Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4wv5-vfv3-96c7

больше 4 лет назад

HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4358.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4wv5-g426-4246

больше 4 лет назад

A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.

EPSS: Низкий
github логотип

GHSA-4wv4-xcmf-c3qh

больше 4 лет назад

HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.

EPSS: Низкий
github логотип

GHSA-4wv4-mgfq-598v

больше 5 лет назад

Code injection in nobelprizeparser

EPSS: Низкий
github логотип

GHSA-4wv4-6mjq-34pw

больше 4 лет назад

FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4wv3-vrp8-r748

больше 4 лет назад

Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file.

EPSS: Низкий
github логотип

GHSA-4wv3-q9v5-fp5m

больше 4 лет назад

Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in the Linux kernel before 3.1, allows local users to overwrite arbitrary files via a crafted config file in the current working directory.

EPSS: Низкий
github логотип

GHSA-4wv3-4xwf-g4g6

больше 4 лет назад

The sahab-alkher.com (aka com.tapatalk.sahabalkhercomvb) application 2.4.9.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4wv3-22h6-h824

около 3 лет назад

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4wv2-5vm5-r9cc

больше 4 лет назад

SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action.

EPSS: Низкий
github логотип

GHSA-4wv2-475w-c2fw

больше 4 лет назад

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4wrx-2682-w227

больше 4 лет назад

resend command in Majordomo allows local users to gain privileges via shell metacharacters.

EPSS: Низкий
github логотип

GHSA-4wrw-r87c-p2q9

23 дня назад

Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4wrw-jm7c-gf3x

больше 4 лет назад

sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4wrw-g53q-g424

больше 4 лет назад

A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0868, CVE-2019-0870.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4wrv-p79w-3qmj

больше 4 лет назад

An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4wrv-c229-vc5p

больше 1 года назад

SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4wrr-xw2g-w6m2

больше 4 лет назад

Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.

EPSS: Низкий
github логотип

GHSA-4wrr-wx49-f3mw

больше 3 лет назад

A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4wrr-9h5r-m92w

больше 4 лет назад

Apache Struts Remote Java Code Execution

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4wv5-vfv3-96c7

HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4358.

CVSS3: 9.1
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv5-g426-4246

A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv4-xcmf-c3qh

HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv4-mgfq-598v

Code injection in nobelprizeparser

больше 5 лет назад
github логотип
GHSA-4wv4-6mjq-34pw

FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv3-vrp8-r748

Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv3-q9v5-fp5m

Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in the Linux kernel before 3.1, allows local users to overwrite arbitrary files via a crafted config file in the current working directory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv3-4xwf-g4g6

The sahab-alkher.com (aka com.tapatalk.sahabalkhercomvb) application 2.4.9.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv3-22h6-h824

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS3: 8
6%
Низкий
около 3 лет назад
github логотип
GHSA-4wv2-5vm5-r9cc

SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wv2-475w-c2fw

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrx-2682-w227

resend command in Majordomo allows local users to gain privileges via shell metacharacters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrw-r87c-p2q9

Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 9.1
0%
Низкий
23 дня назад
github логотип
GHSA-4wrw-jm7c-gf3x

sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrw-g53q-g424

A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0868, CVE-2019-0870.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrv-p79w-3qmj

An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrv-c229-vc5p

SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-4wrr-xw2g-w6m2

Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrr-wx49-f3mw

A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4wrr-9h5r-m92w

Apache Struts Remote Java Code Execution

CVSS3: 9.8
76%
Высокий
больше 4 лет назад

Уязвимостей на страницу