Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4pjp-5725-8mxh

больше 4 лет назад

A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability is due to a logic error that was introduced in the Cisco IOS XE Software 16.1.1 Release, which prevents the ACL from working when applied against the management interface. An attacker could exploit this issue by attempting to access the device via the management interface.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4pjm-vx4x-rjqf

больше 2 лет назад

Rejected reason: This is unused.

EPSS: Низкий
github логотип

GHSA-4pjm-pq6c-p9x5

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers kvm_io_bus_get_dev() returns a device that is only matched by the address, and nothing else. This can cause a lifetime issue if the matched device is not the expected type, as by the time the caller can introspect the object, it might be gone (the srcu lock having been dropped). Given that there is only a single user of this helper, the simplest option is to move the locking responsibility to the caller, which can keep the srcu lock held for as long as it wants. Note that this aligns with other kvm_io_bus*() helpers, which already require the srcu lock to be held by the callers.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pjm-3hpr-w6j5

больше 4 лет назад

Multiple unspecified vulnerabilities in BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allow remote attackers to access MBean attributes or cause an unspecified denial of service via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-4pjm-38fw-w4gm

больше 2 лет назад

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4pjm-2jf5-8h3g

больше 1 года назад

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. Multiple sub-directories are affected.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4pjj-pmhg-p6q3

больше 4 лет назад

Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords.

EPSS: Низкий
github логотип

GHSA-4pjh-q75h-v94p

3 месяца назад

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4pjh-5r8h-799v

около 4 лет назад

H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4pjg-hm2r-rj25

больше 4 лет назад

The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Control Engine Appliance stores a cleartext password by default, which allows context-dependent attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-4pjg-3rwx-hmxx

больше 4 лет назад

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file.

EPSS: Низкий
github логотип

GHSA-4pjf-x44m-95hq

больше 4 лет назад

It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-4pjf-jwfp-vg6f

больше 4 лет назад

Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4pjf-gx23-qw59

11 месяцев назад

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4pjc-pwgq-q9jp

почти 2 года назад

SiYuan has an SSTI via /api/template/renderSprig

EPSS: Низкий
github логотип

GHSA-4pjc-5g8w-829w

больше 4 лет назад

The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.

EPSS: Низкий
github логотип

GHSA-4pj9-rq3x-vjw5

около 3 лет назад

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pj9-mpj4-ccm8

больше 4 лет назад

Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in api/soap/mc_project_api.php; the (2) news_get_limited_rows function in core/news_api.php; the (3) summary_print_by_enum, (4) summary_print_by_age, (5) summary_print_by_developer, (6) summary_print_by_reporter, or (7) summary_print_by_category function in core/summary_api.php; the (8) create_bug_enum_summary or (9) enum_bug_group function in plugins/MantisGraph/core/graph_api.php; (10) bug_graph_bycategory.php or (11) bug_graph_bystatus.php in plugins/MantisGraph/pages/; or (12) proj_doc_page.php, related to use of the db_query function, a different vulnerability than CVE-2014-1608.

EPSS: Низкий
github логотип

GHSA-4pj9-m96x-crhq

больше 4 лет назад

PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.

EPSS: Низкий
github логотип

GHSA-4pj9-g833-qx53

около 2 месяцев назад

lettre has TLS hostname verification disabled when using Boring TLS backend

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4pjp-5725-8mxh

A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability is due to a logic error that was introduced in the Cisco IOS XE Software 16.1.1 Release, which prevents the ACL from working when applied against the management interface. An attacker could exploit this issue by attempting to access the device via the management interface.

CVSS3: 5.3
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4pjm-vx4x-rjqf

Rejected reason: This is unused.

больше 2 лет назад
github логотип
GHSA-4pjm-pq6c-p9x5

In the Linux kernel, the following vulnerability has been resolved: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers kvm_io_bus_get_dev() returns a device that is only matched by the address, and nothing else. This can cause a lifetime issue if the matched device is not the expected type, as by the time the caller can introspect the object, it might be gone (the srcu lock having been dropped). Given that there is only a single user of this helper, the simplest option is to move the locking responsibility to the caller, which can keep the srcu lock held for as long as it wants. Note that this aligns with other kvm_io_bus*() helpers, which already require the srcu lock to be held by the callers.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4pjm-3hpr-w6j5

Multiple unspecified vulnerabilities in BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allow remote attackers to access MBean attributes or cause an unspecified denial of service via unknown attack vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pjm-38fw-w4gm

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4pjm-2jf5-8h3g

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. Multiple sub-directories are affected.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4pjj-pmhg-p6q3

Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pjh-q75h-v94p

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

CVSS3: 9.8
1%
Низкий
3 месяца назад
github логотип
GHSA-4pjh-5r8h-799v

H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-4pjg-hm2r-rj25

The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Control Engine Appliance stores a cleartext password by default, which allows context-dependent attackers to obtain sensitive information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pjg-3rwx-hmxx

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pjf-x44m-95hq

It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.

CVSS3: 5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pjf-jwfp-vg6f

Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pjf-gx23-qw59

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
11 месяцев назад
github логотип
GHSA-4pjc-pwgq-q9jp

SiYuan has an SSTI via /api/template/renderSprig

1%
Низкий
почти 2 года назад
github логотип
GHSA-4pjc-5g8w-829w

The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pj9-rq3x-vjw5

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-4pj9-mpj4-ccm8

Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in api/soap/mc_project_api.php; the (2) news_get_limited_rows function in core/news_api.php; the (3) summary_print_by_enum, (4) summary_print_by_age, (5) summary_print_by_developer, (6) summary_print_by_reporter, or (7) summary_print_by_category function in core/summary_api.php; the (8) create_bug_enum_summary or (9) enum_bug_group function in plugins/MantisGraph/core/graph_api.php; (10) bug_graph_bycategory.php or (11) bug_graph_bystatus.php in plugins/MantisGraph/pages/; or (12) proj_doc_page.php, related to use of the db_query function, a different vulnerability than CVE-2014-1608.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4pj9-m96x-crhq

PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4pj9-g833-qx53

lettre has TLS hostname verification disabled when using Boring TLS backend

0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу