Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4cx5-3q2w-5wr7

около 1 года назад

An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.

EPSS: Низкий
github логотип

GHSA-4cx5-2fr7-x88f

около 2 лет назад

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4cx4-xm36-7hp9

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Marra Smart Mockups allows Stored XSS.This issue affects Smart Mockups: from n/a through 1.2.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4cx4-gv7f-pqv2

3 месяца назад

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cx3-gvx4-j3wg

больше 4 лет назад

A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"

EPSS: Низкий
github логотип

GHSA-4cx3-3c38-j9vv

4 месяца назад

katalyst-koi: Session cookies can be replayed after user logout

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4cx2-fc23-5wg6

около 1 года назад

Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation

EPSS: Низкий
github логотип

GHSA-4cx2-827f-fp6c

больше 4 лет назад

Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.

EPSS: Низкий
github логотип

GHSA-4cx2-4xxw-gpfv

больше 4 лет назад

JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.

EPSS: Низкий
github логотип

GHSA-4cwx-xrxh-9ff7

больше 4 лет назад

An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. ROS_ASSERT_MSG only works when ROS_ASSERT_ENABLED is defined. This leads to a problem in the remove() function in clients/roscpp/src/libros/spinner.cpp. When ROS_ASSERT_ENABLED is not defined, the iterator loop will run out of the scope of the array, and cause denial of service for other components (that depend on the communication-related functions of this package).

EPSS: Низкий
github логотип

GHSA-4cwx-r6vp-5886

больше 4 лет назад

A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processing that occurs when establishing a DTLS tunnel as part of an AnyConnect SSL VPN connection. An attacker could exploit this vulnerability by sending a steady stream of crafted DTLS traffic to an affected device. A successful exploit could allow the attacker to exhaust resources on the affected VPN headend device. This could cause existing DTLS tunnels to stop passing traffic and prevent new DTLS tunnels from establishing, resulting in a DoS condition. Note: When the attack traffic stops, the device recovers gracefully.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cwx-j38m-p4pm

больше 4 лет назад

Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary files via the ExportSettings method.

EPSS: Низкий
github логотип

GHSA-4cwx-87j2-xc8v

почти 4 года назад

** UNSUPPPORTED WHEN ASSIGNED **Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4cwx-7wf7-3272

около 1 месяца назад

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4cww-rww7-fw7q

около 1 года назад

A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process. Additionally, virtual machine images built using the Nutanix or the OVA provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their Windows nodes use VM images created via the Image Builder project with its Nutanix or OVA provider.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cww-f7w5-x525

около 5 лет назад

Stack consumption in trust-dns-server

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cww-8m8h-fvjq

больше 4 лет назад

Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot) and encoded / (%2f) sequence in the URL.

EPSS: Низкий
github логотип

GHSA-4cwv-p4c3-xrh9

почти 4 года назад

Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4cwr-vwjh-j2gw

почти 4 года назад

Active Directory Domain Services Elevation of Privilege Vulnerability.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4cwr-jp57-8cx6

больше 1 года назад

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4cx5-3q2w-5wr7

An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.

0%
Низкий
около 1 года назад
github логотип
GHSA-4cx5-2fr7-x88f

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-4cx4-xm36-7hp9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Marra Smart Mockups allows Stored XSS.This issue affects Smart Mockups: from n/a through 1.2.0.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4cx4-gv7f-pqv2

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4cx3-gvx4-j3wg

A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4cx3-3c38-j9vv

katalyst-koi: Session cookies can be replayed after user logout

CVSS3: 7.4
0%
Низкий
4 месяца назад
github логотип
GHSA-4cx2-fc23-5wg6

Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation

0%
Низкий
около 1 года назад
github логотип
GHSA-4cx2-827f-fp6c

Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cx2-4xxw-gpfv

JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwx-xrxh-9ff7

An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. ROS_ASSERT_MSG only works when ROS_ASSERT_ENABLED is defined. This leads to a problem in the remove() function in clients/roscpp/src/libros/spinner.cpp. When ROS_ASSERT_ENABLED is not defined, the iterator loop will run out of the scope of the array, and cause denial of service for other components (that depend on the communication-related functions of this package).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwx-r6vp-5886

A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processing that occurs when establishing a DTLS tunnel as part of an AnyConnect SSL VPN connection. An attacker could exploit this vulnerability by sending a steady stream of crafted DTLS traffic to an affected device. A successful exploit could allow the attacker to exhaust resources on the affected VPN headend device. This could cause existing DTLS tunnels to stop passing traffic and prevent new DTLS tunnels from establishing, resulting in a DoS condition. Note: When the attack traffic stops, the device recovers gracefully.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwx-j38m-p4pm

Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary files via the ExportSettings method.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwx-87j2-xc8v

** UNSUPPPORTED WHEN ASSIGNED **Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

CVSS3: 9.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-4cwx-7wf7-3272

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

CVSS3: 7.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4cww-rww7-fw7q

A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process. Additionally, virtual machine images built using the Nutanix or the OVA provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their Windows nodes use VM images created via the Image Builder project with its Nutanix or OVA provider.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4cww-f7w5-x525

Stack consumption in trust-dns-server

CVSS3: 7.5
1%
Низкий
около 5 лет назад
github логотип
GHSA-4cww-8m8h-fvjq

Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot) and encoded / (%2f) sequence in the URL.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwv-p4c3-xrh9

Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-4cwr-vwjh-j2gw

Active Directory Domain Services Elevation of Privilege Vulnerability.

CVSS3: 7.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-4cwr-jp57-8cx6

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004.

CVSS3: 9.1
1%
Низкий
больше 1 года назад

Уязвимостей на страницу