Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-26qx-4m49-6cfr

около 2 лет назад

wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26qv-p8cr-jxp5

8 месяцев назад

External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-26qv-cc62-952x

3 месяца назад

Missing Authorization vulnerability in d3wp WP Snow Effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through 1.1.15.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26qv-3573-wxg2

больше 1 года назад

A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272617 was assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-26qr-qf74-v2w4

почти 4 года назад

Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory.

EPSS: Низкий
github логотип

GHSA-26qr-hrpr-gcj8

8 дней назад

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-26qr-5f59-55qh

больше 3 лет назад

Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-26qq-h2w9-r3wv

больше 3 лет назад

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-26qq-9jw6-r5h4

больше 3 лет назад

Intesync Solismed 3.3sp has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-26qp-7xwg-8f45

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26qm-jcfr-w44c

больше 3 лет назад

Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."

EPSS: Средний
github логотип

GHSA-26qm-2594-mccv

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.

EPSS: Низкий
github логотип

GHSA-26qj-cr27-r5c4

больше 3 лет назад

Octopoller gem published with world-writable files

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-26qj-5g3c-qwm4

5 месяцев назад

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26qh-mgjw-5hg7

больше 3 лет назад

D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-26qg-wc7f-8867

больше 3 лет назад

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

CVSS3: 4.8
EPSS: Средний
github логотип

GHSA-26qg-4hpq-vwx9

больше 3 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26qf-c8f8-mrg9

около 3 лет назад

In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID: ALPS07203500.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-26qf-34q8-32jq

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php.

EPSS: Низкий
github логотип

GHSA-26qf-2r89-746r

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through 3.0.5.

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26qx-4m49-6cfr

wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-26qv-p8cr-jxp5

External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
31%
Средний
8 месяцев назад
github логотип
GHSA-26qv-cc62-952x

Missing Authorization vulnerability in d3wp WP Snow Effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through 1.1.15.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-26qv-3573-wxg2

A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272617 was assigned to this vulnerability.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-26qr-qf74-v2w4

Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26qr-hrpr-gcj8

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

CVSS3: 6.3
4%
Низкий
8 дней назад
github логотип
GHSA-26qr-5f59-55qh

Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26qq-h2w9-r3wv

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26qq-9jw6-r5h4

Intesync Solismed 3.3sp has Incorrect Access Control.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26qp-7xwg-8f45

Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26qm-jcfr-w44c

Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."

66%
Средний
больше 3 лет назад
github логотип
GHSA-26qm-2594-mccv

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26qj-cr27-r5c4

Octopoller gem published with world-writable files

CVSS3: 2.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26qj-5g3c-qwm4

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-26qh-mgjw-5hg7

D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.

CVSS3: 9.8
34%
Средний
больше 3 лет назад
github логотип
GHSA-26qg-wc7f-8867

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

CVSS3: 4.8
34%
Средний
больше 3 лет назад
github логотип
GHSA-26qg-4hpq-vwx9

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26qf-c8f8-mrg9

In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID: ALPS07203500.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-26qf-34q8-32jq

Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26qf-2r89-746r

Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through 3.0.5.

CVSS3: 10
1%
Низкий
больше 1 года назад

Уязвимостей на страницу