Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-45fw-qrx2-rj7m

больше 4 лет назад

In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45fw-86j8-623x

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a user to visit specific web pages that include malicious payloads. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Cisco has not released software updates that address these vulnerabilities.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-45fw-7wjh-qgj9

почти 2 года назад

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the newProname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-45fw-396c-r96x

больше 4 лет назад

An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45fw-2mcw-h3gw

больше 4 лет назад

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-45fv-hg56-qgcj

около 3 лет назад

The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. This is due to missing or incorrect nonce validation on the save() and export() functions. This makes it possible for unauthenticated attackers to save plugin settings and trigger a data export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-45fv-9g2p-xqxq

больше 4 лет назад

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1200, CVE-2020-1210, CVE-2020-1452, CVE-2020-1576, CVE-2020-1595.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-45fv-8pr3-cvf3

больше 4 лет назад

cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-45fr-w365-f7pm

больше 4 лет назад

Jenkins HockeyApp Plugin stores credentials in plain text

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-45fr-mwhc-fjp4

больше 4 лет назад

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-45fq-3x36-3r59

около 4 лет назад

OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbbb6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-45fp-v65q-47rh

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the object parameter to module/admin_conf/index.php.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-45fm-cfrr-xr5q

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ata: libata-scsi: avoid Non-NCQ command starvation When a non-NCQ command is issued while NCQ commands are being executed, ata_scsi_qc_issue() indicates to the SCSI layer that the command issuing should be deferred by returning SCSI_MLQUEUE_XXX_BUSY. This command deferring is correct and as mandated by the ACS specifications since NCQ and non-NCQ commands cannot be mixed. However, in the case of a host adapter using multiple submission queues, when the target device is under a constant load of NCQ commands, there are no guarantees that requeueing the non-NCQ command will be executed later and it may be deferred again repeatedly as other submission queues can constantly issue NCQ commands from different CPUs ahead of the non-NCQ command. This can lead to very long delays for the execution of non-NCQ commands, and even complete starvation for these commands in the worst case scenario. Since the block layer and th...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-45fj-fvmm-xcc5

6 месяцев назад

Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-45fj-7pmr-8hr5

около 2 месяцев назад

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Graph / Charting). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-45fh-j4qp-56jm

больше 4 лет назад

CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.

EPSS: Низкий
github логотип

GHSA-45fh-g845-pj9w

больше 4 лет назад

Auth0 Passport-SharePoint does not validate JWT signature

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-45fh-9jcx-vccv

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VirusTran Button contact VR allows Stored XSS.This issue affects Button contact VR: from n/a through 4.7.9.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-45fh-4474-xc77

4 месяца назад

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-45fg-96w2-7j5v

больше 4 лет назад

Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-45fw-qrx2-rj7m

In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-45fw-86j8-623x

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a user to visit specific web pages that include malicious payloads. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Cisco has not released software updates that address these vulnerabilities.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-45fw-7wjh-qgj9

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the newProname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-45fw-396c-r96x

An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-45fw-2mcw-h3gw

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-45fv-hg56-qgcj

The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. This is due to missing or incorrect nonce validation on the save() and export() functions. This makes it possible for unauthenticated attackers to save plugin settings and trigger a data export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-45fv-9g2p-xqxq

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1200, CVE-2020-1210, CVE-2020-1452, CVE-2020-1576, CVE-2020-1595.

CVSS3: 8.6
2%
Низкий
больше 4 лет назад
github логотип
GHSA-45fv-8pr3-cvf3

cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).

CVSS3: 6.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45fr-w365-f7pm

Jenkins HockeyApp Plugin stores credentials in plain text

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45fr-mwhc-fjp4

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45fq-3x36-3r59

OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbbb6.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-45fp-v65q-47rh

Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the object parameter to module/admin_conf/index.php.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45fm-cfrr-xr5q

In the Linux kernel, the following vulnerability has been resolved: ata: libata-scsi: avoid Non-NCQ command starvation When a non-NCQ command is issued while NCQ commands are being executed, ata_scsi_qc_issue() indicates to the SCSI layer that the command issuing should be deferred by returning SCSI_MLQUEUE_XXX_BUSY. This command deferring is correct and as mandated by the ACS specifications since NCQ and non-NCQ commands cannot be mixed. However, in the case of a host adapter using multiple submission queues, when the target device is under a constant load of NCQ commands, there are no guarantees that requeueing the non-NCQ command will be executed later and it may be deferred again repeatedly as other submission queues can constantly issue NCQ commands from different CPUs ahead of the non-NCQ command. This can lead to very long delays for the execution of non-NCQ commands, and even complete starvation for these commands in the worst case scenario. Since the block layer and th...

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-45fj-fvmm-xcc5

Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability

0%
Низкий
6 месяцев назад
github логотип
GHSA-45fj-7pmr-8hr5

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Graph / Charting). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-45fh-j4qp-56jm

CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45fh-g845-pj9w

Auth0 Passport-SharePoint does not validate JWT signature

CVSS3: 7.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45fh-9jcx-vccv

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VirusTran Button contact VR allows Stored XSS.This issue affects Button contact VR: from n/a through 4.7.9.1.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-45fh-4474-xc77

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.

CVSS3: 8.2
1%
Низкий
4 месяца назад
github логотип
GHSA-45fg-96w2-7j5v

Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу