Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4w54-wwc9-x62c

больше 2 лет назад

Silverpeas authentication bypass

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4w54-jmv8-vrwj

больше 4 лет назад

An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code parameter in three pages as collaterals/colexe3t.jsp and /references/refsuppu.jsp and /references/refbranu.jsp is mishandled before being used in SQL queries, allowing SQL injection with an authenticated session.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4w54-c3hg-qqrv

почти 4 года назад

An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (except password hashes) of any user authenticated.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4w53-w67f-ph68

больше 4 лет назад

Buffer overflow in cluster/cman/daemon/daemon.c in cman (redhat-cluster-suite) before 20070622 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long client messages.

EPSS: Низкий
github логотип

GHSA-4w53-cpmg-rg5c

больше 4 лет назад

Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.

EPSS: Низкий
github логотип

GHSA-4w53-6jvp-gg52

больше 2 лет назад

sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4w53-6539-fq3q

больше 4 лет назад

The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.

EPSS: Средний
github логотип

GHSA-4w52-x9c4-c723

больше 4 лет назад

Microsoft PowerPoint Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4w52-frxp-j5cw

больше 4 лет назад

In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-172005755

EPSS: Низкий
github логотип

GHSA-4w52-8g67-jvmf

3 месяца назад

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in takeover of Oracle iSupplier Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w52-3prg-7q3f

больше 4 лет назад

In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-4w4x-gprq-99xm

больше 4 лет назад

Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.

EPSS: Низкий
github логотип

GHSA-4w4x-f4fc-24p5

почти 2 года назад

A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4w4x-65f4-79g2

больше 4 лет назад

Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a URL parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4w4w-p43q-qpr8

больше 4 лет назад

Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers to access arbitrary files via unspecified vectors, a different vulnerability than CVE-2005-2006.

EPSS: Низкий
github логотип

GHSA-4w4w-jrgw-jr5h

около 4 лет назад

The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4w4w-866c-5vgg

больше 4 лет назад

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4w4v-9f8x-9pv8

больше 4 лет назад

An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved state handling. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user's private browsing activity may be unexpectedly saved in Screen Time.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4w4v-5hc9-xrr2

больше 2 лет назад

angular vulnerable to super-linear runtime due to backtracking

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w4r-xmmf-2qqm

больше 4 лет назад

Unspecified vulnerability in the TCP Loopback/Fusion implementation in Sun Solaris 10 allows local users to cause a denial of service (resource exhaustion and service hang) via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4w54-wwc9-x62c

Silverpeas authentication bypass

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4w54-jmv8-vrwj

An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code parameter in three pages as collaterals/colexe3t.jsp and /references/refsuppu.jsp and /references/refbranu.jsp is mishandled before being used in SQL queries, allowing SQL injection with an authenticated session.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w54-c3hg-qqrv

An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (except password hashes) of any user authenticated.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-4w53-w67f-ph68

Buffer overflow in cluster/cman/daemon/daemon.c in cman (redhat-cluster-suite) before 20070622 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long client messages.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w53-cpmg-rg5c

Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-4w53-6jvp-gg52

sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4w53-6539-fq3q

The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.

26%
Средний
больше 4 лет назад
github логотип
GHSA-4w52-x9c4-c723

Microsoft PowerPoint Remote Code Execution Vulnerability

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4w52-frxp-j5cw

In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-172005755

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w52-8g67-jvmf

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in takeover of Oracle iSupplier Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4w52-3prg-7q3f

In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.

CVSS3: 2.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w4x-gprq-99xm

Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4w4x-f4fc-24p5

A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-4w4x-65f4-79g2

Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a URL parameter.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w4w-p43q-qpr8

Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers to access arbitrary files via unspecified vectors, a different vulnerability than CVE-2005-2006.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4w4w-jrgw-jr5h

The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

CVSS3: 9.8
59%
Средний
около 4 лет назад
github логотип
GHSA-4w4w-866c-5vgg

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

CVSS3: 7.8
9%
Низкий
больше 4 лет назад
github логотип
GHSA-4w4v-9f8x-9pv8

An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved state handling. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user's private browsing activity may be unexpectedly saved in Screen Time.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w4v-5hc9-xrr2

angular vulnerable to super-linear runtime due to backtracking

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-4w4r-xmmf-2qqm

Unspecified vulnerability in the TCP Loopback/Fusion implementation in Sun Solaris 10 allows local users to cause a denial of service (resource exhaustion and service hang) via unspecified vectors.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу