Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-49wh-vw4x-p83m

больше 4 лет назад

The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-49wh-pf3r-rqvx

больше 4 лет назад

Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

EPSS: Низкий
github логотип

GHSA-49wh-cm7q-9w2h

больше 4 лет назад

Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer dereference vulnerability. An authenticated attacker could leverage this vulnerability achieve an application denial-of-service in the context of the current user. Exploitation of this issue does not requires user interaction.

EPSS: Низкий
github логотип

GHSA-49wh-6wrq-xcjr

больше 4 лет назад

PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg_racine parameter.

EPSS: Низкий
github логотип

GHSA-49wh-353r-wj79

больше 3 лет назад

This candidate was in a CNA pool that was not assigned to any issues during 2021.

EPSS: Низкий
github логотип

GHSA-49wf-927p-jpvj

больше 4 лет назад

OpenFlow plugin for OpenDaylight allows spoofing the SDN topology

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49wc-x7ph-q668

больше 4 лет назад

On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-49wc-943v-whmw

больше 3 лет назад

Windows Secure Channel Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49w9-82cj-xr48

больше 4 лет назад

MantisBT SQL Injection via mc_project_get_users function

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-49w9-5v8p-jcmw

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: spi: sn-f-ospi: Fix division by zero When there is no dummy cycle in the spi-nor commands, both dummy bus cycle bytes and width are zero. Because of the cpu's warning when divided by zero, the warning should be avoided. Return just zero to avoid such calculations.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-49w8-qx9g-ww3r

больше 4 лет назад

Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet.

EPSS: Низкий
github логотип

GHSA-49w7-7c42-5jfv

больше 4 лет назад

The sell function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49w7-5r33-jm9m

больше 2 лет назад

http-swagger XSS via PUT requests

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-49w6-73cw-chjr

больше 1 года назад

Astro's server source code is exposed to the public if sourcemaps are enabled

EPSS: Низкий
github логотип

GHSA-49w6-3ccf-2xg2

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-49w5-c2q7-xqvq

около 3 лет назад

An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted script to the arrays.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49w4-8c2m-qh25

больше 4 лет назад

Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.

EPSS: Низкий
github логотип

GHSA-49w4-256x-6pj9

больше 4 лет назад

An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-49w3-g48r-qp76

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_name, (2) newuser_email, and (3) newuser_hp parameters in the faction=register mode in index.php.

EPSS: Низкий
github логотип

GHSA-49w3-3w9f-g824

25 дней назад

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-49wh-vw4x-p83m

The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-49wh-pf3r-rqvx

Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-49wh-cm7q-9w2h

Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer dereference vulnerability. An authenticated attacker could leverage this vulnerability achieve an application denial-of-service in the context of the current user. Exploitation of this issue does not requires user interaction.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-49wh-6wrq-xcjr

PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg_racine parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-49wh-353r-wj79

This candidate was in a CNA pool that was not assigned to any issues during 2021.

больше 3 лет назад
github логотип
GHSA-49wf-927p-jpvj

OpenFlow plugin for OpenDaylight allows spoofing the SDN topology

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-49wc-x7ph-q668

On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49wc-943v-whmw

Windows Secure Channel Denial of Service Vulnerability

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-49w9-82cj-xr48

MantisBT SQL Injection via mc_project_get_users function

CVSS3: 5.3
5%
Низкий
больше 4 лет назад
github логотип
GHSA-49w9-5v8p-jcmw

In the Linux kernel, the following vulnerability has been resolved: spi: sn-f-ospi: Fix division by zero When there is no dummy cycle in the spi-nor commands, both dummy bus cycle bytes and width are zero. Because of the cpu's warning when divided by zero, the warning should be avoided. Return just zero to avoid such calculations.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-49w8-qx9g-ww3r

Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-49w7-7c42-5jfv

The sell function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49w7-5r33-jm9m

http-swagger XSS via PUT requests

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-49w6-73cw-chjr

Astro's server source code is exposed to the public if sourcemaps are enabled

1%
Низкий
больше 1 года назад
github логотип
GHSA-49w6-3ccf-2xg2

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-49w5-c2q7-xqvq

An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted script to the arrays.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-49w4-8c2m-qh25

Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-49w4-256x-6pj9

An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.

CVSS3: 6.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-49w3-g48r-qp76

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_name, (2) newuser_email, and (3) newuser_hp parameters in the faction=register mode in index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-49w3-3w9f-g824

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 9.1
0%
Низкий
25 дней назад

Уязвимостей на страницу