Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4r3p-r3fh-c2xr

около 1 года назад

SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4r3p-cxgg-r53c

3 месяца назад

A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file classes/Users.php. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4r3m-j6x5-48m3

около 6 лет назад

Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4r3h-7hr5-pjx6

больше 4 лет назад

Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.

EPSS: Низкий
github логотип

GHSA-4r3h-4pgq-8rpc

больше 4 лет назад

The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4r3g-w96h-5qxg

почти 4 года назад

Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4r3g-w24c-gpr6

больше 4 лет назад

Alkacon OpenCMS XSS via searchfilter parameter in system/workplace/admin/workplace/sessions.jsp

EPSS: Низкий
github логотип

GHSA-4r3g-2r86-vmh6

больше 4 лет назад

b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r3f-c7x3-6vc2

27 дней назад

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4r3c-w524-c83m

больше 4 лет назад

Use after free issue occurs If another instance of open for voice_svc node has been called from application without closing the previous one. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4r3c-9hx8-87cc

около 1 года назад

A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_avaliacao_desempenho_cad.php. The manipulation of the argument titulo_avaliacao/descricao leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4r3c-72vr-vf8h

больше 4 лет назад

Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.

EPSS: Низкий
github логотип

GHSA-4r3c-5hpg-58qr

3 месяца назад

Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r39-fvrv-xrfj

больше 2 лет назад

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could result in a write-what-where condition and an attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15696)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4r39-f4rh-j6q8

больше 4 лет назад

Missing permission check in Jenkins Gerrit Trigger Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4r39-95r5-429h

больше 4 лет назад

SQL injection vulnerability in openSIS 4.5 through 5.3 allows remote attackers to execute arbitrary SQL commands via the Username and password to index.php.

EPSS: Низкий
github логотип

GHSA-4r39-5xx8-q235

больше 4 лет назад

An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application can miscalculate a pointer for the stripes in the tile which allow for the decoder to write out of-bounds and cause memory corruption. This can result in code execution. A specially crafted image can be embedded inside a PDF and loaded by a victim in order to trigger this vulnerability.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-4r38-rqh5-3fvr

около 2 лет назад

Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.5.5.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4r38-38gx-5vr9

больше 4 лет назад

PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.

EPSS: Низкий
github логотип

GHSA-4r38-2fwm-9vj5

больше 1 года назад

In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4r3p-r3fh-c2xr

SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database

CVSS3: 7.2
1%
Низкий
около 1 года назад
github логотип
GHSA-4r3p-cxgg-r53c

A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file classes/Users.php. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4r3m-j6x5-48m3

Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings

CVSS3: 7.3
1%
Низкий
около 6 лет назад
github логотип
GHSA-4r3h-7hr5-pjx6

Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r3h-4pgq-8rpc

The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.

CVSS3: 5.3
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4r3g-w96h-5qxg

Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-4r3g-w24c-gpr6

Alkacon OpenCMS XSS via searchfilter parameter in system/workplace/admin/workplace/sessions.jsp

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r3g-2r86-vmh6

b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4r3f-c7x3-6vc2

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.

CVSS3: 6.5
0%
Низкий
27 дней назад
github логотип
GHSA-4r3c-w524-c83m

Use after free issue occurs If another instance of open for voice_svc node has been called from application without closing the previous one. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r3c-9hx8-87cc

A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_avaliacao_desempenho_cad.php. The manipulation of the argument titulo_avaliacao/descricao leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4r3c-72vr-vf8h

Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4r3c-5hpg-58qr

Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4r39-fvrv-xrfj

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could result in a write-what-where condition and an attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15696)

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4r39-f4rh-j6q8

Missing permission check in Jenkins Gerrit Trigger Plugin

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r39-95r5-429h

SQL injection vulnerability in openSIS 4.5 through 5.3 allows remote attackers to execute arbitrary SQL commands via the Username and password to index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r39-5xx8-q235

An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tiles with sub-sample data, the application can miscalculate a pointer for the stripes in the tile which allow for the decoder to write out of-bounds and cause memory corruption. This can result in code execution. A specially crafted image can be embedded inside a PDF and loaded by a victim in order to trigger this vulnerability.

CVSS3: 7.8
17%
Средний
больше 4 лет назад
github логотип
GHSA-4r38-rqh5-3fvr

Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.5.5.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility.

CVSS3: 8.8
2%
Низкий
около 2 лет назад
github логотип
GHSA-4r38-38gx-5vr9

PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r38-2fwm-9vj5

In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.

CVSS3: 5.6
0%
Низкий
больше 1 года назад

Уязвимостей на страницу