Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 378 065

Количество 378 065

github логотип

GHSA-535p-g7m4-r8xm

около 1 года назад

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-535p-c89j-pqj5

больше 1 года назад

Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-535p-6x4h-f6px

больше 3 лет назад

In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07635697; Issue ID: ALPS07635697.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-535m-8qpw-vrx6

4 месяца назад

Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-535j-hpwq-gc54

около 1 года назад

Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection. This issue affects Hillter: from n/a through 3.0.7.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-535j-5wpp-p7jm

почти 3 года назад

Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-535j-2gj4-m7x7

больше 1 года назад

A vulnerability has been found in code-projects Responsive Hotel Site 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/newsletter.php. The manipulation of the argument eid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-535h-r53g-x9v4

больше 4 лет назад

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3663, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.

EPSS: Низкий
github логотип

GHSA-535h-mv4w-87cj

9 месяцев назад

CWE-434 Unrestricted Upload of File with Dangerous Type

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-535h-62c3-g4j6

больше 1 года назад

Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby compromising the application's confidentiality. There is no impact on integrity or availability

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-535g-qhh4-m728

больше 4 лет назад

Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-535g-mv5c-jrh8

почти 2 года назад

The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.15 via the 'actAjaxRevisionDiffs' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including revisions of posts and pages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-535g-c3ww-mvp7

больше 4 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file uploads. A crafted gui_region in a string table file can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-9756.

EPSS: Низкий
github логотип

GHSA-535g-62r7-cx6v

11 месяцев назад

Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-535f-6cw7-vm9r

больше 1 года назад

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-535c-fwmj-7hhw

больше 4 лет назад

Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5359-pvf2-pw78

больше 2 лет назад

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5359-gfvc-c3p7

11 месяцев назад

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-5359-frvq-63mr

4 месяца назад

Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5359-92wf-c9gq

больше 4 лет назад

An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-535p-g7m4-r8xm

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.

CVSS3: 5.5
1%
Низкий
около 1 года назад
github логотип
GHSA-535p-c89j-pqj5

Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-535p-6x4h-f6px

In widevine, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07635697; Issue ID: ALPS07635697.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-535m-8qpw-vrx6

Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
0%
Низкий
4 месяца назад
github логотип
GHSA-535j-hpwq-gc54

Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection. This issue affects Hillter: from n/a through 3.0.7.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-535j-5wpp-p7jm

Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-535j-2gj4-m7x7

A vulnerability has been found in code-projects Responsive Hotel Site 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/newsletter.php. The manipulation of the argument eid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-535h-r53g-x9v4

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3663, CVE-2015-3666, CVE-2015-3667, and CVE-2015-3668.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-535h-mv4w-87cj

CWE-434 Unrestricted Upload of File with Dangerous Type

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-535h-62c3-g4j6

Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby compromising the application's confidentiality. There is no impact on integrity or availability

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-535g-qhh4-m728

Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-535g-mv5c-jrh8

The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.15 via the 'actAjaxRevisionDiffs' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including revisions of posts and pages.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-535g-c3ww-mvp7

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file uploads. A crafted gui_region in a string table file can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-9756.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-535g-62r7-cx6v

Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-535f-6cw7-vm9r

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-535c-fwmj-7hhw

Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is possible here is to fill up the disk with core dumps if the OS actually generates different core dumps (which is unlikely)... the bug is in the shutdown code (finis()) which leads directly to exit(3), i.e., the process would terminate anyway, no mail delivery or receiption is affected."

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-5359-pvf2-pw78

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-5359-gfvc-c3p7

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.

CVSS3: 7.2
1%
Низкий
11 месяцев назад
github логотип
GHSA-5359-frvq-63mr

Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-5359-92wf-c9gq

An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.

CVSS3: 10
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу