7.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-398r-4xmm-8gch

WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."

1%
Низкий
почти 4 года назад
github логотип
GHSA-398q-xwvh-4mpj

In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-398q-w43p-26hx

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter.

CVSS3: 9.8
19%
Средний
больше 2 лет назад

Уязвимостей на страницу