Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4cvm-w5cq-5ghx

около 1 года назад

A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4cvm-fc9f-m7w8

больше 4 лет назад

The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."

EPSS: Низкий
github логотип

GHSA-4cvm-5776-jx9f

больше 4 лет назад

Ansible Arbitrary Code Execution

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cvj-xf75-4wv6

4 месяца назад

A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component Config API Endpoint. The manipulation of the argument kbId leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4cvh-x6jf-8fq3

11 месяцев назад

Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Progress Planner: from n/a through <= 1.8.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cvh-grfr-3h7q

около 3 лет назад

Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2200HP all versions allows a attacker to execute an arbitrary OS command with the root privilege, after obtaining a high privilege exploiting CVE-2023-3330 and CVE-2023-3331 vulnerabilities.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4cvh-cj9w-82gp

больше 4 лет назад

The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving the dl method; and (2) download arbitrary programs onto a client system via vectors involving the SetDLInfo method in conjunction with the Bdl method.

EPSS: Низкий
github логотип

GHSA-4cvg-j32h-gmp6

больше 4 лет назад

PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

EPSS: Низкий
github логотип

GHSA-4cvg-635c-j7v8

больше 4 лет назад

There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cvf-x339-66xj

больше 4 лет назад

Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, DataMatrix.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

EPSS: Низкий
github логотип

GHSA-4cvf-ff56-8rr3

больше 3 лет назад

A vulnerability classified as critical has been found in Simple Art Gallery 1.0. Affected is an unknown function of the file adminHome.php. The manipulation of the argument social_facebook leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223128.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4cvf-99qg-vwq4

больше 4 лет назад

MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.

EPSS: Низкий
github логотип

GHSA-4cvf-2x9p-w298

больше 4 лет назад

SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.

EPSS: Низкий
github логотип

GHSA-4cvc-j8gf-mg3g

около 2 лет назад

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious user. IBM X-Force ID: 295791.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-4cv9-4v3m-jc4x

больше 4 лет назад

Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a denial of service.

EPSS: Низкий
github логотип

GHSA-4cv9-24m8-f6hx

больше 4 лет назад

SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.

EPSS: Низкий
github логотип

GHSA-4cv8-c362-f6hv

больше 4 лет назад

A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 and earlier, CENTUM VP versions R6.03.10 and earlier, CENTUM VP Small versions R6.03.10 and earlier, CENTUM VP Basic versions R6.03.10 and earlier, Exaopc versions R3.75.00 and earlier, B/M9000 CS all versions, and B/M9000 VP versions R8.01.01 and earlier may allow a local attacker to exploit the message management function of the system. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4cv7-w26g-hfm8

5 месяцев назад

Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cv7-c8cq-mg9f

почти 4 года назад

Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4cv6-9jjm-xp2g

около 2 месяцев назад

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4cvm-w5cq-5ghx

A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4cvm-fc9f-m7w8

The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cvm-5776-jx9f

Ansible Arbitrary Code Execution

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cvj-xf75-4wv6

A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component Config API Endpoint. The manipulation of the argument kbId leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4cvh-x6jf-8fq3

Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Progress Planner: from n/a through <= 1.8.0.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-4cvh-grfr-3h7q

Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2200HP all versions allows a attacker to execute an arbitrary OS command with the root privilege, after obtaining a high privilege exploiting CVE-2023-3330 and CVE-2023-3331 vulnerabilities.

CVSS3: 7.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-4cvh-cj9w-82gp

The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving the dl method; and (2) download arbitrary programs onto a client system via vectors involving the SetDLInfo method in conjunction with the Bdl method.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cvg-j32h-gmp6

PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cvg-635c-j7v8

There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.

CVSS3: 8.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-4cvf-x339-66xj

Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, DataMatrix.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-4cvf-ff56-8rr3

A vulnerability classified as critical has been found in Simple Art Gallery 1.0. Affected is an unknown function of the file adminHome.php. The manipulation of the argument social_facebook leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223128.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4cvf-99qg-vwq4

MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cvf-2x9p-w298

SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cvc-j8gf-mg3g

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 temporarily stores data from different environments that could be obtained by a malicious user. IBM X-Force ID: 295791.

CVSS3: 4.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-4cv9-4v3m-jc4x

Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a denial of service.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cv9-24m8-f6hx

SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cv8-c362-f6hv

A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 3000 Small versions R3.09.50 and earlier, CENTUM VP versions R6.03.10 and earlier, CENTUM VP Small versions R6.03.10 and earlier, CENTUM VP Basic versions R6.03.10 and earlier, Exaopc versions R3.75.00 and earlier, B/M9000 CS all versions, and B/M9000 VP versions R8.01.01 and earlier may allow a local attacker to exploit the message management function of the system. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4cv7-w26g-hfm8

Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-4cv7-c8cq-mg9f

Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.

CVSS3: 6.5
2%
Низкий
почти 4 года назад
github логотип
GHSA-4cv6-9jjm-xp2g

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.

0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу