Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 279

Количество 323 279

github логотип

GHSA-24qv-6795-29jh

почти 4 года назад

The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24qq-8vc9-wp3m

почти 2 года назад

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-24qp-pvw9-442x

почти 4 года назад

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

EPSS: Низкий
github логотип

GHSA-24qp-4xx8-3jvj

около 1 года назад

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

CVSS3: 3.2
EPSS: Низкий
github логотип

GHSA-24qm-h8fv-cv5c

почти 4 года назад

Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24qh-qr2h-95xw

почти 4 года назад

Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-24qh-92m3-q3jj

10 месяцев назад

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-users.php. The manipulation of the argument uid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-24qh-5jcc-qhqq

почти 4 года назад

The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.

EPSS: Средний
github логотип

GHSA-24qg-x6r4-72m5

почти 4 года назад

Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.

EPSS: Средний
github логотип

GHSA-24qg-gp8x-cc5w

почти 4 года назад

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Email Fixed in version 5.0.02.16. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of EML files. The issue results from the lack of proper validation of user-supplied data, which can allow arbitrary JavaScript to execute. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the application. Was ZDI-CAN-5328.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24qg-89rj-g629

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a through 1.0.6.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24qf-fgjm-mfxj

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hands01 e-shops e-shops-cart2 allows DOM-Based XSS.This issue affects e-shops: from n/a through <= 1.0.4.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24qc-25f9-3h95

почти 4 года назад

A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual instance running on the affected device. The vulnerability is due to insufficient input validation of user-supplied application packages. An attacker who can upload a malicious package within Cisco IOx could exploit the vulnerability to modify arbitrary files. The impacts of a successful exploit are limited to the scope of the virtual instance and do not impact the router that is hosting Cisco IOx. Cisco IOx Releases 1.0.0.0 and 1.1.0.0 are vulnerable. Cisco Bug IDs: CSCuy52317.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-24q9-49c8-294h

почти 4 года назад

The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication via a brute force attack, aka "One-time (s/key) Password Authentication."

EPSS: Низкий
github логотип

GHSA-24q9-34wm-r8c7

больше 1 года назад

Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24q8-wj7p-mvj3

больше 3 лет назад

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24q8-rjjm-c7vv

почти 4 года назад

In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-143560807

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24q8-6wpc-mx3g

почти 4 года назад

Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24q8-66w6-4wqm

почти 4 года назад

The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24q8-4qrp-jx53

около 1 года назад

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/goods/update. The manipulation of the argument goodsName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24qv-6795-29jh

The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-24qq-8vc9-wp3m

TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.

CVSS3: 8.6
3%
Низкий
почти 2 года назад
github логотип
GHSA-24qp-pvw9-442x

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.

8%
Низкий
почти 4 года назад
github логотип
GHSA-24qp-4xx8-3jvj

Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers

CVSS3: 3.2
0%
Низкий
около 1 года назад
github логотип
GHSA-24qm-h8fv-cv5c

Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-24qh-qr2h-95xw

Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-24qh-92m3-q3jj

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-users.php. The manipulation of the argument uid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-24qh-5jcc-qhqq

The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.

15%
Средний
почти 4 года назад
github логотип
GHSA-24qg-x6r4-72m5

Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.

30%
Средний
почти 4 года назад
github логотип
GHSA-24qg-gp8x-cc5w

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Email Fixed in version 5.0.02.16. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of EML files. The issue results from the lack of proper validation of user-supplied data, which can allow arbitrary JavaScript to execute. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the application. Was ZDI-CAN-5328.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-24qg-89rj-g629

Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a through 1.0.6.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-24qf-fgjm-mfxj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hands01 e-shops e-shops-cart2 allows DOM-Based XSS.This issue affects e-shops: from n/a through <= 1.0.4.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-24qc-25f9-3h95

A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual instance running on the affected device. The vulnerability is due to insufficient input validation of user-supplied application packages. An attacker who can upload a malicious package within Cisco IOx could exploit the vulnerability to modify arbitrary files. The impacts of a successful exploit are limited to the scope of the virtual instance and do not impact the router that is hosting Cisco IOx. Cisco IOx Releases 1.0.0.0 and 1.1.0.0 are vulnerable. Cisco Bug IDs: CSCuy52317.

CVSS3: 8.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-24q9-49c8-294h

The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication via a brute force attack, aka "One-time (s/key) Password Authentication."

1%
Низкий
почти 4 года назад
github логотип
GHSA-24q9-34wm-r8c7

Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-24q8-wj7p-mvj3

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24q8-rjjm-c7vv

In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-143560807

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-24q8-6wpc-mx3g

Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-24q8-66w6-4wqm

The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-24q8-4qrp-jx53

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/goods/update. The manipulation of the argument goodsName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу