Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4f7q-xq4j-fmj8

больше 4 лет назад

Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap app. Administration role is necessary for exploitation.

EPSS: Низкий
github логотип

GHSA-4f7q-fvgr-jx57

больше 4 лет назад

The TV Bengali Open Directory (aka com.TVBengali) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4f7p-mhh6-p6r7

больше 4 лет назад

The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f7p-jr5x-cg78

больше 1 года назад

Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f7p-398v-2rw7

больше 1 года назад

A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication in an API endpoint. An attacker could exploit this vulnerability by sending a request to the affected API of a Catalyst Center device. A successful exploit could allow the attacker to view or modify the outgoing proxy configuration, which could disrupt internet traffic from Cisco Catalyst Center or may allow the attacker to intercept outbound internet traffic.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4f7p-27jc-3c36

больше 4 лет назад

HTTP Request Smuggling in waitress

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f7m-v6hv-9hcr

больше 1 года назад

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f7m-gcp2-rqr8

больше 4 лет назад

EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administrators to bypass a SmartLock root-login restriction by creating a root account and establishing a login session.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4f7j-xf8r-8572

почти 3 года назад

Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f7j-px6v-m38x

больше 1 года назад

Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4f7j-5j3r-xxc5

больше 4 лет назад

Certain NETGEAR devices are affected by stored XSS. This affects D6100 before 1.0.0.63, DM200 before 1.0.0.61, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before 1.0.4.12, WN3000RPv2 before 1.0.0.68, and WNR2000v5 before 1.0.0.66.

EPSS: Низкий
github логотип

GHSA-4f7h-9j2x-cmr4

больше 4 лет назад

Improper Authentication in Apache Tomcat

EPSS: Низкий
github логотип

GHSA-4f7g-mqhx-8h4r

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a possible memory leak In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails driver is not freeing the memory allocated for "rdev->chip_ctx".

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4f7g-j96w-63jv

около 3 лет назад

Remote Procedure Call Runtime Denial of Service Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4f7g-c479-3cx4

больше 4 лет назад

SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4f7c-pmjv-c25w

5 месяцев назад

Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4f7c-mrrq-rv96

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.

EPSS: Низкий
github логотип

GHSA-4f7c-f5r2-23hx

больше 4 лет назад

Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.

EPSS: Низкий
github логотип

GHSA-4f7c-7x79-wr4p

около 1 года назад

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-4f7c-6xx9-hvm8

около 1 года назад

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f7q-xq4j-fmj8

Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap app. Administration role is necessary for exploitation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7q-fvgr-jx57

The TV Bengali Open Directory (aka com.TVBengali) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7p-mhh6-p6r7

The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7p-jr5x-cg78

Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4f7p-398v-2rw7

A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication in an API endpoint. An attacker could exploit this vulnerability by sending a request to the affected API of a Catalyst Center device. A successful exploit could allow the attacker to view or modify the outgoing proxy configuration, which could disrupt internet traffic from Cisco Catalyst Center or may allow the attacker to intercept outbound internet traffic.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4f7p-27jc-3c36

HTTP Request Smuggling in waitress

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7m-v6hv-9hcr

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4f7m-gcp2-rqr8

EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administrators to bypass a SmartLock root-login restriction by creating a root account and establishing a login session.

CVSS3: 8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7j-xf8r-8572

Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4f7j-px6v-m38x

Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4f7j-5j3r-xxc5

Certain NETGEAR devices are affected by stored XSS. This affects D6100 before 1.0.0.63, DM200 before 1.0.0.61, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before 1.0.4.12, WN3000RPv2 before 1.0.0.68, and WNR2000v5 before 1.0.0.66.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7h-9j2x-cmr4

Improper Authentication in Apache Tomcat

7%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7g-mqhx-8h4r

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a possible memory leak In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails driver is not freeing the memory allocated for "rdev->chip_ctx".

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4f7g-j96w-63jv

Remote Procedure Call Runtime Denial of Service Vulnerability

CVSS3: 6.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-4f7g-c479-3cx4

SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7c-pmjv-c25w

Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters

CVSS3: 5.3
1%
Низкий
5 месяцев назад
github логотип
GHSA-4f7c-mrrq-rv96

Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7c-f5r2-23hx

Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f7c-7x79-wr4p

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

CVSS3: 5
0%
Низкий
около 1 года назад
github логотип
GHSA-4f7c-6xx9-hvm8

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.

около 1 года назад

Уязвимостей на страницу