Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4pp6-84pp-4cqw

около 4 лет назад

A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A low privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pp4-wvvq-cgj8

около 3 лет назад

In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pp4-hqhr-q59r

около 2 лет назад

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pp4-6fgx-j56f

больше 3 лет назад

Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This issue is remediated in version 3.3.0 via safe guards that reject inputs that attempt to do path traversal.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-4pp4-2f6f-77qm

почти 3 года назад

The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4pp2-m693-v6x9

больше 4 лет назад

SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.

EPSS: Низкий
github логотип

GHSA-4pp2-6v2q-mc4p

больше 4 лет назад

Jura E8 devices lack Bluetooth connection security.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4pp2-3663-mcw8

больше 4 лет назад

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.

EPSS: Низкий
github логотип

GHSA-4pmx-x3px-qgrr

больше 2 лет назад

IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4pmx-vh95-832r

почти 4 года назад

Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pmx-r8q4-w4vq

больше 4 лет назад

Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary code via a crafted encoded authentication request.

EPSS: Средний
github логотип

GHSA-4pmx-qx84-x3f4

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Community Yard Sale allows Stored XSS.This issue affects Community Yard Sale: from n/a through 1.1.11.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4pmx-jrq3-v88q

больше 4 лет назад

The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software before 4.4(3.54) and 4.5 before 4.5(1.45), Cisco TelePresence MSE Supervisor Software before 2.3(1.38), Cisco TelePresence Serial Gateway Series Software before 1.0(1.42), Cisco TelePresence Server Software for Hardware before 3.1(1.98), and Cisco TelePresence Server Software for Virtual Machine before 4.1(1.79) allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors, aka Bug IDs CSCul55968, CSCur08993, CSCur15803, CSCur15807, CSCur15825, CSCur15832, CSCur15842, CSCur15850, and CSCur15855.

EPSS: Низкий
github логотип

GHSA-4pmx-grr5-rmvm

больше 2 лет назад

Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4pmx-622h-x359

6 месяцев назад

Mattermost fails to verify run_create permission for empty playbookId

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4pmw-7j2g-cfp7

около 2 лет назад

Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pmw-7hwc-7g5c

больше 4 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pmw-67xf-m59m

больше 4 лет назад

The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid requests. Several areas of the SAP Internet Graphics Server (IGS) did not require sufficient input validation. Namely, the SAP Internet Graphics Server (IGS) HTTP and RFC listener, SAP Internet Graphics Server (IGS) portwatcher when registering a portwatcher to the multiplexer and the SAP Internet Graphics Server (IGS) multiplexer had insufficient input validation and thus allowing a malformed data packet to cause a crash.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4pmv-rc9x-737p

4 месяца назад

InfoScale CmdServer before 7.4.2 mishandles access control.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pmv-pvww-7wmr

около 2 лет назад

The Traffic Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in the 'UserWebStat' AJAX function in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4pp6-84pp-4cqw

A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. A low privileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality, integrity, and availability. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 5 (iLO 5).

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-4pp4-wvvq-cgj8

In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-4pp4-hqhr-q59r

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-4pp4-6fgx-j56f

Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This issue is remediated in version 3.3.0 via safe guards that reject inputs that attempt to do path traversal.

CVSS3: 5.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4pp4-2f6f-77qm

The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.

CVSS3: 9.8
16%
Средний
почти 3 года назад
github логотип
GHSA-4pp2-m693-v6x9

SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4pp2-6v2q-mc4p

Jura E8 devices lack Bluetooth connection security.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pp2-3663-mcw8

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmx-x3px-qgrr

IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4pmx-vh95-832r

Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.

CVSS3: 8.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-4pmx-r8q4-w4vq

Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary code via a crafted encoded authentication request.

69%
Средний
больше 4 лет назад
github логотип
GHSA-4pmx-qx84-x3f4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Community Yard Sale allows Stored XSS.This issue affects Community Yard Sale: from n/a through 1.1.11.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4pmx-jrq3-v88q

The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software before 4.4(3.54) and 4.5 before 4.5(1.45), Cisco TelePresence MSE Supervisor Software before 2.3(1.38), Cisco TelePresence Serial Gateway Series Software before 1.0(1.42), Cisco TelePresence Server Software for Hardware before 3.1(1.98), and Cisco TelePresence Server Software for Virtual Machine before 4.1(1.79) allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors, aka Bug IDs CSCul55968, CSCur08993, CSCur15803, CSCur15807, CSCur15825, CSCur15832, CSCur15842, CSCur15850, and CSCur15855.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmx-grr5-rmvm

Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4pmx-622h-x359

Mattermost fails to verify run_create permission for empty playbookId

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-4pmw-7j2g-cfp7

Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-4pmw-7hwc-7g5c

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmw-67xf-m59m

The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid requests. Several areas of the SAP Internet Graphics Server (IGS) did not require sufficient input validation. Namely, the SAP Internet Graphics Server (IGS) HTTP and RFC listener, SAP Internet Graphics Server (IGS) portwatcher when registering a portwatcher to the multiplexer and the SAP Internet Graphics Server (IGS) multiplexer had insufficient input validation and thus allowing a malformed data packet to cause a crash.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pmv-rc9x-737p

InfoScale CmdServer before 7.4.2 mishandles access control.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-4pmv-pvww-7wmr

The Traffic Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in the 'UserWebStat' AJAX function in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
0%
Низкий
около 2 лет назад

Уязвимостей на страницу