Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 405

Количество 300 405

github логотип

GHSA-22qf-w2wm-5686

больше 3 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the encryption of firmware update images. The issue results from the use of an inappropriate encryption algorithm. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9649.

EPSS: Низкий
github логотип

GHSA-22qf-62f9-pj62

больше 1 года назад

As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22q9-m8j5-x7xg

около 1 года назад

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22q9-hqm5-mhmc

около 5 лет назад

Cross-Site Scripting in swagger-ui

EPSS: Низкий
github логотип

GHSA-22q9-7cmf-jjxp

больше 3 лет назад

The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.

EPSS: Низкий
github логотип

GHSA-22q8-rwx9-62gg

больше 1 года назад

A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-22q8-ghmq-63vf

больше 1 года назад

libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-22q7-qw7f-w974

больше 3 лет назад

Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.

EPSS: Низкий
github логотип

GHSA-22q7-cg4r-p9mx

больше 1 года назад

TYPO3 Cross-Site Scripting in Fluid ViewHelpers

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22q6-wwq7-2jj9

больше 3 лет назад

OpenStack Keystone Improper Authentication vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22q6-rw64-5gjj

больше 2 лет назад

Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-22q6-hvj2-jgmw

больше 3 лет назад

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-22q6-9rvj-cmpf

больше 3 лет назад

Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".

EPSS: Низкий
github логотип

GHSA-22q6-7m3g-6r77

около 1 года назад

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-22q5-qg84-2p5f

больше 3 лет назад

Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.

EPSS: Низкий
github логотип

GHSA-22q5-9phm-744v

8 месяцев назад

XWiki allows unregistered users to access private pages information through REST endpoint

EPSS: Низкий
github логотип

GHSA-22q5-57p4-rxcv

больше 3 лет назад

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22q4-f5r6-3xqw

больше 1 года назад

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

CVSS3: 7.3
EPSS: Критический
github логотип

GHSA-22q4-5758-44qv

больше 3 лет назад

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.

EPSS: Низкий
github логотип

GHSA-22q3-mmfp-g262

больше 3 лет назад

Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22qf-w2wm-5686

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the encryption of firmware update images. The issue results from the use of an inappropriate encryption algorithm. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9649.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22qf-62f9-pj62

As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-22q9-m8j5-x7xg

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-22q9-hqm5-mhmc

Cross-Site Scripting in swagger-ui

около 5 лет назад
github логотип
GHSA-22q9-7cmf-jjxp

The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-22q8-rwx9-62gg

A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-22q8-ghmq-63vf

libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2

CVSS3: 8.6
больше 1 года назад
github логотип
GHSA-22q7-qw7f-w974

Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q7-cg4r-p9mx

TYPO3 Cross-Site Scripting in Fluid ViewHelpers

CVSS3: 6.1
больше 1 года назад
github логотип
GHSA-22q6-wwq7-2jj9

OpenStack Keystone Improper Authentication vulnerability

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22q6-rw64-5gjj

Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.

CVSS3: 4.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22q6-hvj2-jgmw

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q6-9rvj-cmpf

Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q6-7m3g-6r77

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVSS3: 9.1
8%
Низкий
около 1 года назад
github логотип
GHSA-22q5-qg84-2p5f

Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q5-9phm-744v

XWiki allows unregistered users to access private pages information through REST endpoint

0%
Низкий
8 месяцев назад
github логотип
GHSA-22q5-57p4-rxcv

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q4-f5r6-3xqw

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

CVSS3: 7.3
93%
Критический
больше 1 года назад
github логотип
GHSA-22q4-5758-44qv

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22q3-mmfp-g262

Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу