Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2jw5-w5pg-58h8

почти 4 года назад

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

EPSS: Средний
github логотип

GHSA-2jw4-8qc2-wm33

больше 1 года назад

File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2jw4-27vv-49jx

почти 2 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.0.27.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2jw2-w8hc-jqch

около 1 года назад

An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2jw2-fcpf-pj3x

больше 2 лет назад

When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2jw2-8v9p-h7mp

почти 4 года назад

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.

EPSS: Средний
github логотип

GHSA-2jw2-755p-5gqq

больше 3 лет назад

Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2jvx-x849-7gfm

7 месяцев назад

A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteList. The manipulation of the argument addHostFilter leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jvx-f9f6-89cv

больше 2 лет назад

Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jvx-947v-x43p

около 4 лет назад

Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2jvx-42cx-5ggp

больше 2 лет назад

Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jvx-3h5f-w2j7

около 2 лет назад

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jvw-hf8m-phpv

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.

EPSS: Низкий
github логотип

GHSA-2jvw-9p97-g4qj

больше 1 года назад

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2jvv-ppmq-fvgf

больше 3 лет назад

NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.

EPSS: Низкий
github логотип

GHSA-2jvq-qwww-m6j5

больше 3 лет назад

The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2jvq-3rhr-97x9

больше 3 лет назад

Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38660.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jvp-r7m9-xhpr

11 месяцев назад

An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2jvm-wg52-7h4f

больше 3 лет назад

ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2jvm-jgg9-h383

11 месяцев назад

Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jw5-w5pg-58h8

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

20%
Средний
почти 4 года назад
github логотип
GHSA-2jw4-8qc2-wm33

File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.

CVSS3: 9.8
30%
Средний
больше 1 года назад
github логотип
GHSA-2jw4-27vv-49jx

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.0.27.

CVSS3: 8.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2jw2-w8hc-jqch

An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.1
2%
Низкий
около 1 года назад
github логотип
GHSA-2jw2-fcpf-pj3x

When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jw2-8v9p-h7mp

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.

67%
Средний
почти 4 года назад
github логотип
GHSA-2jw2-755p-5gqq

Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

CVSS3: 7.5
29%
Средний
больше 3 лет назад
github логотип
GHSA-2jvx-x849-7gfm

A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteList. The manipulation of the argument addHostFilter leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-2jvx-f9f6-89cv

Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jvx-947v-x43p

Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jvx-42cx-5ggp

Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jvx-3h5f-w2j7

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2jvw-hf8m-phpv

In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2jvw-9p97-g4qj

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jvv-ppmq-fvgf

NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jvq-qwww-m6j5

The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jvq-3rhr-97x9

Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38660.

CVSS3: 7.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-2jvp-r7m9-xhpr

An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.

CVSS3: 8.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-2jvm-wg52-7h4f

ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jvm-jgg9-h383

Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

0%
Низкий
11 месяцев назад

Уязвимостей на страницу