Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4cw9-jpqf-99x8

3 месяца назад

A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to use after free. Local access is required to approach this attack. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 3.7-rc is able to address this issue. The name of the patch is fc6d94a9f8a593bd8b7031650802084385d4ee03. The affected component should be upgraded.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-4cw9-fccf-p75x

больше 4 лет назад

The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."

EPSS: Низкий
github логотип

GHSA-4cw9-293h-hh6c

больше 4 лет назад

Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.

EPSS: Низкий
github логотип

GHSA-4cw8-vv94-cqp8

почти 2 года назад

Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cw8-8gfg-9xm5

больше 1 года назад

A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4cw8-47wj-7w4j

6 месяцев назад

A file access issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.4. An attacker may gain access to protected parts of the file system.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4cw7-7qwm-698q

больше 4 лет назад

Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4cw6-2xfr-c3x9

5 дней назад

In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4cw5-g4mj-3m5f

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-4cw5-64wg-w2cj

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Jens Törnell WP Simple Sitemap allows Stored XSS.This issue affects WP Simple Sitemap: from n/a through 0.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4cw5-565x-w786

больше 4 лет назад

Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.

EPSS: Низкий
github логотип

GHSA-4cw5-4fh5-2c5q

9 месяцев назад

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful information, increasing the likelihood of targeted attacks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4cw3-rhqx-vqwr

около 3 лет назад

GilaCMS Cross Site Request Forgery vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cw3-r5gr-2mrh

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-4cw3-p22h-w3h8

7 месяцев назад

A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Performing a manipulation of the argument page results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cw3-5w3j-qjc5

больше 4 лет назад

Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.

EPSS: Низкий
github логотип

GHSA-4cw2-xw5p-h7jf

больше 3 лет назад

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-4cw2-m9qx-j82j

около 2 месяцев назад

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-4cw2-9hrw-wm6g

больше 4 лет назад

WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters in the nginx_webconsole.php Cookie header can be used to read an etc/config/wac/wns_cfg_admin_detail.xml file containing the admin password. (The password for root is the WebUI admin password concatenated with a static string.)

EPSS: Низкий
github логотип

GHSA-4cw2-92vp-ppvp

больше 4 лет назад

There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4cw9-jpqf-99x8

A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to use after free. Local access is required to approach this attack. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 3.7-rc is able to address this issue. The name of the patch is fc6d94a9f8a593bd8b7031650802084385d4ee03. The affected component should be upgraded.

CVSS3: 4.5
0%
Низкий
3 месяца назад
github логотип
GHSA-4cw9-fccf-p75x

The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cw9-293h-hh6c

Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cw8-vv94-cqp8

Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-4cw8-8gfg-9xm5

A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4cw8-47wj-7w4j

A file access issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.4. An attacker may gain access to protected parts of the file system.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-4cw7-7qwm-698q

Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cw6-2xfr-c3x9

In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 3.3
0%
Низкий
5 дней назад
github логотип
GHSA-4cw5-g4mj-3m5f

Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cw5-64wg-w2cj

Cross-Site Request Forgery (CSRF) vulnerability in Jens Törnell WP Simple Sitemap allows Stored XSS.This issue affects WP Simple Sitemap: from n/a through 0.2.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4cw5-565x-w786

Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cw5-4fh5-2c5q

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful information, increasing the likelihood of targeted attacks.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-4cw3-rhqx-vqwr

GilaCMS Cross Site Request Forgery vulnerability

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4cw3-r5gr-2mrh

Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cw3-p22h-w3h8

A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Performing a manipulation of the argument page results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

CVSS3: 8.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-4cw3-5w3j-qjc5

Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4cw2-xw5p-h7jf

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.8
54%
Средний
больше 3 лет назад
github логотип
GHSA-4cw2-m9qx-j82j

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4cw2-9hrw-wm6g

WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters in the nginx_webconsole.php Cookie header can be used to read an etc/config/wac/wns_cfg_admin_detail.xml file containing the admin password. (The password for root is the WebUI admin password concatenated with a static string.)

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4cw2-92vp-ppvp

There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу