Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4vx4-vp54-mwmc

4 месяца назад

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-4vx4-3qfh-m6gm

больше 4 лет назад

Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).

EPSS: Низкий
github логотип

GHSA-4vx3-w9x3-ppmr

больше 4 лет назад

Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCuh73454.

EPSS: Низкий
github логотип

GHSA-4vx3-rfqx-v945

12 дней назад

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.

EPSS: Низкий
github логотип

GHSA-4vx3-8w8x-cp7w

11 месяцев назад

A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-4vx3-3xr8-7q3x

больше 4 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.

EPSS: Низкий
github логотип

GHSA-4vx2-wjfv-v48h

больше 4 лет назад

SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

EPSS: Низкий
github логотип

GHSA-4vwx-vcmw-r92m

больше 4 лет назад

Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.

EPSS: Низкий
github логотип

GHSA-4vwx-r658-c2mg

больше 4 лет назад

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-4vwx-p2g9-hr37

больше 4 лет назад

In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4vwx-54mw-vqfw

больше 2 лет назад

Traefik vulnerable to denial of service with Content-length header

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vwx-53cp-qmh4

больше 1 года назад

An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vww-mc66-62m6

около 5 лет назад

HTTP Request Smuggling in Apache Tomcat

CVSS3: 5.3
EPSS: Высокий
github логотип

GHSA-4vww-h9rr-whmq

6 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ProLingua prolingua allows PHP Local File Inclusion.This issue affects ProLingua: from n/a through <= 1.1.12.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4vww-ch2x-c53p

7 месяцев назад

FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-character buffer to cause the application to crash when opening options.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vww-5597-52xv

больше 4 лет назад

Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors, related to a "bounds checking" issue, a different vulnerability than CVE-2011-0623, CVE-2011-0624, and CVE-2011-0625.

EPSS: Низкий
github логотип

GHSA-4vww-46cf-g96h

2 месяца назад

The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate the login name, email address, and user ID of all WordPress accounts — including administrators — by submitting arbitrary search terms to the AJAX handler. The required 'search-user' nonce is localized into the wallet_param object on the standard WooCommerce My Account page, which is accessible to any authenticated user, making it trivially obtainable by a Subscriber.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4vwv-x3gp-2j4g

больше 4 лет назад

The Undertow module of WildFly allows source code disclosure

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vwr-f92g-29m6

9 месяцев назад

A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/api/status/. Performing manipulation results in improper authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 2023.1.1.13.486, 2023.2.1.10.293, 2024.1.1.9.236, 2024.2.1.6.125 and 2025.1.1.1.31 can resolve this issue. Upgrading the affected component is recommended.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4vwr-5vph-4mjg

8 месяцев назад

Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4vx4-vp54-mwmc

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

CVSS3: 7.5
40%
Средний
4 месяца назад
github логотип
GHSA-4vx4-3qfh-m6gm

Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vx3-w9x3-ppmr

Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCuh73454.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4vx3-rfqx-v945

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.

0%
Низкий
12 дней назад
github логотип
GHSA-4vx3-8w8x-cp7w

A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine

CVSS3: 10
1%
Низкий
11 месяцев назад
github логотип
GHSA-4vx3-3xr8-7q3x

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4vx2-wjfv-v48h

SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vwx-vcmw-r92m

Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-4vwx-r658-c2mg

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.

CVSS3: 6.5
69%
Средний
больше 4 лет назад
github логотип
GHSA-4vwx-p2g9-hr37

In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vwx-54mw-vqfw

Traefik vulnerable to denial of service with Content-length header

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4vwx-53cp-qmh4

An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4vww-mc66-62m6

HTTP Request Smuggling in Apache Tomcat

CVSS3: 5.3
75%
Высокий
около 5 лет назад
github логотип
GHSA-4vww-h9rr-whmq

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ProLingua prolingua allows PHP Local File Inclusion.This issue affects ProLingua: from n/a through <= 1.1.12.

CVSS3: 8.1
1%
Низкий
6 месяцев назад
github логотип
GHSA-4vww-ch2x-c53p

FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-character buffer to cause the application to crash when opening options.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-4vww-5597-52xv

Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors, related to a "bounds checking" issue, a different vulnerability than CVE-2011-0623, CVE-2011-0624, and CVE-2011-0625.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4vww-46cf-g96h

The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate the login name, email address, and user ID of all WordPress accounts — including administrators — by submitting arbitrary search terms to the AJAX handler. The required 'search-user' nonce is localized into the wallet_param object on the standard WooCommerce My Account page, which is accessible to any authenticated user, making it trivially obtainable by a Subscriber.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-4vwv-x3gp-2j4g

The Undertow module of WildFly allows source code disclosure

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vwr-f92g-29m6

A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/api/status/. Performing manipulation results in improper authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 2023.1.1.13.486, 2023.2.1.10.293, 2024.1.1.9.236, 2024.2.1.6.125 and 2025.1.1.1.31 can resolve this issue. Upgrading the affected component is recommended.

CVSS3: 7.3
1%
Низкий
9 месяцев назад
github логотип
GHSA-4vwr-5vph-4mjg

Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service

0%
Низкий
8 месяцев назад

Уязвимостей на страницу