Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4f8m-7h83-9f6m

около 3 лет назад

XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4f8m-5f89-p953

больше 4 лет назад

curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f8j-vhh2-g372

8 месяцев назад

SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/edit_config_files to access and modify files outside the intended /etc/config/ directory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4f8j-fccm-mr22

больше 4 лет назад

The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed).

EPSS: Низкий
github логотип

GHSA-4f8j-4r9h-5jxr

почти 2 года назад

DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_top10.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f8j-483g-w9w4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

EPSS: Низкий
github логотип

GHSA-4f8j-3ph5-xq82

27 дней назад

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f8h-hq55-xrp6

8 месяцев назад

An issue in nanomq v0.22.7 allows attackers to cause a Denial of Service (DoS) via a crafted request. The number of data packets received in the recv-q queue of the Nanomq process continues to increase, causing the nanomq broker to fall into a deadlock and be unable to provide normal services.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f8g-r594-5rqr

больше 4 лет назад

Unspecified vulnerability in Oracle Sun Solaris 8 and 9 allows local users to affect confidentiality and integrity via unknown vectors related to sort.

EPSS: Низкий
github логотип

GHSA-4f8g-q626-3w4p

больше 4 лет назад

MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.

EPSS: Низкий
github логотип

GHSA-4f8g-fq6x-jqrr

больше 3 лет назад

org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f8g-77mw-3rxc

5 месяцев назад

OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4f8f-mxjm-p699

больше 4 лет назад

LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data exfiltration.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4f8f-h23v-qmv8

больше 4 лет назад

Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.

EPSS: Низкий
github логотип

GHSA-4f89-5cwm-rm5g

почти 2 года назад

Magento Open Source Information Exposure vulnerability

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-4f88-x3x5-4xc4

больше 4 лет назад

An issue was discovered in Adobe InDesign 12.1.0 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f87-mww8-gm8x

больше 4 лет назад

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f86-7p6f-wpvq

больше 4 лет назад

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-4f85-wphf-9gf3

больше 4 лет назад

Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of packets with 0xFF characters to the Telnet port (TCP 23), which corrupts the heap.

EPSS: Низкий
github логотип

GHSA-4f85-23vm-r4hq

8 месяцев назад

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘options’ parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NOTE: Successful exploitation of this vulnerability requires that the PDFCrowd API key is blank (also known as "demo mode", which is the default configuration when the plugin is installed) or known.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f8m-7h83-9f6m

XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action

CVSS3: 8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4f8m-5f89-p953

curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8j-vhh2-g372

SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/edit_config_files to access and modify files outside the intended /etc/config/ directory.

CVSS3: 6.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-4f8j-fccm-mr22

The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8j-4r9h-5jxr

DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_top10.php.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-4f8j-483g-w9w4

Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8j-3ph5-xq82

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
0%
Низкий
27 дней назад
github логотип
GHSA-4f8h-hq55-xrp6

An issue in nanomq v0.22.7 allows attackers to cause a Denial of Service (DoS) via a crafted request. The number of data packets received in the recv-q queue of the Nanomq process continues to increase, causing the nanomq broker to fall into a deadlock and be unable to provide normal services.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-4f8g-r594-5rqr

Unspecified vulnerability in Oracle Sun Solaris 8 and 9 allows local users to affect confidentiality and integrity via unknown vectors related to sort.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8g-q626-3w4p

MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8g-fq6x-jqrr

org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4f8g-77mw-3rxc

OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`

CVSS3: 7.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-4f8f-mxjm-p699

LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data exfiltration.

CVSS3: 3.3
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8f-h23v-qmv8

Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4f89-5cwm-rm5g

Magento Open Source Information Exposure vulnerability

CVSS3: 2.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-4f88-x3x5-4xc4

An issue was discovered in Adobe InDesign 12.1.0 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4f87-mww8-gm8x

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f86-7p6f-wpvq

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f85-wphf-9gf3

Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of packets with 0xFF characters to the Telnet port (TCP 23), which corrupts the heap.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4f85-23vm-r4hq

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘options’ parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NOTE: Successful exploitation of this vulnerability requires that the PDFCrowd API key is blank (also known as "demo mode", which is the default configuration when the plugin is installed) or known.

CVSS3: 6.1
0%
Низкий
8 месяцев назад

Уязвимостей на страницу