Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4rwx-mrf5-wx33

больше 2 лет назад

Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission model bypass through path traversal attack. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-4rwx-9hrf-jj43

11 дней назад

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.

EPSS: Низкий
github логотип

GHSA-4rww-qqx8-7693

больше 4 лет назад

IBM Jazz applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 145609.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4rww-gpv7-6j3g

7 месяцев назад

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rww-7vcv-43j8

больше 4 лет назад

Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.write, which allows remote attackers to supply unauthenticated content and conduct phishing attacks.

EPSS: Низкий
github логотип

GHSA-4rwv-25f9-m5gh

больше 4 лет назад

The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rwr-9f6c-x66x

больше 2 лет назад

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4rwr-8c3m-55f6

11 месяцев назад

TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rwr-62pp-84mp

больше 4 лет назад

Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file.

EPSS: Низкий
github логотип

GHSA-4rwq-m5m5-h79g

больше 4 лет назад

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

EPSS: Низкий
github логотип

GHSA-4rwq-456r-x2vq

больше 2 лет назад

Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only about one million possibilities).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rwp-3x5g-4c6w

около 1 месяца назад

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents including user credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30 (UTC).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4rwm-w4qm-p8q2

25 дней назад

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-4rwm-c5mj-wh7x

6 месяцев назад

Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rwm-76xq-3xjv

больше 4 лет назад

The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4rwm-74mf-prpv

больше 2 лет назад

Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This issue affects All-in-One WP Migration Box Extension: from n/a through 1.53; All-in-One WP Migration OneDrive Extension: from n/a through 1.66; All-in-One WP Migration Dropbox Extension: from n/a through 3.75; All-in-One WP Migration Google Drive Extension: from n/a through 2.79.

CVSS3: 7.3
EPSS: Средний
github логотип

GHSA-4rwh-hg22-2pc2

больше 4 лет назад

GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4rwh-4cv9-9p66

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Properly hide first-in-list PCIe extended capability There are cases where a PCIe extended capability should be hidden from the user. For example, an unknown capability (i.e., capability with ID greater than PCI_EXT_CAP_ID_MAX) or a capability that is intentionally chosen to be hidden from the user. Hiding a capability is done by virtualizing and modifying the 'Next Capability Offset' field of the previous capability so it points to the capability after the one that should be hidden. The special case where the first capability in the list should be hidden is handled differently because there is no previous capability that can be modified. In this case, the capability ID and version are zeroed while leaving the next pointer intact. This hides the capability and leaves an anchor for the rest of the capability list. However, today, hiding the first capability in the list is not done properly if the capab...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4rwg-mr3v-x763

около 1 месяца назад

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rwg-8m37-cjcc

2 месяца назад

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4rwx-mrf5-wx33

Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission model bypass through path traversal attack. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 7.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4rwx-9hrf-jj43

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.

0%
Низкий
11 дней назад
github логотип
GHSA-4rww-qqx8-7693

IBM Jazz applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 145609.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rww-gpv7-6j3g

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

CVSS3: 8.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-4rww-7vcv-43j8

Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.write, which allows remote attackers to supply unauthenticated content and conduct phishing attacks.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rwv-25f9-m5gh

The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rwr-9f6c-x66x

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4rwr-8c3m-55f6

TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-4rwr-62pp-84mp

Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4rwq-m5m5-h79g

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rwq-456r-x2vq

Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only about one million possibilities).

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4rwp-3x5g-4c6w

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents including user credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30 (UTC).

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4rwm-w4qm-p8q2

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."

CVSS3: 6
0%
Низкий
25 дней назад
github логотип
GHSA-4rwm-c5mj-wh7x

Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-4rwm-76xq-3xjv

The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rwm-74mf-prpv

Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This issue affects All-in-One WP Migration Box Extension: from n/a through 1.53; All-in-One WP Migration OneDrive Extension: from n/a through 1.66; All-in-One WP Migration Dropbox Extension: from n/a through 3.75; All-in-One WP Migration Google Drive Extension: from n/a through 2.79.

CVSS3: 7.3
11%
Средний
больше 2 лет назад
github логотип
GHSA-4rwh-hg22-2pc2

GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4rwh-4cv9-9p66

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Properly hide first-in-list PCIe extended capability There are cases where a PCIe extended capability should be hidden from the user. For example, an unknown capability (i.e., capability with ID greater than PCI_EXT_CAP_ID_MAX) or a capability that is intentionally chosen to be hidden from the user. Hiding a capability is done by virtualizing and modifying the 'Next Capability Offset' field of the previous capability so it points to the capability after the one that should be hidden. The special case where the first capability in the list should be hidden is handled differently because there is no previous capability that can be modified. In this case, the capability ID and version are zeroed while leaving the next pointer intact. This hides the capability and leaves an anchor for the rest of the capability list. However, today, hiding the first capability in the list is not done properly if the capab...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4rwg-mr3v-x763

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

CVSS3: 9.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-4rwg-8m37-cjcc

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
2 месяца назад

Уязвимостей на страницу