Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 528

Количество 373 528

github логотип

GHSA-4jh8-xj74-jhxx

7 месяцев назад

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4jh8-f2cr-j6hg

больше 4 лет назад

Multiple "overflows" in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-4jh8-5fmv-rj32

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in core/handleTw.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4jh7-wh4m-f4pq

больше 4 лет назад

Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension restrictions of third-party upload applications via a filename with a (1) .asp, (2) .cer, or (3) .asa first extension, followed by a semicolon and a safe extension, as demonstrated by the use of asp.dll to handle a .asp;.jpg file.

EPSS: Средний
github логотип

GHSA-4jh7-m9q3-3qw9

около 2 лет назад

CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4jh7-c2vv-7qf2

больше 1 года назад

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus < 138.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4jh7-7xmh-98px

больше 4 лет назад

A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17.

EPSS: Низкий
github логотип

GHSA-4jh6-hfr3-fg82

больше 4 лет назад

The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.

EPSS: Низкий
github логотип

GHSA-4jh6-gx4g-g6m8

11 месяцев назад

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-4jh6-gh8q-jcwr

больше 4 лет назад

Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

EPSS: Низкий
github логотип

GHSA-4jh6-6j22-8j58

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects Mediawiki - MassEditRegex Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-4jh5-ggm8-wxch

больше 4 лет назад

Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

EPSS: Низкий
github логотип

GHSA-4jh5-9c29-9299

больше 4 лет назад

Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.

EPSS: Низкий
github логотип

GHSA-4jh5-95f7-hf6w

больше 1 года назад

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl with the input getInitCfg/getSysStatusCfg leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-4jh4-xcv6-j74j

больше 4 лет назад

Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-4jh4-mwq8-wx24

почти 3 года назад

The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4jh4-4vjf-72wq

больше 4 лет назад

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:559:29.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4jh3-6jhv-2mgp

больше 2 лет назад

react-native-mmkv Insertion of Sensitive Information into Log File vulnerability

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4jh3-696v-qm6r

больше 4 лет назад

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4jh2-4rxm-r2jw

больше 4 лет назад

SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4jh8-xj74-jhxx

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options

CVSS3: 9.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-4jh8-f2cr-j6hg

Multiple "overflows" in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh8-5fmv-rj32

Cross-site scripting (XSS) vulnerability in core/handleTw.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh7-wh4m-f4pq

Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension restrictions of third-party upload applications via a filename with a (1) .asp, (2) .cer, or (3) .asa first extension, followed by a semicolon and a safe extension, as demonstrated by the use of asp.dll to handle a .asp;.jpg file.

64%
Средний
больше 4 лет назад
github логотип
GHSA-4jh7-m9q3-3qw9

CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-4jh7-c2vv-7qf2

Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus < 138.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4jh7-7xmh-98px

A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh6-hfr3-fg82

The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh6-gx4g-g6m8

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

CVSS3: 9
1%
Низкий
11 месяцев назад
github логотип
GHSA-4jh6-gh8q-jcwr

Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh6-6j22-8j58

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects Mediawiki - MassEditRegex Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

CVSS3: 5.6
0%
Низкий
около 1 года назад
github логотип
GHSA-4jh5-ggm8-wxch

Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh5-9c29-9299

Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh5-95f7-hf6w

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl with the input getInitCfg/getSysStatusCfg leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
13%
Средний
больше 1 года назад
github логотип
GHSA-4jh4-xcv6-j74j

Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh4-mwq8-wx24

The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.

CVSS3: 7.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-4jh4-4vjf-72wq

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:559:29.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh3-6jhv-2mgp

react-native-mmkv Insertion of Sensitive Information into Log File vulnerability

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4jh3-696v-qm6r

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4jh2-4rxm-r2jw

SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу