Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4qxv-j5h7-m4jq

больше 1 года назад

Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4qxr-q27x-w926

3 месяца назад

Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4qxr-h6g3-8f95

3 месяца назад

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4qxr-c6vx-j7fm

около 1 года назад

A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article Comment Handler. The manipulation leads to authentication bypass by capture-replay. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4qxr-4w4x-7j43

больше 4 лет назад

The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool.

EPSS: Низкий
github логотип

GHSA-4qxq-56pv-jrxw

больше 2 лет назад

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been classified as critical. This affects an unknown part of the file /admin_route/inc_service_credits.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250575.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4qxq-29xm-x943

9 месяцев назад

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_service in file /usr/lib/lua/luci/controller/admin/service.lua.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4qxp-gr36-38c7

больше 4 лет назад

OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.

EPSS: Низкий
github логотип

GHSA-4qxp-c58r-4xg9

около 2 лет назад

A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.3 could allow an attacker to potentially uninstall CylanceOPTICS from a system thereby leaving it with only the protection of CylancePROTECT.

EPSS: Низкий
github логотип

GHSA-4qxm-xm9h-rhmg

больше 4 лет назад

Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.

EPSS: Низкий
github логотип

GHSA-4qxm-6rr2-4xf8

почти 4 года назад

The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation or a compromise of a targeted account.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-4qxh-cm8m-xm4j

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, and SD 820A, a buffer overread in Playready may occur due to lack of input validation of the buffer size provided by HLOS.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4qxh-75jf-785r

больше 1 года назад

Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qxh-72x2-v8fc

почти 2 года назад

A maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior to initialization. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4qxg-q4h5-wpq2

больше 3 лет назад

A vulnerability classified as critical was found in dst-admin 1.5.0. Affected by this vulnerability is an unknown functionality of the file /home/cavesConsole. The manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220033 was assigned to this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qxg-mfmj-r355

больше 1 года назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4qxg-68vm-h4qh

больше 3 лет назад

Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4qxg-56mj-c47p

больше 4 лет назад

Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24108, CVE-2021-27057.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-4qxf-vv9q-j2g9

2 месяца назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qxf-cfrr-vxjg

больше 2 лет назад

URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4qxv-j5h7-m4jq

Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-4qxr-q27x-w926

Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-4qxr-h6g3-8f95

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

CVSS3: 6.5
1%
Низкий
3 месяца назад
github логотип
GHSA-4qxr-c6vx-j7fm

A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article Comment Handler. The manipulation leads to authentication bypass by capture-replay. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
1%
Низкий
около 1 года назад
github логотип
GHSA-4qxr-4w4x-7j43

The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4qxq-56pv-jrxw

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been classified as critical. This affects an unknown part of the file /admin_route/inc_service_credits.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250575.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4qxq-29xm-x943

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_service in file /usr/lib/lua/luci/controller/admin/service.lua.

CVSS3: 8.8
3%
Низкий
9 месяцев назад
github логотип
GHSA-4qxp-gr36-38c7

OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4qxp-c58r-4xg9

A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.3 could allow an attacker to potentially uninstall CylanceOPTICS from a system thereby leaving it with only the protection of CylancePROTECT.

0%
Низкий
около 2 лет назад
github логотип
GHSA-4qxm-xm9h-rhmg

Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qxm-6rr2-4xf8

The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation or a compromise of a targeted account.

CVSS3: 9
1%
Низкий
почти 4 года назад
github логотип
GHSA-4qxh-cm8m-xm4j

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, and SD 820A, a buffer overread in Playready may occur due to lack of input validation of the buffer size provided by HLOS.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qxh-75jf-785r

Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
2%
Низкий
больше 1 года назад
github логотип
GHSA-4qxh-72x2-v8fc

A maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior to initialization. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-4qxg-q4h5-wpq2

A vulnerability classified as critical was found in dst-admin 1.5.0. Affected by this vulnerability is an unknown functionality of the file /home/cavesConsole. The manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220033 was assigned to this vulnerability.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-4qxg-mfmj-r355

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4qxg-68vm-h4qh

Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4qxg-56mj-c47p

Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24108, CVE-2021-27057.

CVSS3: 7.6
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4qxf-vv9q-j2g9

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4qxf-cfrr-vxjg

URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу