Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2cww-rcpx-vmvj

почти 2 года назад

TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2cww-m3rc-2vgr

около 3 лет назад

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2cww-fgmg-4jqc

больше 1 года назад

Keycloak's admin API allows low privilege users to use administrative functions

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-2cww-cxmg-44cc

почти 4 года назад

Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.

EPSS: Низкий
github логотип

GHSA-2cww-3vfj-9m4c

больше 2 лет назад

Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-2cwv-7h96-mp7x

больше 2 лет назад

A vulnerability was found in DedeBIZ 6.2 and classified as critical. This issue affects some unknown processing of the file /src/admin/makehtml_taglist_action.php. The manipulation of the argument mktime leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240881 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2cwr-wmx6-5wcx

почти 4 года назад

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly validate PowerPoint files, which allows remote attackers to execute arbitrary code via multiple crafted BuildList records that include ChartBuild containers, which triggers memory corruption, aka "Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-2cwr-cqcg-933x

почти 4 года назад

fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.

EPSS: Низкий
github логотип

GHSA-2cwr-c8cj-f6f4

11 месяцев назад

A vulnerability classified as critical has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This affects an unknown part of the file /password-recovery.php of the component Password Recovery Page. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2cwp-h6w6-7hmq

17 дней назад

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2cwp-9vcw-fc97

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gutentor Gutentor allows DOM-Based XSS.This issue affects Gutentor: from n/a through 3.4.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2cwp-85p5-6fwc

около 1 года назад

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2cwm-wr5w-g4f2

больше 3 лет назад

In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2cwm-q4rq-7594

больше 3 лет назад

A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL template action parameter.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-2cwm-q27v-2mv8

больше 3 лет назад

The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after a failed data copy, which allows local users to cause a denial of service (tcp_xmit_retransmit_queue use-after-free and system crash) via a crafted SACK option.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cwm-8g9v-gmr9

больше 3 лет назад

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.3), 8.0 before 8.0(5.24), 8.1 before 8.1(2.50), 8.2 before 8.2(5), 8.3 before 8.3(2.18), 8.4 before 8.4(1.10), and 8.5 before 8.5(1.1) and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7) allow remote attackers to bypass authentication via a crafted TACACS+ reply, aka Bug IDs CSCto40365 and CSCto74274.

EPSS: Низкий
github логотип

GHSA-2cwj-97vw-wc3w

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2cwj-8xwx-w45p

больше 3 лет назад

Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-2cwj-8chv-9pp9

около 5 лет назад

XML External Entity attack in log4net

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2cwj-7vfc-5vfh

около 1 года назад

Microsoft Office Remote Code Execution Vulnerability

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2cww-rcpx-vmvj

TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.

CVSS3: 2.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-2cww-m3rc-2vgr

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2cww-fgmg-4jqc

Keycloak's admin API allows low privilege users to use administrative functions

CVSS3: 8.1
89%
Высокий
больше 1 года назад
github логотип
GHSA-2cww-cxmg-44cc

Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2cww-3vfj-9m4c

Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.

CVSS3: 3.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2cwv-7h96-mp7x

A vulnerability was found in DedeBIZ 6.2 and classified as critical. This issue affects some unknown processing of the file /src/admin/makehtml_taglist_action.php. The manipulation of the argument mktime leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240881 was assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2cwr-wmx6-5wcx

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly validate PowerPoint files, which allows remote attackers to execute arbitrary code via multiple crafted BuildList records that include ChartBuild containers, which triggers memory corruption, aka "Memory Corruption Vulnerability."

52%
Средний
почти 4 года назад
github логотип
GHSA-2cwr-cqcg-933x

fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2cwr-c8cj-f6f4

A vulnerability classified as critical has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This affects an unknown part of the file /password-recovery.php of the component Password Recovery Page. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2cwp-h6w6-7hmq

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
0%
Низкий
17 дней назад
github логотип
GHSA-2cwp-9vcw-fc97

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gutentor Gutentor allows DOM-Based XSS.This issue affects Gutentor: from n/a through 3.4.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2cwp-85p5-6fwc

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2cwm-wr5w-g4f2

In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cwm-q4rq-7594

A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL template action parameter.

CVSS3: 6.1
19%
Средний
больше 3 лет назад
github логотип
GHSA-2cwm-q27v-2mv8

The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after a failed data copy, which allows local users to cause a denial of service (tcp_xmit_retransmit_queue use-after-free and system crash) via a crafted SACK option.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cwm-8g9v-gmr9

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.3), 8.0 before 8.0(5.24), 8.1 before 8.1(2.50), 8.2 before 8.2(5), 8.3 before 8.3(2.18), 8.4 before 8.4(1.10), and 8.5 before 8.5(1.1) and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7) allow remote attackers to bypass authentication via a crafted TACACS+ reply, aka Bug IDs CSCto40365 and CSCto74274.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cwj-97vw-wc3w

Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.

CVSS3: 8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cwj-8xwx-w45p

Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".

CVSS3: 7.8
32%
Средний
больше 3 лет назад
github логотип
GHSA-2cwj-8chv-9pp9

XML External Entity attack in log4net

CVSS3: 9.8
49%
Средний
около 5 лет назад
github логотип
GHSA-2cwj-7vfc-5vfh

Microsoft Office Remote Code Execution Vulnerability

CVSS3: 5.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу