Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-4q7p-3266-2mj7

больше 4 лет назад

D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of crafted fragmented UDP packets, possibly involving a missing fragment.

EPSS: Низкий
github логотип

GHSA-4q7m-xhfm-m8w5

больше 4 лет назад

Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif.

EPSS: Низкий
github логотип

GHSA-4q7m-mf5f-23v3

около 3 лет назад

The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitrary files on the affected site's server which may make remote code execution possible. This was partially patched in version 3.0.2 and fully patched in version 3.0.2.1.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-4q7h-c39w-2pw2

больше 1 года назад

Missing Authorization vulnerability in Webful Creations Computer Repair Shop allows Privilege Escalation.This issue affects Computer Repair Shop: from n/a through 3.8119.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4q7h-5rhf-q8ch

больше 4 лет назад

Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4q7h-5c9f-8xqg

больше 4 лет назад

An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. The FOURCC code, 'trik', is parsed by the function within the library. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4q7g-xw2p-3724

5 месяцев назад

Inappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4q7g-w286-mwc4

больше 4 лет назад

Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4q7g-933v-g3rq

больше 2 лет назад

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /view/timetable_grade_wise.php. The manipulation of the argument grade leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263119.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4q7c-7fj7-4vmq

больше 4 лет назад

The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged.

EPSS: Низкий
github логотип

GHSA-4q7c-37x4-482q

больше 4 лет назад

An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4q7c-2w2g-hrfp

больше 4 лет назад

An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; PAN-OS 9.1 version 9.1.4 through PAN-OS 9.1.10; PAN-OS 10.0 version 10.0.7 and earlier PAN-OS 10.0 versions; PAN-OS 10.1 version 10.1.0 through PAN-OS 10.1.1. Prisma Access firewalls and firewalls running PAN-OS 8.1 versions are not impacted by this issue.

EPSS: Низкий
github логотип

GHSA-4q79-qphh-pxpm

больше 4 лет назад

Integer overflow in the COFF/EPOC/EXPLOAD input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation.

EPSS: Низкий
github логотип

GHSA-4q79-fg6h-v56p

больше 3 лет назад

An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4q79-fch7-g78q

больше 7 лет назад

Downloads Resources over HTTP in grunt-webdriver-qunit

EPSS: Низкий
github логотип

GHSA-4q79-4m2m-vrg8

больше 4 лет назад

TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mail/createorupdate.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4q78-hrh3-2w49

почти 2 года назад

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4q78-4x34-hf7v

больше 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to LDAP.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-4q77-2r7r-9qjc

больше 4 лет назад

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4q76-wc8j-pm27

11 месяцев назад

The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in the csv-export.php file in all versions up to, and including, 6.1.5. This makes it possible for unauthenticated attackers to directly access the file and obtain an export of all booking data.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4q7p-3266-2mj7

D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of crafted fragmented UDP packets, possibly involving a missing fragment.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4q7m-xhfm-m8w5

Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4q7m-mf5f-23v3

The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitrary files on the affected site's server which may make remote code execution possible. This was partially patched in version 3.0.2 and fully patched in version 3.0.2.1.

CVSS3: 9.9
2%
Низкий
около 3 лет назад
github логотип
GHSA-4q7h-c39w-2pw2

Missing Authorization vulnerability in Webful Creations Computer Repair Shop allows Privilege Escalation.This issue affects Computer Repair Shop: from n/a through 3.8119.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4q7h-5rhf-q8ch

Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q7h-5c9f-8xqg

An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption. The FOURCC code, 'trik', is parsed by the function within the library. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4q7g-xw2p-3724

Inappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-4q7g-w286-mwc4

Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q7g-933v-g3rq

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /view/timetable_grade_wise.php. The manipulation of the argument grade leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263119.

CVSS3: 3.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4q7c-7fj7-4vmq

The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q7c-37x4-482q

An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q7c-2w2g-hrfp

An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; PAN-OS 9.1 version 9.1.4 through PAN-OS 9.1.10; PAN-OS 10.0 version 10.0.7 and earlier PAN-OS 10.0 versions; PAN-OS 10.1 version 10.1.0 through PAN-OS 10.1.1. Prisma Access firewalls and firewalls running PAN-OS 8.1 versions are not impacted by this issue.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4q79-qphh-pxpm

Integer overflow in the COFF/EPOC/EXPLOAD input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q79-fg6h-v56p

An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4q79-fch7-g78q

Downloads Resources over HTTP in grunt-webdriver-qunit

2%
Низкий
больше 7 лет назад
github логотип
GHSA-4q79-4m2m-vrg8

TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mail/createorupdate.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q78-hrh3-2w49

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-4q78-4x34-hf7v

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to LDAP.

CVSS3: 7.6
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q77-2r7r-9qjc

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4q76-wc8j-pm27

The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in the csv-export.php file in all versions up to, and including, 6.1.5. This makes it possible for unauthenticated attackers to directly access the file and obtain an export of all booking data.

CVSS3: 5.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу