Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4g4c-8gqh-m4vm

около 7 лет назад

paranoid2 gem Code backdoor

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g4c-285h-w45p

около 2 лет назад

A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_payment.php. The manipulation of the argument ef_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272579.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4g49-qqgp-g5cv

больше 4 лет назад

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent from CVE-2019-18311. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

EPSS: Низкий
github логотип

GHSA-4g49-fgg9-9m4w

больше 4 лет назад

Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."

EPSS: Низкий
github логотип

GHSA-4g48-xcj2-xjr4

больше 4 лет назад

Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list containing a long line.

EPSS: Низкий
github логотип

GHSA-4g48-m7qw-9j6j

больше 4 лет назад

Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4g48-c9r3-fjv8

больше 2 лет назад

Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file creation.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4g48-54q2-fg7q

5 месяцев назад

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4g48-423m-8v44

12 месяцев назад

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers entry granting that account passwordless root privileges (ubuntu ALL=(ALL) NOPASSWD: ALL). Anyone who knows the hardcoded password can obtain root privileges via local console or equivalent administrative access, enabling local privilege escalation. NOTE: The patch for this vulnerability is reported to be incomplete: /etc/shadow was remediated but /etc/sudoers remains vulnerable.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g47-3fx3-5q52

больше 4 лет назад

In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.

EPSS: Низкий
github логотип

GHSA-4g46-5grc-wq49

больше 6 лет назад

Cross-Site Scripting in seeftl

EPSS: Низкий
github логотип

GHSA-4g45-vj69-x97c

больше 4 лет назад

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020).

EPSS: Низкий
github логотип

GHSA-4g45-rw93-8jmc

больше 4 лет назад

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g44-xjmc-rxcq

больше 4 лет назад

Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to gain elevated privileges via the GUI or GUI terminal commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g44-cv7p-fgrg

3 месяца назад

In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4g44-5j4j-c7x6

больше 4 лет назад

In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g44-2wm9-33xf

больше 4 лет назад

The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4g43-pmw7-v27w

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2().

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4g43-jcgp-9p5g

больше 4 лет назад

Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests.

EPSS: Низкий
github логотип

GHSA-4g42-x277-3hhc

больше 4 лет назад

A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4g4c-8gqh-m4vm

paranoid2 gem Code backdoor

CVSS3: 9.8
4%
Низкий
около 7 лет назад
github логотип
GHSA-4g4c-285h-w45p

A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_payment.php. The manipulation of the argument ef_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272579.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-4g49-qqgp-g5cv

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent from CVE-2019-18311. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g49-fgg9-9m4w

Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g48-xcj2-xjr4

Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list containing a long line.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g48-m7qw-9j6j

Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g48-c9r3-fjv8

Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file creation.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4g48-54q2-fg7q

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

CVSS3: 6.5
1%
Низкий
5 месяцев назад
github логотип
GHSA-4g48-423m-8v44

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers entry granting that account passwordless root privileges (ubuntu ALL=(ALL) NOPASSWD: ALL). Anyone who knows the hardcoded password can obtain root privileges via local console or equivalent administrative access, enabling local privilege escalation. NOTE: The patch for this vulnerability is reported to be incomplete: /etc/shadow was remediated but /etc/sudoers remains vulnerable.

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-4g47-3fx3-5q52

In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4g46-5grc-wq49

Cross-Site Scripting in seeftl

1%
Низкий
больше 6 лет назад
github логотип
GHSA-4g45-vj69-x97c

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4g45-rw93-8jmc

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g44-xjmc-rxcq

Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to gain elevated privileges via the GUI or GUI terminal commands.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g44-cv7p-fgrg

In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4g44-5j4j-c7x6

In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-4g44-2wm9-33xf

The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g43-pmw7-v27w

In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_read_lock()/rcu_read_unlock() pairs from ip6_finish_output2().

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-4g43-jcgp-9p5g

Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g42-x277-3hhc

A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу