Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-45gc-6g92-9g2j

больше 4 лет назад

Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-45g9-v625-vr5r

больше 3 лет назад

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45g9-98w8-8m3w

больше 4 лет назад

Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45g8-5xrw-r5wm

больше 4 лет назад

A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists because the affected software insufficiently validates incoming traffic. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to bypass the file and malware inspection policies and send malicious traffic through the affected device.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-45g7-4cgq-4vp4

больше 4 лет назад

Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Jsi_ValueArrayIndex (jsiValue.c:366). The attack vector is: executing crafted javascript code. The fixed version is: after commit 738ead193aff380a7e3d7ffb8e11e446f76867f3.

EPSS: Низкий
github логотип

GHSA-45g7-3c3h-rm3p

больше 4 лет назад

A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45g5-qmv3-9f22

3 месяца назад

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-45g4-mj6j-wggg

около 3 лет назад

A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. VDB-233890 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-45g4-83v3-gcqp

12 месяцев назад

A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and executed when a user or administrator accesses the affected report page. This allows attackers to exfiltrate session cookies, hijack user sessions, and perform unauthorized actions in the context of the victims browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-45g4-3pq8-625w

почти 2 года назад

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-45g3-mf2x-6mxc

больше 4 лет назад

Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.

EPSS: Низкий
github логотип

GHSA-45g3-hwwx-j5r9

больше 4 лет назад

In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45g3-59h2-54v9

больше 4 лет назад

Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.

EPSS: Низкий
github логотип

GHSA-45g3-4pmp-w6x8

больше 4 лет назад

Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.

EPSS: Низкий
github логотип

GHSA-45g2-wqp2-rh43

больше 4 лет назад

SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.

EPSS: Низкий
github логотип

GHSA-45g2-r339-pjwf

около 3 лет назад

Cockpit CMS Cross-Site Request Forgery vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-45g2-pwgf-cj2v

12 месяцев назад

An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-45g2-3cmv-w565

около 1 года назад

In Developer Tools, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-45fx-qq48-m87m

2 месяца назад

FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-45fx-8598-pqhv

больше 2 лет назад

Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-45gc-6g92-9g2j

Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-45g9-v625-vr5r

TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-45g9-98w8-8m3w

Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-45g8-5xrw-r5wm

A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists because the affected software insufficiently validates incoming traffic. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to bypass the file and malware inspection policies and send malicious traffic through the affected device.

CVSS3: 5.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45g7-4cgq-4vp4

Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Jsi_ValueArrayIndex (jsiValue.c:366). The attack vector is: executing crafted javascript code. The fixed version is: after commit 738ead193aff380a7e3d7ffb8e11e446f76867f3.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45g7-3c3h-rm3p

A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45g5-qmv3-9f22

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-45g4-mj6j-wggg

A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. VDB-233890 is the identifier assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-45g4-83v3-gcqp

A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and executed when a user or administrator accesses the affected report page. This allows attackers to exfiltrate session cookies, hijack user sessions, and perform unauthorized actions in the context of the victims browser.

CVSS3: 5.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-45g4-3pq8-625w

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-45g3-mf2x-6mxc

Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-45g3-hwwx-j5r9

In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-45g3-59h2-54v9

Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-45g3-4pmp-w6x8

Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45g2-wqp2-rh43

SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45g2-r339-pjwf

Cockpit CMS Cross-Site Request Forgery vulnerability

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-45g2-pwgf-cj2v

An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-45g2-3cmv-w565

In Developer Tools, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-45fx-qq48-m87m

FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
0%
Низкий
2 месяца назад
github логотип
GHSA-45fx-8598-pqhv

Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу