Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 915

Количество 300 915

github логотип

GHSA-25r5-69f6-hgcg

больше 3 лет назад

Skype for Business Information Disclosure Vulnerability.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-25r4-xgpc-p9hq

больше 3 лет назад

SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitrary SQL commands via the objID parameter to the default URI.

EPSS: Низкий
github логотип

GHSA-25r4-89vx-h95c

больше 2 лет назад

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25r4-295r-fvqm

больше 3 лет назад

A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.

EPSS: Низкий
github логотип

GHSA-25r3-fx4p-7qc5

больше 3 лет назад

Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.

EPSS: Низкий
github логотип

GHSA-25r3-9hc8-wv3w

больше 3 лет назад

An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-25r3-37cq-xj9m

больше 3 лет назад

A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vulnerability is due to insufficient buffer allocation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to exhaust available resources and cause a DoS condition on an affected AP, as well as a DoS condition for client traffic traversing the AP.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-25r2-v989-pqgp

почти 3 года назад

IBM OpenBMC OP910 and OP940 could allow a privileged user to cause a denial of service by uploading or deleting too many CA certificates in a short period of time. IBM X-Force ID: 2226337.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-25r2-cxj6-67v5

больше 3 лет назад

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.1.3 and 12.2.3 through 12.2.6 allows remote administrators to affect confidentiality and integrity via vectors related to AD Utilities, a different vulnerability than CVE-2016-5567.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25r2-9vcc-j43c

4 месяца назад

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the share_name parameter.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25r2-963f-gx8g

больше 3 лет назад

Azure RTOS GUIX Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30175, CVE-2022-30176, CVE-2022-34687, CVE-2022-35773, CVE-2022-35806.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25qx-vfw2-fw8r

около 1 года назад

Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-25qx-g7cf-9cwg

больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. Note: the vulnerability can be exploited when it is used in "interactive" mode while, cause of a max number characters limitation, it cannot be exploited in batch or command line usage (e.g. dsmadmc.exe -id=username -password=pwd). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-25qw-9qm7-q8v7

больше 3 лет назад

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-25qv-rf35-39r8

больше 3 лет назад

spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.

EPSS: Низкий
github логотип

GHSA-25qv-mpwh-3c2j

больше 3 лет назад

RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.

EPSS: Низкий
github логотип

GHSA-25qv-8m5r-8645

больше 3 лет назад

A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to check the bounds of input data. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25qr-xf4w-7m3j

около 2 месяцев назад

A vulnerability was determined in codesiddhant Jasmin Ransomware up to 1.0.1. This vulnerability affects unknown code of the file /handshake.php. This manipulation of the argument machine_name/computer_user/os/date/time/ip/location/systemid/password causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-25qr-x7j7-m2cj

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biancardi Mixcloud Embed allows Stored XSS. This issue affects Mixcloud Embed: from n/a through 2.2.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25qr-gjf9-whgm

больше 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25r5-69f6-hgcg

Skype for Business Information Disclosure Vulnerability.

CVSS3: 6.5
20%
Средний
больше 3 лет назад
github логотип
GHSA-25r4-xgpc-p9hq

SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitrary SQL commands via the objID parameter to the default URI.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25r4-89vx-h95c

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-25r4-295r-fvqm

A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25r3-fx4p-7qc5

Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-25r3-9hc8-wv3w

An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.

CVSS3: 5.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25r3-37cq-xj9m

A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vulnerability is due to insufficient buffer allocation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to exhaust available resources and cause a DoS condition on an affected AP, as well as a DoS condition for client traffic traversing the AP.

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25r2-v989-pqgp

IBM OpenBMC OP910 and OP940 could allow a privileged user to cause a denial of service by uploading or deleting too many CA certificates in a short period of time. IBM X-Force ID: 2226337.

CVSS3: 4.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-25r2-cxj6-67v5

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.1.3 and 12.2.3 through 12.2.6 allows remote administrators to affect confidentiality and integrity via vectors related to AD Utilities, a different vulnerability than CVE-2016-5567.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25r2-9vcc-j43c

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the share_name parameter.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-25r2-963f-gx8g

Azure RTOS GUIX Studio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30175, CVE-2022-30176, CVE-2022-34687, CVE-2022-35773, CVE-2022-35806.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25qx-vfw2-fw8r

Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking

CVSS3: 5.8
0%
Низкий
около 1 года назад
github логотип
GHSA-25qx-g7cf-9cwg

** UNSUPPORTED WHEN ASSIGNED ** The 'id' parameter of IBM Tivoli Storage Manager Version 5 Release 2 (Command Line Administrative Interface, dsmadmc.exe) is vulnerable to an exploitable stack buffer overflow. Note: the vulnerability can be exploited when it is used in "interactive" mode while, cause of a max number characters limitation, it cannot be exploited in batch or command line usage (e.g. dsmadmc.exe -id=username -password=pwd). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25qw-9qm7-q8v7

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'.

CVSS3: 7.8
20%
Средний
больше 3 лет назад
github логотип
GHSA-25qv-rf35-39r8

spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25qv-mpwh-3c2j

RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-25qv-8m5r-8645

A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to check the bounds of input data. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

CVSS3: 7.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-25qr-xf4w-7m3j

A vulnerability was determined in codesiddhant Jasmin Ransomware up to 1.0.1. This vulnerability affects unknown code of the file /handshake.php. This manipulation of the argument machine_name/computer_user/os/date/time/ip/location/systemid/password causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-25qr-x7j7-m2cj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biancardi Mixcloud Embed allows Stored XSS. This issue affects Mixcloud Embed: from n/a through 2.2.0.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-25qr-gjf9-whgm

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу