Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 635

Количество 367 635

github логотип

GHSA-45v6-9x5v-7h9m

11 месяцев назад

Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-45v6-42h5-vq5q

больше 4 лет назад

A vulnerability in the web framework of Cisco Unified Communications Manager 11.5(1.10000.6) could allow an authenticated, remote attacker to access arbitrary files in the context of the web root directory structure on an affected device. The vulnerability is due to insufficient input validation by the affected software. An attacker could exploit this vulnerability by using directory traversal techniques to read files in the web root directory structure on the Cisco Unified Communications Manager filesystem. Cisco Bug IDs: CSCve13796.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-45v5-mvm5-gw3v

больше 4 лет назад

The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500, Eudemon1000, Eudemon1000E-U/USG5300, Eudemon1000E-X/USG5500, Eudemon8080E/USG9300, Eudemon8160E/USG9300, Eudemon8000E-X/USG9500, E200E-C/USG2200, E200E-X3/USG2200, E200E-X5/USG2200, E200E-X7/USG2200, E200E-C/USG5100, E200E-X3/USG5100, E200E-X5/USG5100, E200E-X7/USG5100, E200E-B/USG2100, E200E-X1/USG2100, E200E-X2/USG2100, SVN5300, SVN2000, SVN5000, SVN3000, NIP100, NIP200, NIP1000, NIP2100, NIP2200, and NIP5100 use the DES algorithm for stored passwords, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

EPSS: Низкий
github логотип

GHSA-45v5-fv79-85c6

больше 3 лет назад

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. A sandboxed app may be able to determine which app is currently using the camera

CVSS3: 3.6
EPSS: Низкий
github логотип

GHSA-45v5-583j-cjfj

около 4 лет назад

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page of the Engineering portal. An authenticated remote attacker on the local network can inject shell metacharacters into /usr/lib/lua/5.1/luci/controller/admin/settings.lua to achieve remote code execution as root.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-45v5-32pp-w79g

12 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proof Factor LLC Proof Factor – Social Proof Notifications allows Stored XSS. This issue affects Proof Factor – Social Proof Notifications: from n/a through 1.0.5.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-45v4-crhq-rhhc

больше 4 лет назад

NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection.

EPSS: Низкий
github логотип

GHSA-45v4-893g-9x45

почти 2 года назад

Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 allows Object Injection.This issue affects IP Loc8: from n/a through 1.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45v3-x47m-5fcr

больше 4 лет назад

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to including deleting files or causing a denial of service. IBM X-Force ID: 140363.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-45v3-g2v6-9342

больше 4 лет назад

Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-21124.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-45v3-cf2w-246x

больше 4 лет назад

The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

EPSS: Низкий
github логотип

GHSA-45v3-9cr7-qf7v

больше 4 лет назад

Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daemon crash) via an unspecified sequence of FTP commands.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-45v3-38pc-874v

больше 1 года назад

notation-go's timestamp signature generation lacks certificate revocation check

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-45v3-2xjf-j6vx

больше 4 лет назад

In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

EPSS: Низкий
github логотип

GHSA-45v2-7387-4mj3

около 2 лет назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication relations. This could allow an authenticated attacker with the permission to manage devices to gain access to participant groups that the attacked does not belong to.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-45v2-23j7-x684

больше 4 лет назад

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-45rx-ww54-53rf

около 2 месяцев назад

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-45rx-vcq8-mhj9

больше 4 лет назад

An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. Authenticated attackers with the "Operator" Privilege can gain admin privileges via a crafted request to '/goform/formUserMng'.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-45rx-p9fm-3wgm

больше 4 лет назад

Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-45rx-4g83-g5mj

больше 2 лет назад

The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the word_replacer_ultra() function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to update arbitrary content on the affected WordPress site.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-45v6-9x5v-7h9m

Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.

CVSS3: 6.2
0%
Низкий
11 месяцев назад
github логотип
GHSA-45v6-42h5-vq5q

A vulnerability in the web framework of Cisco Unified Communications Manager 11.5(1.10000.6) could allow an authenticated, remote attacker to access arbitrary files in the context of the web root directory structure on an affected device. The vulnerability is due to insufficient input validation by the affected software. An attacker could exploit this vulnerability by using directory traversal techniques to read files in the web root directory structure on the Cisco Unified Communications Manager filesystem. Cisco Bug IDs: CSCve13796.

CVSS3: 6.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-45v5-mvm5-gw3v

The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500, Eudemon1000, Eudemon1000E-U/USG5300, Eudemon1000E-X/USG5500, Eudemon8080E/USG9300, Eudemon8160E/USG9300, Eudemon8000E-X/USG9500, E200E-C/USG2200, E200E-X3/USG2200, E200E-X5/USG2200, E200E-X7/USG2200, E200E-C/USG5100, E200E-X3/USG5100, E200E-X5/USG5100, E200E-X7/USG5100, E200E-B/USG2100, E200E-X1/USG2100, E200E-X2/USG2100, SVN5300, SVN2000, SVN5000, SVN3000, NIP100, NIP200, NIP1000, NIP2100, NIP2200, and NIP5100 use the DES algorithm for stored passwords, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-45v5-fv79-85c6

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. A sandboxed app may be able to determine which app is currently using the camera

CVSS3: 3.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-45v5-583j-cjfj

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page of the Engineering portal. An authenticated remote attacker on the local network can inject shell metacharacters into /usr/lib/lua/5.1/luci/controller/admin/settings.lua to achieve remote code execution as root.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-45v5-32pp-w79g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proof Factor LLC Proof Factor &#8211; Social Proof Notifications allows Stored XSS. This issue affects Proof Factor &#8211; Social Proof Notifications: from n/a through 1.0.5.

CVSS3: 5.9
0%
Низкий
12 месяцев назад
github логотип
GHSA-45v4-crhq-rhhc

NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45v4-893g-9x45

Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 allows Object Injection.This issue affects IP Loc8: from n/a through 1.1.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-45v3-x47m-5fcr

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to including deleting files or causing a denial of service. IBM X-Force ID: 140363.

CVSS3: 7.6
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45v3-g2v6-9342

Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-21124.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45v3-cf2w-246x

The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45v3-9cr7-qf7v

Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daemon crash) via an unspecified sequence of FTP commands.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45v3-38pc-874v

notation-go's timestamp signature generation lacks certificate revocation check

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-45v3-2xjf-j6vx

In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45v2-7387-4mj3

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication relations. This could allow an authenticated attacker with the permission to manage devices to gain access to participant groups that the attacked does not belong to.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-45v2-23j7-x684

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45rx-ww54-53rf

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-45rx-vcq8-mhj9

An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. Authenticated attackers with the "Operator" Privilege can gain admin privileges via a crafted request to '/goform/formUserMng'.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45rx-p9fm-3wgm

Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45rx-4g83-g5mj

The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the word_replacer_ultra() function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to update arbitrary content on the affected WordPress site.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу