Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4wvj-8v7h-xg58

больше 4 лет назад

A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4wvj-6mmr-g6xj

больше 4 лет назад

Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-4wvh-hcxh-m8xx

больше 4 лет назад

A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.

EPSS: Низкий
github логотип

GHSA-4wvg-r3cj-2gc3

больше 4 лет назад

Unspecified vulnerability in HP Virtual Connect Enterprise Manager (VCEM) 6.0 and 6.1 allows remote attackers to read arbitrary files via unknown vectors.

EPSS: Низкий
github логотип

GHSA-4wvg-hh97-h3gv

больше 4 лет назад

arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.

EPSS: Низкий
github логотип

GHSA-4wvg-c8hr-7h76

около 2 лет назад

A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4wvg-7886-83gv

больше 4 лет назад

Moodle cross-site request forgery (CSRF) vulnerability

EPSS: Низкий
github логотип

GHSA-4wvf-7qxr-6vrg

8 дней назад

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-4wvf-2vqw-mj6r

почти 4 года назад

Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wvc-w234-qmf8

больше 4 лет назад

Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.

EPSS: Низкий
github логотип

GHSA-4wvc-ffmh-rrcr

больше 4 лет назад

Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

EPSS: Низкий
github логотип

GHSA-4wvc-8m2g-c9q7

около 4 лет назад

The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitation of this vulnerability may result in the acquisition of data from unknown addresses in address mappings.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wvc-3vgh-543q

почти 2 года назад

In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4wv9-rjh2-6fhw

больше 3 лет назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Big Sur 11.7.5. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4wv9-fx5g-4f62

больше 4 лет назад

SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.

EPSS: Низкий
github логотип

GHSA-4wv8-v68w-x5mv

больше 4 лет назад

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1101, CVE-2020-1106.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4wv8-p854-pjqv

больше 4 лет назад

In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525

EPSS: Низкий
github логотип

GHSA-4wv7-jg5w-qpfh

около 2 лет назад

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4wv7-983f-6869

около 3 лет назад

Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4wv6-hfwf-hgxc

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4wvj-8v7h-xg58

A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvj-6mmr-g6xj

Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors.

34%
Средний
больше 4 лет назад
github логотип
GHSA-4wvh-hcxh-m8xx

A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvg-r3cj-2gc3

Unspecified vulnerability in HP Virtual Connect Enterprise Manager (VCEM) 6.0 and 6.1 allows remote attackers to read arbitrary files via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvg-hh97-h3gv

arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvg-c8hr-7h76

A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

CVSS3: 8.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-4wvg-7886-83gv

Moodle cross-site request forgery (CSRF) vulnerability

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvf-7qxr-6vrg

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 8.7
0%
Низкий
8 дней назад
github логотип
GHSA-4wvf-2vqw-mj6r

Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-4wvc-w234-qmf8

Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvc-ffmh-rrcr

Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4wvc-8m2g-c9q7

The fingerprint module has a vulnerability of overflow in arithmetic addition. Successful exploitation of this vulnerability may result in the acquisition of data from unknown addresses in address mappings.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-4wvc-3vgh-543q

In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4wv9-rjh2-6fhw

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Big Sur 11.7.5. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4wv9-fx5g-4f62

SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv8-v68w-x5mv

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1101, CVE-2020-1106.

CVSS3: 5.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv8-p854-pjqv

In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv7-jg5w-qpfh

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.

CVSS3: 4.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-4wv7-983f-6869

Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-4wv6-hfwf-hgxc

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу