Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4f63-f425-rwcr

больше 4 лет назад

Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."

EPSS: Средний
github логотип

GHSA-4f63-89w9-3jjv

почти 4 года назад

Using a Custom Cipher with `NID_undef` may lead to NULL encryption

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f62-x2cj-9j6j

больше 4 лет назад

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4f62-jjjx-4hrr

7 месяцев назад

Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through <= 3.7.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f62-c8fw-44pp

больше 4 лет назад

Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4f62-78r3-84fq

около 2 месяцев назад

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f5x-v9cj-7ffr

10 дней назад

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-4f5x-q4jc-xfcf

больше 4 лет назад

Cross-site Scripting in pimcore

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-4f5x-m8xg-x3fm

больше 4 лет назад

Arbitrary File Read in Saperion Web Client version 7.5.2 83166.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f5x-fxpp-vm4x

больше 4 лет назад

myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-4f5x-cggh-2x55

почти 4 года назад

dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4f5x-9vpp-x3hw

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.

EPSS: Низкий
github логотип

GHSA-4f5w-x884-92x8

почти 2 года назад

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4f5w-5x35-7vgh

больше 4 лет назад

An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f5w-5ccj-9j8h

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MorganF Weather Layer allows Stored XSS. This issue affects Weather Layer: from n/a through 4.2.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4f5w-42g5-f95q

8 месяцев назад

Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4f5w-327f-jw8g

больше 1 года назад

An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.

EPSS: Низкий
github логотип

GHSA-4f5v-gcjx-w64x

больше 4 лет назад

A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3). A local attacker with elevated user privileges (manufact) could modify a CRAMFS archive so that after reboot the system loads the modified CRAMFS file and attacker-controlled code is executed with root privileges. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires elevated user privileges (manufact) but no user interaction. The vulnerability could allow an attacker to compromise confidentiality, integrity and availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4f5v-4r5w-g4x3

больше 4 лет назад

Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f5r-h5fc-r77g

больше 4 лет назад

Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f63-f425-rwcr

Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."

21%
Средний
больше 4 лет назад
github логотип
GHSA-4f63-89w9-3jjv

Using a Custom Cipher with `NID_undef` may lead to NULL encryption

CVSS3: 7.5
3%
Низкий
почти 4 года назад
github логотип
GHSA-4f62-x2cj-9j6j

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f62-jjjx-4hrr

Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through <= 3.7.

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-4f62-c8fw-44pp

Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.

CVSS3: 9.8
13%
Средний
больше 4 лет назад
github логотип
GHSA-4f62-78r3-84fq

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-4f5x-v9cj-7ffr

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.

CVSS3: 5
0%
Низкий
10 дней назад
github логотип
GHSA-4f5x-q4jc-xfcf

Cross-site Scripting in pimcore

CVSS3: 6.6
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5x-m8xg-x3fm

Arbitrary File Read in Saperion Web Client version 7.5.2 83166.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5x-fxpp-vm4x

myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5x-cggh-2x55

dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.

CVSS3: 9.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-4f5x-9vpp-x3hw

Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5w-x884-92x8

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.

CVSS3: 7.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-4f5w-5x35-7vgh

An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5w-5ccj-9j8h

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MorganF Weather Layer allows Stored XSS. This issue affects Weather Layer: from n/a through 4.2.1.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-4f5w-42g5-f95q

Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-4f5w-327f-jw8g

An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.

0%
Низкий
больше 1 года назад
github логотип
GHSA-4f5v-gcjx-w64x

A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3). A local attacker with elevated user privileges (manufact) could modify a CRAMFS archive so that after reboot the system loads the modified CRAMFS file and attacker-controlled code is executed with root privileges. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires elevated user privileges (manufact) but no user interaction. The vulnerability could allow an attacker to compromise confidentiality, integrity and availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5v-4r5w-g4x3

Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5r-h5fc-r77g

Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу