Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2vp3-8fjm-gfmm

больше 2 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion plugin <= 1.1.16 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2vp3-4m5j-qcxm

больше 3 лет назад

Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vp2-mmfj-gw73

около 1 года назад

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload files on the affected site's server which may make remote code execution possible and is confirmed to make Cross-Site Scripting possible.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2vp2-8m5j-4rjx

больше 3 лет назад

cnlh nps vulnerable to file overwrite by local user

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vp2-4cqw-xhcc

почти 2 года назад

Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2vmv-r5mh-gqqw

почти 4 года назад

The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the service socket that create (1) PreScript or (2) PostScript registry values under Veritas\VxSvc\CurrentVersion\Schedules specifying future command execution.

EPSS: Средний
github логотип

GHSA-2vmv-m3hj-2wh8

больше 2 лет назад

ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vmv-9g4h-j379

почти 4 года назад

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2vmr-8c82-x8xq

3 месяца назад

Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml files

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2vmp-q8v6-7qc9

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: net: fix stack overflow when LRO is disabled for virtual interfaces When the virtual interface's feature is updated, it synchronizes the updated feature for its own lower interface. This propagation logic should be worked as the iteration, not recursively. But it works recursively due to the netdev notification unexpectedly. This problem occurs when it disables LRO only for the team and bonding interface type. team0 | +------+------+-----+-----+ | | | | | team1 team2 team3 ... team200 If team0's LRO feature is updated, it generates the NETDEV_FEAT_CHANGE event to its own lower interfaces(team1 ~ team200). It is worked by netdev_sync_lower_features(). So, the NETDEV_FEAT_CHANGE notification logic of each lower interface work iteratively. But generated NETDEV_FEAT_CHANGE event is also sent to the upper interface too. upper interface(team0) generates the NETDEV_FEAT_CHANGE ...

EPSS: Низкий
github логотип

GHSA-2vmp-ffrr-x6p5

больше 3 лет назад

A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vmm-vm8r-59c6

больше 3 лет назад

The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.

EPSS: Высокий
github логотип

GHSA-2vmm-25vj-5925

почти 4 года назад

Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary web script or HTML via the Word parameter. NOTE: it is possible that this issue is resultant from SQL injection.

EPSS: Низкий
github логотип

GHSA-2vmj-9h29-92pm

около 1 года назад

The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vmh-83hf-jfxj

больше 3 лет назад

soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS file because of an invalid write near address 0 in an out-of-memory situation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vmg-wrjc-c333

больше 3 лет назад

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code with root privileges on the underlying Linux shell. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by first creating a malicious file on the affected device itself and then uploading a second malicious file to the device. A successful exploit could allow the attacker to execute arbitrary code with root privileges or bypass licensing requirements on the device.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2vmf-rc4q-xhgw

почти 4 года назад

Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vmf-372v-59rj

около 4 лет назад

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672038.

EPSS: Низкий
github логотип

GHSA-2vm9-v8wh-q7q8

больше 3 лет назад

ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for auto.mdb.

EPSS: Низкий
github логотип

GHSA-2vm9-j4w3-6329

почти 4 года назад

SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vp3-8fjm-gfmm

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion plugin <= 1.1.16 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vp3-4m5j-qcxm

Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vp2-mmfj-gw73

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload files on the affected site's server which may make remote code execution possible and is confirmed to make Cross-Site Scripting possible.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2vp2-8m5j-4rjx

cnlh nps vulnerable to file overwrite by local user

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vp2-4cqw-xhcc

Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.

CVSS3: 7.6
1%
Низкий
почти 2 года назад
github логотип
GHSA-2vmv-r5mh-gqqw

The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the service socket that create (1) PreScript or (2) PostScript registry values under Veritas\VxSvc\CurrentVersion\Schedules specifying future command execution.

13%
Средний
почти 4 года назад
github логотип
GHSA-2vmv-m3hj-2wh8

ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2vmv-9g4h-j379

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 6.7
1%
Низкий
почти 4 года назад
github логотип
GHSA-2vmr-8c82-x8xq

Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml files

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2vmp-q8v6-7qc9

In the Linux kernel, the following vulnerability has been resolved: net: fix stack overflow when LRO is disabled for virtual interfaces When the virtual interface's feature is updated, it synchronizes the updated feature for its own lower interface. This propagation logic should be worked as the iteration, not recursively. But it works recursively due to the netdev notification unexpectedly. This problem occurs when it disables LRO only for the team and bonding interface type. team0 | +------+------+-----+-----+ | | | | | team1 team2 team3 ... team200 If team0's LRO feature is updated, it generates the NETDEV_FEAT_CHANGE event to its own lower interfaces(team1 ~ team200). It is worked by netdev_sync_lower_features(). So, the NETDEV_FEAT_CHANGE notification logic of each lower interface work iteratively. But generated NETDEV_FEAT_CHANGE event is also sent to the upper interface too. upper interface(team0) generates the NETDEV_FEAT_CHANGE ...

0%
Низкий
около 1 месяца назад
github логотип
GHSA-2vmp-ffrr-x6p5

A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vmm-vm8r-59c6

The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.

84%
Высокий
больше 3 лет назад
github логотип
GHSA-2vmm-25vj-5925

Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary web script or HTML via the Word parameter. NOTE: it is possible that this issue is resultant from SQL injection.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2vmj-9h29-92pm

The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.

CVSS3: 9.8
2%
Низкий
около 1 года назад
github логотип
GHSA-2vmh-83hf-jfxj

soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS file because of an invalid write near address 0 in an out-of-memory situation.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vmg-wrjc-c333

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code with root privileges on the underlying Linux shell. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by first creating a malicious file on the affected device itself and then uploading a second malicious file to the device. A successful exploit could allow the attacker to execute arbitrary code with root privileges or bypass licensing requirements on the device.

CVSS3: 7.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2vmf-rc4q-xhgw

Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-2vmf-372v-59rj

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672038.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2vm9-v8wh-q7q8

ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for auto.mdb.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-2vm9-j4w3-6329

SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу