Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2qxv-q349-j3hw

больше 3 лет назад

SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2qxv-pr9r-9797

больше 1 года назад

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2qxv-mghj-hfhr

почти 4 года назад

The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.

EPSS: Низкий
github логотип

GHSA-2qxr-q4ff-f53j

около 1 года назад

The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qxr-pm64-6wjg

почти 4 года назад

Unknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.

EPSS: Низкий
github логотип

GHSA-2qxr-7mvv-54x4

больше 1 года назад

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2qxr-5pf2-3p3h

почти 4 года назад

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 217369.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qxq-774f-5m45

больше 3 лет назад

Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.

EPSS: Низкий
github логотип

GHSA-2qxp-xmx6-cq4f

почти 3 года назад

Cross-Site Request Forgery (CSRF) in wallabag/wallabag

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qxp-f77x-jpcf

11 месяцев назад

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2qxm-j67j-mv87

11 месяцев назад

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument name/path leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2qxm-84pw-9jpr

больше 3 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2015-0472.

EPSS: Низкий
github логотип

GHSA-2qxj-9jmr-f734

около 4 лет назад

SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.

EPSS: Средний
github логотип

GHSA-2qxj-6c76-45f9

больше 3 лет назад

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the request admin-tech command in the CLI of the affected software. An attacker could exploit this vulnerability by modifying the request admin-tech command in the CLI of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the underlying operating system of an affected device and escalate their privileges to the root user. This vulnerability affects the following Cisco products if they are running a release of the Cisco SD-WAN Solution prior to Release 18.3.0: vBond Orchestrator Software, vEdge 100 Series Routers, vEdge 1000 Series Routers, vEdge 2000 Series Routers, vEdge 5000 Series Routers, vEdge Cloud Router Platform, vManage Network Management Software, vSmart Controller Software. Cisco Bug IDs: CSCvi6...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qxh-pcmm-764x

около 2 лет назад

Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2qxh-3hg7-46j4

больше 3 лет назад

The Dreamland Super Theme GO Gold (aka com.gau.go.launcherex.viptheme.dreamland.gold) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2qxf-2q6r-ff67

5 месяцев назад

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2qxc-rxrw-rpvh

больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue involves the replacement of the "XML DSig Transform or C14N algorithm implementations."

EPSS: Низкий
github логотип

GHSA-2qxc-rcjp-37j2

больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-2qxc-mf4x-wr29

5 месяцев назад

DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module

CVSS3: 9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2qxv-q349-j3hw

SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qxv-pr9r-9797

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qxv-mghj-hfhr

The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2qxr-q4ff-f53j

The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2qxr-pm64-6wjg

Unknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2qxr-7mvv-54x4

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.

CVSS3: 8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qxr-5pf2-3p3h

IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 217369.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2qxq-774f-5m45

Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qxp-xmx6-cq4f

Cross-Site Request Forgery (CSRF) in wallabag/wallabag

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2qxp-f77x-jpcf

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-2qxm-j67j-mv87

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument name/path leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2qxm-84pw-9jpr

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2015-0472.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qxj-9jmr-f734

SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.

11%
Средний
около 4 лет назад
github логотип
GHSA-2qxj-6c76-45f9

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the request admin-tech command in the CLI of the affected software. An attacker could exploit this vulnerability by modifying the request admin-tech command in the CLI of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the underlying operating system of an affected device and escalate their privileges to the root user. This vulnerability affects the following Cisco products if they are running a release of the Cisco SD-WAN Solution prior to Release 18.3.0: vBond Orchestrator Software, vEdge 100 Series Routers, vEdge 1000 Series Routers, vEdge 2000 Series Routers, vEdge 5000 Series Routers, vEdge Cloud Router Platform, vManage Network Management Software, vSmart Controller Software. Cisco Bug IDs: CSCvi6...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qxh-pcmm-764x

Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-2qxh-3hg7-46j4

The Dreamland Super Theme GO Gold (aka com.gau.go.launcherex.viptheme.dreamland.gold) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qxf-2q6r-ff67

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2qxc-rxrw-rpvh

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue involves the replacement of the "XML DSig Transform or C14N algorithm implementations."

7%
Низкий
больше 3 лет назад
github логотип
GHSA-2qxc-rcjp-37j2

** UNSUPPORTED WHEN ASSIGNED ** D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.5
92%
Критический
больше 3 лет назад
github логотип
GHSA-2qxc-mf4x-wr29

DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module

CVSS3: 9
0%
Низкий
5 месяцев назад

Уязвимостей на страницу