Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2rj9-5j2p-fq98

больше 2 лет назад

A vulnerability was found in YFCMF up to 3.0.4. It has been declared as problematic. This vulnerability affects unknown code of the file index.php. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-230542 is the identifier assigned to this vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rj6-jjxr-v6wr

больше 3 лет назад

NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate the fields of the boot image, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.

EPSS: Низкий
github логотип

GHSA-2rj5-gh6q-72fp

3 месяца назад

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

CVSS3: 10
EPSS: Средний
github логотип

GHSA-2rj5-2chg-7g5m

больше 3 лет назад

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32838767. References: B-RB#107459.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rj4-3r7h-xp98

почти 4 года назад

Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows remote attackers to execute arbitrary code via a long GET request.

EPSS: Высокий
github логотип

GHSA-2rj3-rg6r-7hhr

около 2 месяцев назад

The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rj3-qghx-m6qc

больше 3 лет назад

Out-of-bounds read in kernel mode driver for some Intel(R) Wireless Bluetooth(R) products on Windows* 10, may allow a privileged user to potentially enable information disclosure via local access.

EPSS: Низкий
github логотип

GHSA-2rj3-6v2f-79ff

почти 4 года назад

Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) the w parameter to mod.php, (3) the e parameter to login.php, (4) the o parameter to login.php, and possibly other scripts.

EPSS: Низкий
github логотип

GHSA-2rj3-5w4f-4xjj

6 месяцев назад

ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2rj3-2h3h-5h64

больше 1 года назад

An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2rhx-qhxp-5jpw

больше 1 года назад

Submariner Operator sets unnecessary RBAC permissions

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2rhx-8hc8-f268

больше 3 лет назад

profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."

EPSS: Низкий
github логотип

GHSA-2rhx-838f-x5jw

больше 1 года назад

Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2rhw-5pj3-hhx2

больше 3 лет назад

SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2rhv-qrh4-ppvg

больше 3 лет назад

Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-1730.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2rhr-9v3p-vv9j

почти 2 года назад

This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local administrative privileges could exploit this to obtain the password of AppSamvid on the targeted system. Successful exploitation of this vulnerability could allow the attacker to take complete control of the application on the targeted system.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2rhr-5rr8-pf6q

больше 3 лет назад

An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. An attacker with physical access to the UART interface could access additional diagnostic and configuration functionalities as well as the camera's bootloader. Successful exploitation could compromise confidentiality, integrity, and availability of the affected system. It could even render the device inoperable.

EPSS: Низкий
github логотип

GHSA-2rhr-29cm-5chf

почти 2 года назад

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rhq-96q8-4vjq

7 месяцев назад

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rhp-j953-ghxr

11 месяцев назад

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via Iframe OVE-20230524-0012.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rj9-5j2p-fq98

A vulnerability was found in YFCMF up to 3.0.4. It has been declared as problematic. This vulnerability affects unknown code of the file index.php. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-230542 is the identifier assigned to this vulnerability.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rj6-jjxr-v6wr

NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate the fields of the boot image, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rj5-gh6q-72fp

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.  Affected Products: UniFi Access Application (Version 3.3.22 through 3.4.31). Mitigation: Update your UniFi Access Application to Version 4.0.21 or later.

CVSS3: 10
11%
Средний
3 месяца назад
github логотип
GHSA-2rj5-2chg-7g5m

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32838767. References: B-RB#107459.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rj4-3r7h-xp98

Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows remote attackers to execute arbitrary code via a long GET request.

80%
Высокий
почти 4 года назад
github логотип
GHSA-2rj3-rg6r-7hhr

The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2rj3-qghx-m6qc

Out-of-bounds read in kernel mode driver for some Intel(R) Wireless Bluetooth(R) products on Windows* 10, may allow a privileged user to potentially enable information disclosure via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rj3-6v2f-79ff

Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) the w parameter to mod.php, (3) the e parameter to login.php, (4) the o parameter to login.php, and possibly other scripts.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2rj3-5w4f-4xjj

ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

CVSS3: 6.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-2rj3-2h3h-5h64

An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rhx-qhxp-5jpw

Submariner Operator sets unnecessary RBAC permissions

CVSS3: 6.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rhx-8hc8-f268

profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhx-838f-x5jw

Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.

CVSS3: 5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rhw-5pj3-hhx2

SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php. NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhv-qrh4-ppvg

Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-1730.

CVSS3: 6.5
18%
Средний
больше 3 лет назад
github логотип
GHSA-2rhr-9v3p-vv9j

This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local administrative privileges could exploit this to obtain the password of AppSamvid on the targeted system. Successful exploitation of this vulnerability could allow the attacker to take complete control of the application on the targeted system.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2rhr-5rr8-pf6q

An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. An attacker with physical access to the UART interface could access additional diagnostic and configuration functionalities as well as the camera's bootloader. Successful exploitation could compromise confidentiality, integrity, and availability of the affected system. It could even render the device inoperable.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rhr-29cm-5chf

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2rhq-96q8-4vjq

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2rhp-j953-ghxr

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via Iframe OVE-20230524-0012.

CVSS3: 9.8
0%
Низкий
11 месяцев назад

Уязвимостей на страницу