Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4rv5-wq7q-4wfm

больше 4 лет назад

IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4rv5-hh7f-94pj

больше 4 лет назад

An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8314.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4rv5-cvr5-mg5p

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.

EPSS: Низкий
github логотип

GHSA-4rv4-vpmj-m97r

больше 4 лет назад

SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-4rv4-2rhp-3qjw

больше 4 лет назад

** DISPUTED ** main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?language=en_US) and disagrees that this issue is a vulnerability. They also claim that MicroStrategy was never properly informed of this issue via normal support channels or their vulnerability reporting page on their website, so they were unable to evaluate the report or explain how this is something their customers view as a feature and not a security vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rv3-m58q-vg7c

больше 4 лет назад

The ff_free_picture_tables function in libavcodec/mpegpicture.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to vc1_decode_i_blocks_adv.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rv3-gffj-q2p5

почти 5 лет назад

GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with an XSS payload as the name.

EPSS: Низкий
github логотип

GHSA-4rv2-mwgh-33gj

почти 2 года назад

A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4rv2-mv82-8rpm

больше 4 лет назад

e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.

EPSS: Низкий
github логотип

GHSA-4rv2-fpjm-34hr

больше 2 лет назад

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-4rv2-f267-rh4v

больше 4 лет назад

The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rrx-pvg4-78rv

около 3 лет назад

The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a missing capability check on the chp_abd_action function in versions up to, and including, 3.9.4. This makes it possible for subscriber-level attackers to change or reset plugin settings. CVE-2023-36509 appears to be a duplicate of this issue.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rrx-m76x-mwvv

почти 4 года назад

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rrx-j7vf-86fq

больше 4 лет назад

There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

EPSS: Низкий
github логотип

GHSA-4rrx-2jjh-rw9q

2 месяца назад

A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4rrw-4h2w-765q

больше 2 лет назад

A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-252185 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4rrv-pmrh-2vc4

4 месяца назад

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4rrv-8gcp-24v8

больше 2 лет назад

PaddlePaddle stack overflow in paddle.searchsorted

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4rrr-x7hr-6whv

около 3 лет назад

D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rrr-pc4c-p38g

больше 4 лет назад

Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4rv5-wq7q-4wfm

IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv5-hh7f-94pj

An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8314.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv5-cvr5-mg5p

Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv4-vpmj-m97r

SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv4-2rhp-3qjw

** DISPUTED ** main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?language=en_US) and disagrees that this issue is a vulnerability. They also claim that MicroStrategy was never properly informed of this issue via normal support channels or their vulnerability reporting page on their website, so they were unable to evaluate the report or explain how this is something their customers view as a feature and not a security vulnerability.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv3-m58q-vg7c

The ff_free_picture_tables function in libavcodec/mpegpicture.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to vc1_decode_i_blocks_adv.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv3-gffj-q2p5

GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with an XSS payload as the name.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-4rv2-mwgh-33gj

A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-4rv2-mv82-8rpm

e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rv2-fpjm-34hr

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.

CVSS3: 8.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4rv2-f267-rh4v

The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4rrx-pvg4-78rv

The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a missing capability check on the chp_abd_action function in versions up to, and including, 3.9.4. This makes it possible for subscriber-level attackers to change or reset plugin settings. CVE-2023-36509 appears to be a duplicate of this issue.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-4rrx-m76x-mwvv

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-4rrx-j7vf-86fq

There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rrx-2jjh-rw9q

A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 5.3
1%
Низкий
2 месяца назад
github логотип
GHSA-4rrw-4h2w-765q

A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-252185 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4rrv-pmrh-2vc4

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

CVSS3: 5.3
2%
Низкий
4 месяца назад
github логотип
GHSA-4rrv-8gcp-24v8

PaddlePaddle stack overflow in paddle.searchsorted

CVSS3: 8.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4rrr-x7hr-6whv

D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4rrr-pc4c-p38g

Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу