Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-2fw3-wc2h-wv2q

почти 4 года назад

PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.

EPSS: Высокий
github логотип

GHSA-2fw3-jw4x-3m5f

почти 4 года назад

Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.

EPSS: Средний
github логотип

GHSA-2fw2-jxh6-36cg

около 3 лет назад

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fw2-hj8q-m4ff

больше 3 лет назад

Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.

EPSS: Низкий
github логотип

GHSA-2fvx-vhr6-r4cv

около 4 лет назад

Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side attacks.

EPSS: Низкий
github логотип

GHSA-2fvx-fjcj-g5x8

больше 3 лет назад

An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33547247.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2fvx-54hx-6r34

почти 2 года назад

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263311. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2fvx-46rg-mf9q

около 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-2fvw-qmcc-8m37

12 месяцев назад

An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without proper hardware programming, leading to a potential denial-of-service with privileged access.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2fvw-ppfc-cm77

больше 2 лет назад

In JetBrains Ktor before 2.3.5 server certificates were not verified

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2fvw-mmpv-h962

больше 3 лет назад

The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2fvw-6h8p-qwr7

больше 3 лет назад

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

CVSS3: 6.1
EPSS: Высокий
github логотип

GHSA-2fvw-3vhp-2m2r

почти 4 года назад

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg.

EPSS: Низкий
github логотип

GHSA-2fvv-qxrq-7jq6

больше 3 лет назад

apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page

EPSS: Низкий
github логотип

GHSA-2fvq-w5h5-q4v5

больше 3 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2fvq-gwm3-84c2

больше 3 лет назад

In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fvq-8pc8-8468

больше 2 лет назад

MiniTool Movie Maker 6.1.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2fvp-h46w-x58c

больше 3 лет назад

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fvp-7f4c-65qh

больше 3 лет назад

A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2fvm-j35v-vj7q

почти 4 года назад

Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inject arbitrary PHP code into a certain file in regged/ via the username parameter in a Register action, possibly related to the register function in forumfunctions.php.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fw3-wc2h-wv2q

PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.

72%
Высокий
почти 4 года назад
github логотип
GHSA-2fw3-jw4x-3m5f

Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.

55%
Средний
почти 4 года назад
github логотип
GHSA-2fw2-jxh6-36cg

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2fw2-hj8q-m4ff

Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvx-vhr6-r4cv

Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side attacks.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2fvx-fjcj-g5x8

An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33547247.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvx-54hx-6r34

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263311. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2fvx-46rg-mf9q

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

около 2 лет назад
github логотип
GHSA-2fvw-qmcc-8m37

An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without proper hardware programming, leading to a potential denial-of-service with privileged access.

CVSS3: 7.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-2fvw-ppfc-cm77

In JetBrains Ktor before 2.3.5 server certificates were not verified

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fvw-mmpv-h962

The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvw-6h8p-qwr7

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

CVSS3: 6.1
74%
Высокий
больше 3 лет назад
github логотип
GHSA-2fvw-3vhp-2m2r

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2fvv-qxrq-7jq6

apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page

больше 3 лет назад
github логотип
GHSA-2fvq-w5h5-q4v5

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvq-gwm3-84c2

In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvq-8pc8-8468

MiniTool Movie Maker 6.1.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

CVSS3: 8.1
3%
Низкий
больше 2 лет назад
github логотип
GHSA-2fvp-h46w-x58c

An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvp-7f4c-65qh

A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fvm-j35v-vj7q

Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inject arbitrary PHP code into a certain file in regged/ via the username parameter in a Register action, possibly related to the register function in forumfunctions.php.

10%
Средний
почти 4 года назад

Уязвимостей на страницу