Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4x33-2p42-q5cq

больше 4 лет назад

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4x32-w753-pwww

22 дня назад

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to view sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further privileges on the affected system.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4x32-m936-v3x7

11 месяцев назад

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLanSetupRouterSettings.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4x32-h296-rg6j

больше 4 лет назад

Singularity Incorrect Access Control

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4x2w-rqr8-f75m

больше 2 лет назад

In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4x2v-m9jj-4p23

9 дней назад

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4x2v-6qj2-vggc

больше 4 лет назад

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4x2v-66mc-66vr

больше 4 лет назад

Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super privileges via a "p4 protect" command.

EPSS: Низкий
github логотип

GHSA-4x2v-58g3-c5j2

больше 4 лет назад

Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.

EPSS: Низкий
github логотип

GHSA-4x2p-6cr9-jx6r

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change account privileges via an edit access_permissions action to index.php.

EPSS: Низкий
github логотип

GHSA-4x2m-9cgv-ww5m

больше 1 года назад

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetActiveProjects' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4x2j-vmv4-3qc3

больше 4 лет назад

The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.

EPSS: Низкий
github логотип

GHSA-4x2h-wcjq-p974

около 2 месяцев назад

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4x2h-w98x-4p25

больше 1 года назад

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4x2g-x3r2-29r6

больше 4 лет назад

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4x2g-7mfh-8rx6

9 дней назад

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

EPSS: Низкий
github логотип

GHSA-4x2g-6qf5-ww63

почти 2 года назад

The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4x2g-5mhv-x2fx

больше 4 лет назад

A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to memory corruption and other potential consequences.

EPSS: Низкий
github логотип

GHSA-4x2f-q7jf-fpvv

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4x2f-54wr-4hjg

почти 5 лет назад

Potential Zip Slip Vulnerability in baserCMS

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4x33-2p42-q5cq

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x32-w753-pwww

A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to view sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further privileges on the affected system.

CVSS3: 4.7
0%
Низкий
22 дня назад
github логотип
GHSA-4x32-m936-v3x7

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLanSetupRouterSettings.

CVSS3: 9.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-4x32-h296-rg6j

Singularity Incorrect Access Control

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x2w-rqr8-f75m

In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.

CVSS3: 6.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4x2v-m9jj-4p23

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

CVSS3: 9.1
0%
Низкий
9 дней назад
github логотип
GHSA-4x2v-6qj2-vggc

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4x2v-66mc-66vr

Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super privileges via a "p4 protect" command.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x2v-58g3-c5j2

Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x2p-6cr9-jx6r

Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change account privileges via an edit access_permissions action to index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4x2m-9cgv-ww5m

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetActiveProjects' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-4x2j-vmv4-3qc3

The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x2h-wcjq-p974

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is never cleared on password change events. The TokensClearer::clearPasswordTokens() function only removes rows from the password_tokens table while leaving all active session cookies and API bearer tokens intact, including long-lived RememberAccessToken entries, and administrator-forced password resets via the user update endpoint are equally ineffective at revoking attacker-held sessions.

CVSS3: 6.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4x2h-w98x-4p25

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-4x2g-x3r2-29r6

zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4x2g-7mfh-8rx6

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

0%
Низкий
9 дней назад
github логотип
GHSA-4x2g-6qf5-ww63

The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-4x2g-5mhv-x2fx

A Heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_w3fdif.c in filter16_complex_low, which might lead to memory corruption and other potential consequences.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4x2f-q7jf-fpvv

Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4x2f-54wr-4hjg

Potential Zip Slip Vulnerability in baserCMS

CVSS3: 7.7
2%
Низкий
почти 5 лет назад

Уязвимостей на страницу