Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-33ff-q632-5gfm

больше 3 лет назад

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

EPSS: Средний
github логотип

GHSA-33ff-c2wp-wfmh

около 3 лет назад

Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33f9-j839-rf8h

больше 4 лет назад

Prototype Pollution in immer

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33f9-8mmr-x938

больше 3 лет назад

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33f9-622r-p353

больше 3 лет назад

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-33f9-4h6q-m86q

больше 3 лет назад

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-33f8-vpx6-6229

больше 3 лет назад

Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128.

EPSS: Низкий
github логотип

GHSA-33f8-qg6q-959p

почти 4 года назад

SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.

EPSS: Низкий
github логотип

GHSA-33f7-633w-3fph

5 месяцев назад

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-33f5-5f45-vcqg

больше 3 лет назад

Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33f4-xj2w-x86q

11 месяцев назад

A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper authorization. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-33f4-mjch-7fpr

4 месяца назад

Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

EPSS: Низкий
github логотип

GHSA-33f4-9prw-vfp6

больше 3 лет назад

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33f4-9hr4-253g

больше 3 лет назад

A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An attacker could exploit this vulnerability by sending properly formatted data values to the statistics collection service of an affected device. A successful exploit could allow the attacker to cause the web interface statistics view to present invalid data to users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33f3-88p6-j3f9

около 2 лет назад

TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33f2-v5w3-mmvw

9 месяцев назад

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-33f2-r445-jvq6

больше 3 лет назад

Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file following after call_mmap() returns an error. However, the aufs patchs change mmap_region() to replace the fput() using a local variable with vma_fput(), which will fput() vm_file, leading to a refcount underflow.

EPSS: Низкий
github логотип

GHSA-33f2-chfr-x425

больше 3 лет назад

Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.

EPSS: Низкий
github логотип

GHSA-33f2-544v-wh7x

почти 4 года назад

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33cx-2vvq-mf52

9 месяцев назад

Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33ff-q632-5gfm

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

24%
Средний
больше 3 лет назад
github логотип
GHSA-33ff-c2wp-wfmh

Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-33f9-j839-rf8h

Prototype Pollution in immer

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-33f9-8mmr-x938

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVSS3: 6.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-33f9-622r-p353

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33f9-4h6q-m86q

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.

CVSS3: 7.2
3%
Низкий
больше 3 лет назад
github логотип
GHSA-33f8-vpx6-6229

Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33f8-qg6q-959p

SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.

6%
Низкий
почти 4 года назад
github логотип
GHSA-33f7-633w-3fph

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-33f5-5f45-vcqg

Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.

CVSS3: 7.5
7%
Низкий
больше 3 лет назад
github логотип
GHSA-33f4-xj2w-x86q

A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper authorization. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-33f4-mjch-7fpr

Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

0%
Низкий
4 месяца назад
github логотип
GHSA-33f4-9prw-vfp6

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33f4-9hr4-253g

A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An attacker could exploit this vulnerability by sending properly formatted data values to the statistics collection service of an affected device. A successful exploit could allow the attacker to cause the web interface statistics view to present invalid data to users.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33f3-88p6-j3f9

TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-33f2-v5w3-mmvw

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-33f2-r445-jvq6

Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file following after call_mmap() returns an error. However, the aufs patchs change mmap_region() to replace the fput() using a local variable with vma_fput(), which will fput() vm_file, leading to a refcount underflow.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33f2-chfr-x425

Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-33f2-544v-wh7x

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-33cx-2vvq-mf52

Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.

0%
Низкий
9 месяцев назад

Уязвимостей на страницу