Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-227x-w5qv-2294

почти 4 года назад

admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

EPSS: Низкий
github логотип

GHSA-227x-7mh8-3cf6

4 месяца назад

Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-227x-6m74-5g32

почти 3 года назад

Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-227x-48c5-2jpf

больше 3 лет назад

HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.

EPSS: Низкий
github логотип

GHSA-227w-xh58-rx2j

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.

EPSS: Низкий
github логотип

GHSA-227w-wv4j-67h4

почти 4 года назад

Class Loading Vulnerability in Artemis

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-227w-82c7-87qx

больше 3 лет назад

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS: Низкий
github логотип

GHSA-227v-w3r6-6vc4

больше 3 лет назад

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-227v-m6p6-j6gx

больше 2 лет назад

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-227r-w5j2-6243

11 месяцев назад

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-227r-vmhh-jq3x

около 2 месяцев назад

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.

EPSS: Низкий
github логотип

GHSA-227r-cc3q-mh85

больше 3 лет назад

Windows GDI+ Information Disclosure Vulnerability

CVSS3: 5.7
EPSS: Средний
github логотип

GHSA-227p-7qgj-96v9

больше 1 года назад

Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-227m-878m-h3qm

больше 1 года назад

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-227j-xj2v-7f5v

больше 3 лет назад

The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

EPSS: Низкий
github логотип

GHSA-227h-wvc4-w9jx

больше 3 лет назад

In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-227h-6jwp-327q

почти 2 года назад

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-227g-p58c-6fwx

11 месяцев назад

Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-227g-7cvv-6ff3

больше 3 лет назад

Apache Tapestry 5.8.1 vulnerable to ReDoS via Content Types causing catastrophic backtracking

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-227g-5725-2cf3

больше 3 лет назад

A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebsd-tools/vmware-tools-distrib/vmware-install.pl path. The fake ISO image will be mounted and the script wmware-install.pl will be executed with super-user privileges as soon as the hidden option to install VMware Tools is selected in the main menu of the restricted shell (option number 5). The contents of the script can be whatever the attacker wants, including a backdoor or similar.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-227x-w5qv-2294

admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

1%
Низкий
почти 4 года назад
github логотип
GHSA-227x-7mh8-3cf6

Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning

CVSS3: 9.9
0%
Низкий
4 месяца назад
github логотип
GHSA-227x-6m74-5g32

Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-227x-48c5-2jpf

HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-227w-xh58-rx2j

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-227w-wv4j-67h4

Class Loading Vulnerability in Artemis

CVSS3: 8.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-227w-82c7-87qx

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-227v-w3r6-6vc4

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-227v-m6p6-j6gx

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-227r-w5j2-6243

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
1%
Низкий
11 месяцев назад
github логотип
GHSA-227r-vmhh-jq3x

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-227r-cc3q-mh85

Windows GDI+ Information Disclosure Vulnerability

CVSS3: 5.7
13%
Средний
больше 3 лет назад
github логотип
GHSA-227p-7qgj-96v9

Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-227m-878m-h3qm

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-227j-xj2v-7f5v

The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-227h-wvc4-w9jx

In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-227h-6jwp-327q

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-227g-p58c-6fwx

Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-227g-7cvv-6ff3

Apache Tapestry 5.8.1 vulnerable to ReDoS via Content Types causing catastrophic backtracking

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-227g-5725-2cf3

A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebsd-tools/vmware-tools-distrib/vmware-install.pl path. The fake ISO image will be mounted and the script wmware-install.pl will be executed with super-user privileges as soon as the hidden option to install VMware Tools is selected in the main menu of the restricted shell (option number 5). The contents of the script can be whatever the attacker wants, including a backdoor or similar.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу