Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2hxq-j7vv-gr4m

почти 4 года назад

There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hxq-hqp9-w42p

около 4 лет назад

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.

EPSS: Низкий
github логотип

GHSA-2hxh-f4xp-4wcj

около 1 года назад

Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hxg-rh2v-hj3h

больше 3 лет назад

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to DocumentsProvider with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157320716

EPSS: Низкий
github логотип

GHSA-2hxg-84pv-j2pg

8 месяцев назад

A vulnerability was found in FLIR AX8 up to 1.46. It has been declared as critical. This vulnerability affects unknown code of the file /upload.php. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2hxf-vvc6-4wwp

больше 3 лет назад

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2hxf-jmpm-jxjc

больше 1 года назад

Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2hxf-gmcq-wh7p

почти 4 года назад

Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.

EPSS: Низкий
github логотип

GHSA-2hxf-5ppp-g398

3 месяца назад

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context of the victim's browser. The session cookie cannot be accessed, but a number of other operations could be performed. The vulnerability is present in the admin-search.php file and can be exploited via the compact parameter.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2hxc-x8ph-68p8

почти 4 года назад

Unspecified vulnerability in the domain alias management in Virtual Hosting Control System (VHCS) 2.4.6.2, related to "creating and deleting forwards for domain aliases," allows users to hijack the forwardings of other users.

EPSS: Низкий
github логотип

GHSA-2hxc-g3vg-5jpj

больше 3 лет назад

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hxc-85rf-9fw9

9 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress allows Cross Site Request Forgery. This issue affects WP Compress: from n/a through 6.30.30.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2hxc-7g8w-hjm5

больше 3 лет назад

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2hxc-5mh2-9rxg

больше 3 лет назад

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

EPSS: Низкий
github логотип

GHSA-2hx9-hxp6-qh98

почти 4 года назад

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_vertex() vh->shalfedges_begin().

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hx9-gcpq-rv3h

больше 3 лет назад

Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative Content-Length field.

EPSS: Средний
github логотип

GHSA-2hx9-6g7v-6xm4

больше 3 лет назад

cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hx8-w2c3-vxv7

почти 3 года назад

A vulnerability classified as problematic has been found in SourceCodester Online Student Management System 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument adminname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222984.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hx8-7322-mqv6

почти 4 года назад

Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.

EPSS: Низкий
github логотип

GHSA-2hx7-vxgc-r4p4

почти 4 года назад

The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hxq-j7vv-gr4m

There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2hxq-hqp9-w42p

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2hxh-f4xp-4wcj

Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2hxg-rh2v-hj3h

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to DocumentsProvider with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157320716

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hxg-84pv-j2pg

A vulnerability was found in FLIR AX8 up to 1.46. It has been declared as critical. This vulnerability affects unknown code of the file /upload.php. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2hxf-vvc6-4wwp

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hxf-jmpm-jxjc

Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hxf-gmcq-wh7p

Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hxf-5ppp-g398

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context of the victim's browser. The session cookie cannot be accessed, but a number of other operations could be performed. The vulnerability is present in the admin-search.php file and can be exploited via the compact parameter.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2hxc-x8ph-68p8

Unspecified vulnerability in the domain alias management in Virtual Hosting Control System (VHCS) 2.4.6.2, related to "creating and deleting forwards for domain aliases," allows users to hijack the forwardings of other users.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hxc-g3vg-5jpj

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.

CVSS3: 7.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-2hxc-85rf-9fw9

Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress allows Cross Site Request Forgery. This issue affects WP Compress: from n/a through 6.30.30.

CVSS3: 7.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-2hxc-7g8w-hjm5

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

CVSS3: 9.8
74%
Высокий
больше 3 лет назад
github логотип
GHSA-2hxc-5mh2-9rxg

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2hx9-hxp6-qh98

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_vertex() vh->shalfedges_begin().

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2hx9-gcpq-rv3h

Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative Content-Length field.

19%
Средний
больше 3 лет назад
github логотип
GHSA-2hx9-6g7v-6xm4

cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hx8-w2c3-vxv7

A vulnerability classified as problematic has been found in SourceCodester Online Student Management System 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument adminname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222984.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-2hx8-7322-mqv6

Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hx7-vxgc-r4p4

The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу