Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 805

Количество 323 805

github логотип

GHSA-26v8-8f97-fq68

почти 3 года назад

H3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-26v7-7j6w-h2wc

почти 4 года назад

xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."

EPSS: Низкий
github логотип

GHSA-26v6-wwwv-j4cc

почти 2 года назад

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26v6-w6fw-rh94

больше 7 лет назад

Apache Camel can allow remote attackers to execute arbitrary commands

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-26v6-w2vj-4j4v

почти 4 года назад

The Big Win Slots - Slot Machines (aka com.gosub60.BigWinSlots) application 1.11.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-26v6-r4x8-vv44

почти 4 года назад

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-26v6-mp3h-qg6h

почти 4 года назад

The JavaScript implementation in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

EPSS: Средний
github логотип

GHSA-26v6-j796-w9w7

около 1 года назад

A vulnerability, which was classified as critical, was found in VAM Virtual Airlines Manager up to 2.6.2. Affected is an unknown function of the file /vam/index.php of the component HTTP GET Parameter Handler. The manipulation of the argument ID/registry_id/plane_icao leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-26v6-h3rv-wj58

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncode Ncep allows SQL Injection.This issue affects Ncep: before 20230914 .

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26v6-42cg-wj34

около 4 лет назад

A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.

EPSS: Низкий
github логотип

GHSA-26v6-3ggr-9jj5

почти 4 года назад

Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action.

EPSS: Средний
github логотип

GHSA-26v5-wxrq-v623

почти 4 года назад

Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-26v5-q2r5-7mv2

почти 4 года назад

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-26v4-wj6c-25pg

почти 4 года назад

In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38159931.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-26v4-vq66-h2r9

почти 4 года назад

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Memory Corruption Vulnerability."

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-26v4-7jhr-3827

около 3 лет назад

A vulnerability was found in SourceCodester Moosikay E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Moosikay/order.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221732.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26v4-76jx-c7r4

почти 4 года назад

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26v4-3ghx-vmrv

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26v2-rqv8-w34m

почти 4 года назад

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22882938.

EPSS: Низкий
github логотип

GHSA-26v2-hwwj-jjg2

около 4 лет назад

SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26v8-8f97-fq68

H3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.

CVSS3: 4.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-26v7-7j6w-h2wc

xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators."

1%
Низкий
почти 4 года назад
github логотип
GHSA-26v6-wwwv-j4cc

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.

CVSS3: 5.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-26v6-w6fw-rh94

Apache Camel can allow remote attackers to execute arbitrary commands

CVSS3: 8.1
7%
Низкий
больше 7 лет назад
github логотип
GHSA-26v6-w2vj-4j4v

The Big Win Slots - Slot Machines (aka com.gosub60.BigWinSlots) application 1.11.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26v6-r4x8-vv44

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

CVSS3: 7.7
8%
Низкий
почти 4 года назад
github логотип
GHSA-26v6-mp3h-qg6h

The JavaScript implementation in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

23%
Средний
почти 4 года назад
github логотип
GHSA-26v6-j796-w9w7

A vulnerability, which was classified as critical, was found in VAM Virtual Airlines Manager up to 2.6.2. Affected is an unknown function of the file /vam/index.php of the component HTTP GET Parameter Handler. The manipulation of the argument ID/registry_id/plane_icao leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-26v6-h3rv-wj58

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncode Ncep allows SQL Injection.This issue affects Ncep: before 20230914 .

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26v6-42cg-wj34

A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.

3%
Низкий
около 4 лет назад
github логотип
GHSA-26v6-3ggr-9jj5

Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action.

61%
Средний
почти 4 года назад
github логотип
GHSA-26v5-wxrq-v623

Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26v5-q2r5-7mv2

A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and ArubaOS that address this security vulnerability.

CVSS3: 7.2
4%
Низкий
почти 4 года назад
github логотип
GHSA-26v4-wj6c-25pg

In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38159931.

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-26v4-vq66-h2r9

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Memory Corruption Vulnerability."

CVSS3: 7.8
20%
Средний
почти 4 года назад
github логотип
GHSA-26v4-7jhr-3827

A vulnerability was found in SourceCodester Moosikay E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Moosikay/order.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221732.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-26v4-76jx-c7r4

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-26v4-3ghx-vmrv

Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-26v2-rqv8-w34m

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22882938.

3%
Низкий
почти 4 года назад
github логотип
GHSA-26v2-hwwj-jjg2

SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.

CVSS3: 8.8
36%
Средний
около 4 лет назад

Уязвимостей на страницу