Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43vh-22m9-hr9x

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.

EPSS: Низкий
github логотип

GHSA-43vf-866m-gxw3

больше 4 лет назад

Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

EPSS: Низкий
github логотип

GHSA-43vf-7f59-hwgm

больше 4 лет назад

UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43vf-2x6g-p2m5

около 6 лет назад

Malicious Package in browserift

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43vf-262m-2h43

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.

EPSS: Низкий
github логотип

GHSA-43vc-pv65-hrhm

больше 4 лет назад

The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43v9-vxgc-g477

больше 4 лет назад

Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

EPSS: Низкий
github логотип

GHSA-43v9-p898-p49x

больше 4 лет назад

An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43v9-5jqv-2894

больше 4 лет назад

Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors.

EPSS: Низкий
github логотип

GHSA-43v8-mm65-g3xj

6 месяцев назад

ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-43v7-wxwq-5hp3

больше 4 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-43v7-fp2v-68f6

6 месяцев назад

n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-43v6-mq3r-qmhx

около 1 года назад

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43v5-w42f-65jx

больше 4 лет назад

Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.

EPSS: Средний
github логотип

GHSA-43v5-882w-9hpj

больше 3 лет назад

A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-43v5-5g9q-m394

больше 4 лет назад

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "GDI Information Disclosure Vulnerability."

CVSS3: 3.3
EPSS: Средний
github логотип

GHSA-43v3-5j9f-4vh2

около 2 лет назад

IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43v2-6grp-9pp9

больше 4 лет назад

Apache Tomcat does not enforce the maxHttpHeaderSize limit

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43rx-99w7-v5fh

5 месяцев назад

OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling in permission enforcement, allowing attackers who can influence agent tool execution to read arbitrary local files outside the intended repository scope. Attackers can exploit the path parameter not being passed to the PermissionChecker in read_file, write_file, edit_file, and notebook_edit tools to bypass deny rules and access sensitive files such as configuration files, credentials, and SSH material, or create and overwrite files in restricted host paths in full_auto mode.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43rw-xw76-9g92

5 месяцев назад

prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai media status polling that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validation to disclose the FAL_API_KEY in the Authorization header, enabling credential theft, internal network probing, and abuse of the victim's Fal.ai account.

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43vh-22m9-hr9x

Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43vf-866m-gxw3

Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43vf-7f59-hwgm

UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-43vf-2x6g-p2m5

Malicious Package in browserift

CVSS3: 9.8
около 6 лет назад
github логотип
GHSA-43vf-262m-2h43

Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43vc-pv65-hrhm

The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43v9-vxgc-g477

Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43v9-p898-p49x

An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-43v9-5jqv-2894

Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-43v8-mm65-g3xj

ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.

CVSS3: 7.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-43v7-wxwq-5hp3

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-43v7-fp2v-68f6

n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-43v6-mq3r-qmhx

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-43v5-w42f-65jx

Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.

68%
Средний
больше 4 лет назад
github логотип
GHSA-43v5-882w-9hpj

A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.

CVSS3: 4.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43v5-5g9q-m394

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "GDI Information Disclosure Vulnerability."

CVSS3: 3.3
14%
Средний
больше 4 лет назад
github логотип
GHSA-43v3-5j9f-4vh2

IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-43v2-6grp-9pp9

Apache Tomcat does not enforce the maxHttpHeaderSize limit

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-43rx-99w7-v5fh

OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling in permission enforcement, allowing attackers who can influence agent tool execution to read arbitrary local files outside the intended repository scope. Attackers can exploit the path parameter not being passed to the PermissionChecker in read_file, write_file, edit_file, and notebook_edit tools to bypass deny rules and access sensitive files such as configuration files, credentials, and SSH material, or create and overwrite files in restricted host paths in full_auto mode.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-43rw-xw76-9g92

prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai media status polling that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validation to disclose the FAL_API_KEY in the Authorization header, enabling credential theft, internal network probing, and abuse of the victim's Fal.ai account.

CVSS3: 7.7
0%
Низкий
5 месяцев назад

Уязвимостей на страницу