Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-4q9c-68c7-fxff

больше 2 лет назад

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4q9c-6763-78hw

3 месяца назад

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Install). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVS...

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-4q98-wr72-h35w

около 7 лет назад

Improper input validation in Apache Santuario XML Security for Java

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4q98-p85m-4p54

больше 3 лет назад

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4q98-jf5r-gpmg

больше 4 лет назад

In findAvailSpellCheckerLocked of TextServicesManagerService.java, there is a possible way to bypass the warning dialog when selecting an untrusted spell checker due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0Android ID: A-118694079

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4q98-f277-w2f4

больше 4 лет назад

The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long password. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-4q97-mrgv-92q2

больше 1 года назад

jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4q97-g4xv-35c8

больше 4 лет назад

IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4q97-fh3f-j294

больше 5 лет назад

Prototype Pollution in tiny-conf

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4q96-h8mr-4mvm

почти 2 года назад

Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4q96-9f63-p7jj

больше 4 лет назад

Path Traversal in ImpressCMS

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4q96-97v6-xq9v

больше 4 лет назад

The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4q96-6xhq-ff43

почти 6 лет назад

malicious SVG attachment causing stored XSS vulnerability

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-4q95-v5vg-fjc2

больше 4 лет назад

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.

EPSS: Низкий
github логотип

GHSA-4q95-6mw3-3rm5

9 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-4q95-263m-g434

больше 4 лет назад

Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4q94-m8w5-hxm3

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-4q93-v92x-p89f

4 месяца назад

Keycloak Vulnerable to Incorrect Authorization

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4q93-fvm9-qjff

больше 4 лет назад

A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php component via the PATH_INFO.

EPSS: Низкий
github логотип

GHSA-4q93-6p46-6x3h

больше 2 лет назад

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.

CVSS3: 6.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4q9c-68c7-fxff

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.

CVSS3: 9.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-4q9c-6763-78hw

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Install). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVS...

CVSS3: 9
0%
Низкий
3 месяца назад
github логотип
GHSA-4q98-wr72-h35w

Improper input validation in Apache Santuario XML Security for Java

CVSS3: 5.5
1%
Низкий
около 7 лет назад
github логотип
GHSA-4q98-p85m-4p54

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4q98-jf5r-gpmg

In findAvailSpellCheckerLocked of TextServicesManagerService.java, there is a possible way to bypass the warning dialog when selecting an untrusted spell checker due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0Android ID: A-118694079

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4q98-f277-w2f4

The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long password. NOTE: some of these details are obtained from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4q97-mrgv-92q2

jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4q97-g4xv-35c8

IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.

CVSS3: 7.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4q97-fh3f-j294

Prototype Pollution in tiny-conf

CVSS3: 9.8
2%
Низкий
больше 5 лет назад
github логотип
GHSA-4q96-h8mr-4mvm

Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.3.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-4q96-9f63-p7jj

Path Traversal in ImpressCMS

CVSS3: 8.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4q96-97v6-xq9v

The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q96-6xhq-ff43

malicious SVG attachment causing stored XSS vulnerability

CVSS3: 8.7
2%
Низкий
почти 6 лет назад
github логотип
GHSA-4q95-v5vg-fjc2

SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q95-6mw3-3rm5

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

9 месяцев назад
github логотип
GHSA-4q95-263m-g434

Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4q94-m8w5-hxm3

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-4q93-v92x-p89f

Keycloak Vulnerable to Incorrect Authorization

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4q93-fvm9-qjff

A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php component via the PATH_INFO.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q93-6p46-6x3h

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.

CVSS3: 6.6
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу