Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2gp8-fw4p-p6jj

больше 3 лет назад

index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gp7-jhh8-9gqw

больше 3 лет назад

The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality.

EPSS: Низкий
github логотип

GHSA-2gp6-x3qj-wq4m

почти 4 года назад

Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests.

EPSS: Высокий
github логотип

GHSA-2gp6-v2j8-wm92

почти 3 года назад

A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gp6-hhcq-r4r4

больше 3 лет назад

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34714, CVE-2022-35745, CVE-2022-35752, CVE-2022-35753, CVE-2022-35766, CVE-2022-35767, CVE-2022-35794.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2gp5-q39j-fmr2

около 3 лет назад

A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality of the file ip/syscmd.htm. The manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214592.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2gp5-8mpc-j48f

больше 3 лет назад

Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2, 11.1.1.6.1, and 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to Security.

EPSS: Низкий
github логотип

GHSA-2gp5-7cf4-978c

больше 3 лет назад

This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. This issue results from the use of hard-coded encryption key. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9652.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2gp4-84j2-ghj7

больше 3 лет назад

Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gp3-mqcp-8ch9

больше 3 лет назад

tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2gp3-6mvr-759r

больше 3 лет назад

Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname.

EPSS: Высокий
github логотип

GHSA-2gp3-6c9p-jp7w

больше 3 лет назад

Cross site scripting in code-server

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2gp2-rmvv-g4h5

8 месяцев назад

The WP Masonry & Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wmis' shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2gmw-j4qh-8xwv

почти 4 года назад

Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter, as demonstrated using content.php, a different vector than CVE-2007-4805.

EPSS: Низкий
github логотип

GHSA-2gmw-gg2v-3ffg

больше 3 лет назад

An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.

EPSS: Низкий
github логотип

GHSA-2gmw-4qv6-96c6

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in jobseekers/forgot.php in Diesel Job Site allow remote attackers to inject arbitrary web script or HTML via the (1) uname or (2) SEmail parameters.

EPSS: Низкий
github логотип

GHSA-2gmv-qx2q-7g63

почти 3 года назад

A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipulation of the argument redirect_url leads to open redirect. The attack may be launched remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is 63124c021ae24b68e56872530df26eb4268ad633. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227756.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2gmr-x2wc-4g5j

больше 3 лет назад

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gmr-vqp5-r9qg

20 дней назад

A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2gmr-g5v4-9cch

около 1 года назад

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Service. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. This product is not affiliated with the company Adobe.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gp8-fw4p-p6jj

index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gp7-jhh8-9gqw

The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gp6-x3qj-wq4m

Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests.

76%
Высокий
почти 4 года назад
github логотип
GHSA-2gp6-v2j8-wm92

A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2gp6-hhcq-r4r4

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34714, CVE-2022-35745, CVE-2022-35752, CVE-2022-35753, CVE-2022-35766, CVE-2022-35767, CVE-2022-35794.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gp5-q39j-fmr2

A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality of the file ip/syscmd.htm. The manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214592.

CVSS3: 8.8
10%
Средний
около 3 лет назад
github логотип
GHSA-2gp5-8mpc-j48f

Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2, 11.1.1.6.1, and 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to Security.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gp5-7cf4-978c

This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. This issue results from the use of hard-coded encryption key. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9652.

CVSS3: 8.8
29%
Средний
больше 3 лет назад
github логотип
GHSA-2gp4-84j2-ghj7

Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gp3-mqcp-8ch9

tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gp3-6mvr-759r

Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname.

70%
Высокий
больше 3 лет назад
github логотип
GHSA-2gp3-6c9p-jp7w

Cross site scripting in code-server

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gp2-rmvv-g4h5

The WP Masonry & Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wmis' shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-2gmw-j4qh-8xwv

Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter, as demonstrated using content.php, a different vector than CVE-2007-4805.

7%
Низкий
почти 4 года назад
github логотип
GHSA-2gmw-gg2v-3ffg

An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmw-4qv6-96c6

Multiple cross-site scripting (XSS) vulnerabilities in jobseekers/forgot.php in Diesel Job Site allow remote attackers to inject arbitrary web script or HTML via the (1) uname or (2) SEmail parameters.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gmv-qx2q-7g63

A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipulation of the argument redirect_url leads to open redirect. The attack may be launched remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is 63124c021ae24b68e56872530df26eb4268ad633. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227756.

CVSS3: 3.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2gmr-x2wc-4g5j

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmr-vqp5-r9qg

A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.

CVSS3: 6.3
0%
Низкий
20 дней назад
github логотип
GHSA-2gmr-g5v4-9cch

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Service. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. This product is not affiliated with the company Adobe.

CVSS3: 7.8
0%
Низкий
около 1 года назад

Уязвимостей на страницу