Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43qh-4rrx-cfw6

12 месяцев назад

Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management (DPM) functions resulting in an out of bounds read and loss of availability.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-43qg-hpjm-xmxr

больше 4 лет назад

Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.

EPSS: Низкий
github логотип

GHSA-43qf-qj5j-5r47

9 месяцев назад

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43qf-4rqw-9q2g

больше 1 года назад

Flask-CORS vulnerable to Improper Handling of Case Sensitivity

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43qc-p452-9j38

больше 4 лет назад

A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43qc-c2gq-5fq2

24 дня назад

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker (v2.0.22) that listens on all network interfaces with anonymous access enabled and no firewall restriction. An attacker with access to the Bridge's network can read device data and control connected lights.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-43qc-6x8c-rggm

больше 4 лет назад

The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-43qc-57r7-5r46

больше 4 лет назад

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-43q9-x7jp-29r7

больше 4 лет назад

The Celluloid (aka com.eurisko.celluloid) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-43q8-jq5v-77gp

больше 4 лет назад

Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-43q8-3fv7-pr5x

больше 4 лет назад

Improper Validation of Integrity Check Value in TensorFlow

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-43q7-q5vp-3g68

больше 4 лет назад

Path Traversal in Eclipse Mojarra

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43q6-3r5v-55cg

больше 4 лет назад

SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43q4-pf55-3xhc

больше 3 лет назад

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43q2-w229-6g78

около 1 года назад

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43q2-pmmj-8ph8

25 дней назад

Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.

EPSS: Низкий
github логотип

GHSA-43q2-3hxx-r5j2

больше 4 лет назад

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-43px-q73q-v324

больше 2 лет назад

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. Affected is an unknown function of the file /admin/list_localuser.php. The manipulation of the argument ResId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-255300. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-43px-gpwc-q84v

3 месяца назад

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-43px-cc38-6vvc

5 дней назад

LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or network access to enroll a rogue SNMP device can inject malicious JavaScript that executes when admins view affected routing and device pages, enabling credential theft and CSRF token exfiltration.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43qh-4rrx-cfw6

Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management (DPM) functions resulting in an out of bounds read and loss of availability.

CVSS3: 3.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-43qg-hpjm-xmxr

Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43qf-qj5j-5r47

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-43qf-4rqw-9q2g

Flask-CORS vulnerable to Improper Handling of Case Sensitivity

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-43qc-p452-9j38

A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43qc-c2gq-5fq2

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker (v2.0.22) that listens on all network interfaces with anonymous access enabled and no firewall restriction. An attacker with access to the Bridge's network can read device data and control connected lights.

CVSS3: 6.3
0%
Низкий
24 дня назад
github логотип
GHSA-43qc-6x8c-rggm

The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43qc-57r7-5r46

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

CVSS3: 6.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43q9-x7jp-29r7

The Celluloid (aka com.eurisko.celluloid) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43q8-jq5v-77gp

Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-43q8-3fv7-pr5x

Improper Validation of Integrity Check Value in TensorFlow

CVSS3: 7
больше 4 лет назад
github логотип
GHSA-43q7-q5vp-3g68

Path Traversal in Eclipse Mojarra

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-43q6-3r5v-55cg

SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-43q4-pf55-3xhc

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-43q2-w229-6g78

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-43q2-pmmj-8ph8

Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.

0%
Низкий
25 дней назад
github логотип
GHSA-43q2-3hxx-r5j2

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file.

CVSS3: 7.2
4%
Низкий
больше 4 лет назад
github логотип
GHSA-43px-q73q-v324

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. Affected is an unknown function of the file /admin/list_localuser.php. The manipulation of the argument ResId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-255300. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-43px-gpwc-q84v

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-43px-cc38-6vvc

LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or network access to enroll a rogue SNMP device can inject malicious JavaScript that executes when admins view affected routing and device pages, enabling credential theft and CSRF token exfiltration.

0%
Низкий
5 дней назад

Уязвимостей на страницу