Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4f6w-v2mv-qm2r

больше 4 лет назад

One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UART pins without any restrictions, which leads to full system compromise and disclosure of user communications.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4f6v-52xw-69q3

около 1 года назад

An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-4f6r-fq28-v5m3

5 дней назад

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-4f6r-fm5m-93qf

почти 4 года назад

A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processing component.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4f6r-f3wr-x5fw

больше 2 лет назад

The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manger-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4f6r-97c9-vqq2

больше 1 года назад

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4f6q-pc62-pfpp

почти 2 года назад

A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-4f6p-j74c-h2q4

больше 1 года назад

Visual Studio Elevation of Privilege Vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4f6p-h9jv-xcr3

больше 3 лет назад

A vulnerability was found in lmxcms 1.41 and classified as critical. Affected by this issue is the function reply of the file BookAction.class.php. The manipulation of the argument id with the input 1) and updatexml(0,concat(0x7e,user()),1)# leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222728.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f6p-cv97-w83q

больше 4 лет назад

Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr44645, CSCts10195, and CSCts10188.

EPSS: Низкий
github логотип

GHSA-4f6m-rg28-hw58

больше 4 лет назад

IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102.

EPSS: Низкий
github логотип

GHSA-4f6m-8f4h-c96r

больше 4 лет назад

Cross-Site Request Forgery (CSRF) vulnerability discovered in PHP Everywhere (WordPress plugin) versions (<= 2.0.2).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f6j-pw77-g8r4

больше 4 лет назад

ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f6j-fh69-v9rq

больше 4 лет назад

There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24. The key for obfuscating the fingerprint image is vulnerable to brute-force attacks. This allows an attacker to recover the key and decrypt that image using the key. Successful exploitation causes a sensitive biometric information leak.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4f6h-p35h-c9p6

больше 4 лет назад

AlstraSoft Web Host Directory allows remote attackers to obtain sensitive information by requesting any invalid URI, which reveals the path in an error message, a different vulnerability than CVE-2006-2617.

EPSS: Низкий
github логотип

GHSA-4f6h-9vp6-5p6r

больше 4 лет назад

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-4f6g-grvj-2rjg

больше 4 лет назад

BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.

EPSS: Низкий
github логотип

GHSA-4f6g-8xj6-wfjv

больше 4 лет назад

airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f6g-68pf-7vhv

8 месяцев назад

pypdf has possible long runtimes for malformed startxref

EPSS: Низкий
github логотип

GHSA-4f6g-5j2m-r93v

больше 4 лет назад

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Search Functionality). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f6w-v2mv-qm2r

One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UART pins without any restrictions, which leads to full system compromise and disclosure of user communications.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6v-52xw-69q3

An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file.

CVSS3: 5.6
0%
Низкий
около 1 года назад
github логотип
GHSA-4f6r-fq28-v5m3

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

CVSS3: 5.6
0%
Низкий
5 дней назад
github логотип
GHSA-4f6r-fm5m-93qf

A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processing component.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-4f6r-f3wr-x5fw

The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manger-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4f6r-97c9-vqq2

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL.

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4f6q-pc62-pfpp

A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-4f6p-j74c-h2q4

Visual Studio Elevation of Privilege Vulnerability

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4f6p-h9jv-xcr3

A vulnerability was found in lmxcms 1.41 and classified as critical. Affected by this issue is the function reply of the file BookAction.class.php. The manipulation of the argument id with the input 1) and updatexml(0,concat(0x7e,user()),1)# leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222728.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4f6p-cv97-w83q

Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr44645, CSCts10195, and CSCts10188.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6m-rg28-hw58

IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6m-8f4h-c96r

Cross-Site Request Forgery (CSRF) vulnerability discovered in PHP Everywhere (WordPress plugin) versions (<= 2.0.2).

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6j-pw77-g8r4

ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784.

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6j-fh69-v9rq

There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24. The key for obfuscating the fingerprint image is vulnerable to brute-force attacks. This allows an attacker to recover the key and decrypt that image using the key. Successful exploitation causes a sensitive biometric information leak.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6h-p35h-c9p6

AlstraSoft Web Host Directory allows remote attackers to obtain sensitive information by requesting any invalid URI, which reveals the path in an error message, a different vulnerability than CVE-2006-2617.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6h-9vp6-5p6r

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 5.5
69%
Средний
больше 4 лет назад
github логотип
GHSA-4f6g-grvj-2rjg

BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6g-8xj6-wfjv

airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6g-68pf-7vhv

pypdf has possible long runtimes for malformed startxref

0%
Низкий
8 месяцев назад
github логотип
GHSA-4f6g-5j2m-r93v

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Search Functionality). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 4.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу