Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4x22-29pf-hh57

больше 1 года назад

Missing Authorization vulnerability in smackcoders Lead Form Data Collection to CRM allows Privilege Escalation. This issue affects Lead Form Data Collection to CRM: from n/a through 3.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4wxx-xmrx-3xq9

больше 4 лет назад

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4wxw-w756-wvc6

больше 1 года назад

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report. This issue affects CompletePBX: all versions up to and prior to 5.2.35

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4wxw-jxm6-5ch2

больше 4 лет назад

IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4wxw-g9jf-83hv

больше 4 лет назад

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000000f53."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4wxw-42wx-2wfx

больше 2 лет назад

Apache Solr Schema Designer blindly "trusts" all configsets

EPSS: Низкий
github логотип

GHSA-4wxw-3vrc-3hmh

больше 1 года назад

A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERRNO value. This issue may lead to a NULL pointer access.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4wxv-72gg-pr7r

почти 2 года назад

AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4wxr-8w46-674r

больше 4 лет назад

An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. The issue was addressed with improved permissions logic.

EPSS: Низкий
github логотип

GHSA-4wxr-85gq-28v4

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prem Tiwari FM Notification Bar allows Stored XSS. This issue affects FM Notification Bar: from n/a through 1.0.2.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4wxr-6xmc-853x

больше 2 лет назад

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4wxp-pf54-mr3v

больше 4 лет назад

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

EPSS: Низкий
github логотип

GHSA-4wxp-p2xq-9854

4 месяца назад

A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4wxp-jxg3-992f

больше 4 лет назад

Kilo 0.0.1 has a heap-based buffer overflow because there is an integer overflow in a calculation involving the number of tabs in one row.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wxp-6xr4-5pvw

больше 1 года назад

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4wxp-4p3q-cvf5

больше 4 лет назад

QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further compromise the device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wxm-q46g-3mcf

больше 4 лет назад

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4wxm-97vh-7m26

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4wxj-v45f-gf8f

4 месяца назад

A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4wxj-r835-5f6x

больше 4 лет назад

An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4x22-29pf-hh57

Missing Authorization vulnerability in smackcoders Lead Form Data Collection to CRM allows Privilege Escalation. This issue affects Lead Form Data Collection to CRM: from n/a through 3.1.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4wxx-xmrx-3xq9

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."

CVSS3: 8.8
60%
Средний
больше 4 лет назад
github логотип
GHSA-4wxw-w756-wvc6

Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete any retrieved file in place of the expected report. This issue affects CompletePBX: all versions up to and prior to 5.2.35

CVSS3: 6.7
2%
Низкий
больше 1 года назад
github логотип
GHSA-4wxw-jxm6-5ch2

IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.

CVSS3: 6.2
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4wxw-g9jf-83hv

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000000f53."

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4wxw-42wx-2wfx

Apache Solr Schema Designer blindly "trusts" all configsets

3%
Низкий
больше 2 лет назад
github логотип
GHSA-4wxw-3vrc-3hmh

A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERRNO value. This issue may lead to a NULL pointer access.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4wxv-72gg-pr7r

AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-4wxr-8w46-674r

An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. The issue was addressed with improved permissions logic.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wxr-85gq-28v4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prem Tiwari FM Notification Bar allows Stored XSS. This issue affects FM Notification Bar: from n/a through 1.0.2.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-4wxr-6xmc-853x

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4wxp-pf54-mr3v

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4wxp-p2xq-9854

A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4wxp-jxg3-992f

Kilo 0.0.1 has a heap-based buffer overflow because there is an integer overflow in a calculation involving the number of tabs in one row.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wxp-6xr4-5pvw

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4wxp-4p3q-cvf5

QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further compromise the device.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wxm-q46g-3mcf

In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wxm-97vh-7m26

Multiple cross-site scripting (XSS) vulnerabilities in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wxj-v45f-gf8f

A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4wxj-r835-5f6x

An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу