Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 024

Количество 301 024

github логотип

GHSA-26hh-jgf5-3gmg

больше 3 лет назад

Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-26hg-qjgg-2868

больше 3 лет назад

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.

EPSS: Низкий
github логотип

GHSA-26hg-crh6-mjrw

больше 4 лет назад

Directory Traversal

EPSS: Низкий
github логотип

GHSA-26hg-8v7r-7fj4

больше 3 лет назад

Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login method, an attacker can monitor the device network to intercept network packets to attack the device. So it is recommended that the user disable this login method.

EPSS: Низкий
github логотип

GHSA-26hc-78hm-m2x7

3 месяца назад

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-26h9-w3fm-wprg

6 месяцев назад

A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.  The attacker must have network access to the Broker VM to exploit this issue.

EPSS: Низкий
github логотип

GHSA-26h8-5m63-2p8j

больше 3 лет назад

Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.

EPSS: Низкий
github логотип

GHSA-26h8-43q7-4r2w

больше 3 лет назад

lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.

EPSS: Низкий
github логотип

GHSA-26h7-5j9f-3jj7

около 3 лет назад

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26h6-6mgm-v632

больше 3 лет назад

When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono() function in lib/wav.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26h6-63w6-777w

больше 3 лет назад

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26h5-qgg3-p324

больше 3 лет назад

WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26h2-xpj3-3r9v

10 месяцев назад

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-26h2-jmcv-j5g4

больше 3 лет назад

In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Out of Bounds Write vulnerability because of not validating input values from IOCtl 0x83000058, a related issue to CVE-2017-17112.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26h2-7ff9-7pj5

больше 3 лет назад

CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlier is prone to a stack-based buffer overflow, which allows a remote attacker to achieve code execution or denial of service by sending a crafted payload to the listening server.

EPSS: Низкий
github логотип

GHSA-26gw-crpw-vhg7

больше 3 лет назад

The Aptallik Testi (aka com.wAptallikTesti) application 4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-26gw-4gmp-qgf3

больше 3 лет назад

In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-26gv-x98q-gqcw

около 2 месяцев назад

A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the component HTTP Header Handler. The manipulation of the argument Host results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26gv-chv5-g7q6

9 месяцев назад

An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26gr-cvq3-qxgf

больше 4 лет назад

Improper Authentication in Apache Shiro

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26hh-jgf5-3gmg

Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high privileges.

CVSS3: 6.7
2%
Низкий
больше 3 лет назад
github логотип
GHSA-26hg-qjgg-2868

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26hg-crh6-mjrw

Directory Traversal

больше 4 лет назад
github логотип
GHSA-26hg-8v7r-7fj4

Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login method, an attacker can monitor the device network to intercept network packets to attack the device. So it is recommended that the user disable this login method.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26hc-78hm-m2x7

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

CVSS3: 9
0%
Низкий
3 месяца назад
github логотип
GHSA-26h9-w3fm-wprg

A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM.  The attacker must have network access to the Broker VM to exploit this issue.

0%
Низкий
6 месяцев назад
github логотип
GHSA-26h8-5m63-2p8j

Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-26h8-43q7-4r2w

lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-26h7-5j9f-3jj7

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-26h6-6mgm-v632

When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono() function in lib/wav.c.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26h6-63w6-777w

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26h5-qgg3-p324

WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-26h2-xpj3-3r9v

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-26h2-jmcv-j5g4

In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Out of Bounds Write vulnerability because of not validating input values from IOCtl 0x83000058, a related issue to CVE-2017-17112.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26h2-7ff9-7pj5

CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlier is prone to a stack-based buffer overflow, which allows a remote attacker to achieve code execution or denial of service by sending a crafted payload to the listening server.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-26gw-crpw-vhg7

The Aptallik Testi (aka com.wAptallikTesti) application 4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26gw-4gmp-qgf3

In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26gv-x98q-gqcw

A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the component HTTP Header Handler. The manipulation of the argument Host results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-26gv-chv5-g7q6

An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-26gr-cvq3-qxgf

Improper Authentication in Apache Shiro

CVSS3: 9.8
86%
Высокий
больше 4 лет назад

Уязвимостей на страницу