Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2xcr-gqqg-9mwf

больше 3 лет назад

The FTP server in Cisco Unified Computing System (UCS) has a hardcoded password for an unspecified user account, which makes it easier for remote attackers to read or modify files by leveraging knowledge of this password, aka Bug ID CSCtg20769.

EPSS: Низкий
github логотип

GHSA-2xcq-qj4r-f2xv

больше 3 лет назад

Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, backup.asp, sys-power.asp, ifaces-wls.asp, ifaces-wls-pkt.asp, and ifaces-wls-pkt-adv.asp.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2xcq-fmvr-mmpw

3 месяца назад

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2xcp-78pq-jqq3

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Check pat.ops before dumping PAT settings We may leave pat.ops unset when running on brand new platform or when running as a VF. While the former is unlikely, the latter is valid (future) use case and will cause NPD when someone will try to dump PAT settings by debugfs. It's better to check pointer to pat.ops instead of specific .dump hook, as we have this hook always defined for every .ops variant.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xcj-m3jp-cgj9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING. NOTE: this can be used to bypass the cross-site request forgery (CSRF) protection mechanism by setting the Referer.

EPSS: Низкий
github логотип

GHSA-2xcj-557c-hf8r

около 2 лет назад

Cross-site Scripting in evershop

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2xcj-24q6-g2ch

больше 3 лет назад

On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xch-p59c-qwvr

около 1 года назад

An issue in the exps_bind_column component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xch-p52g-f698

почти 2 года назад

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2xch-5969-phfh

10 месяцев назад

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2xch-4r76-8cgw

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: KEYS: prevent NULL pointer dereference in find_asymmetric_key() In find_asymmetric_key(), if all NULLs are passed in the id_{0,1,2} arguments, the kernel will first emit WARN but then have an oops because id_2 gets dereferenced anyway. Add the missing id_2 check and move WARN_ON() to the final else branch to avoid duplicate NULL checks. Found by Linux Verification Center (linuxtesting.org) with Svace static analysis tool.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xch-253x-wxp6

5 месяцев назад

In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.

EPSS: Низкий
github логотип

GHSA-2xcg-h5x6-gp8h

почти 2 года назад

D-Link DAP-2622 DDP Configuration Restore Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20069.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xcf-4mrc-5rrg

почти 4 года назад

ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.

EPSS: Низкий
github логотип

GHSA-2xcc-vm3f-m8rw

около 1 года назад

@lobehub/chat Server Side Request Forgery vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2xcc-5x48-fhp2

больше 3 лет назад

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetQosBand.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xcc-3vq7-mvjp

10 месяцев назад

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2xc9-w6jv-x92w

больше 3 лет назад

Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2xc7-wvf3-85p6

больше 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2xc7-724c-r36j

больше 3 лет назад

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy in H5T.c.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xcr-gqqg-9mwf

The FTP server in Cisco Unified Computing System (UCS) has a hardcoded password for an unspecified user account, which makes it easier for remote attackers to read or modify files by leveraging knowledge of this password, aka Bug ID CSCtg20769.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xcq-qj4r-f2xv

Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, backup.asp, sys-power.asp, ifaces-wls.asp, ifaces-wls-pkt.asp, and ifaces-wls-pkt-adv.asp.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xcq-fmvr-mmpw

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-2xcp-78pq-jqq3

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Check pat.ops before dumping PAT settings We may leave pat.ops unset when running on brand new platform or when running as a VF. While the former is unlikely, the latter is valid (future) use case and will cause NPD when someone will try to dump PAT settings by debugfs. It's better to check pointer to pat.ops instead of specific .dump hook, as we have this hook always defined for every .ops variant.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xcj-m3jp-cgj9

Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING. NOTE: this can be used to bypass the cross-site request forgery (CSRF) protection mechanism by setting the Referer.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xcj-557c-hf8r

Cross-site Scripting in evershop

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2xcj-24q6-g2ch

On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xch-p59c-qwvr

An issue in the exps_bind_column component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2xch-p52g-f698

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
почти 2 года назад
github логотип
GHSA-2xch-5969-phfh

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

CVSS3: 4.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-2xch-4r76-8cgw

In the Linux kernel, the following vulnerability has been resolved: KEYS: prevent NULL pointer dereference in find_asymmetric_key() In find_asymmetric_key(), if all NULLs are passed in the id_{0,1,2} arguments, the kernel will first emit WARN but then have an oops because id_2 gets dereferenced anyway. Add the missing id_2 check and move WARN_ON() to the final else branch to avoid duplicate NULL checks. Found by Linux Verification Center (linuxtesting.org) with Svace static analysis tool.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2xch-253x-wxp6

In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.

0%
Низкий
5 месяцев назад
github логотип
GHSA-2xcg-h5x6-gp8h

D-Link DAP-2622 DDP Configuration Restore Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20069.

CVSS3: 8.8
2%
Низкий
почти 2 года назад
github логотип
GHSA-2xcf-4mrc-5rrg

ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.

7%
Низкий
почти 4 года назад
github логотип
GHSA-2xcc-vm3f-m8rw

@lobehub/chat Server Side Request Forgery vulnerability

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2xcc-5x48-fhp2

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetQosBand.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xcc-3vq7-mvjp

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.

CVSS3: 5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2xc9-w6jv-x92w

Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.

CVSS3: 8.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xc7-wvf3-85p6

A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xc7-724c-r36j

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy in H5T.c.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу