Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43p3-6ww8-9fwv

3 месяца назад

An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content during installation.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43p2-q7g7-857m

больше 4 лет назад

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2730.

EPSS: Низкий
github логотип

GHSA-43mx-p8wf-wh27

почти 2 года назад

An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Several configuration statements meant to enforce limits on MAC learning and moves can be configured but do not take effect. This can lead to control plane overload situations which will severely impact the ability of the device to processes legitimate traffic. This issue affects Junos OS Evolved on QFX5000 Series: * All versions before 21.4R3-S8-EVO, * 22.2-EVO versions before 22.2R3-S5-EVO, * 22.4-EVO versions before 22.4R3-EVO, * 23.2-EVO versions before 23.2R2-EVO.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43mx-8xm7-7p46

больше 4 лет назад

AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43mx-35xv-4r2v

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation allows Reflected XSS. This issue affects ReDi Restaurant Reservation: from n/a through 24.1209.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43mw-w97r-j4p7

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tomroyal Stop Registration Spam allows Reflected XSS. This issue affects Stop Registration Spam: from n/a through 1.24.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43mw-858p-8pf4

около 1 года назад

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system wide instead of an account-by-account basis, potentially leading to a Denial of Service (DoS) via resource exhaustion.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43mw-6w68-5pvw

больше 4 лет назад

Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.

EPSS: Критический
github логотип

GHSA-43mv-m2vr-rqqc

больше 4 лет назад

An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-43mv-gcv3-rmpw

больше 4 лет назад

Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.

EPSS: Низкий
github логотип

GHSA-43mv-f787-vp98

больше 4 лет назад

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43mv-86p8-mrjm

около 4 лет назад

WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43mv-63pp-x6jr

больше 2 лет назад

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43mv-4mpj-gj4v

больше 3 лет назад

Visual Studio Remote Code Execution Vulnerability

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-43mr-mm46-m2qq

больше 2 лет назад

A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-43mr-gg87-qwf3

больше 4 лет назад

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.

EPSS: Низкий
github логотип

GHSA-43mq-6xmg-29vm

больше 1 года назад

Apache Struts file upload logic is flawed

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-43mp-rw63-xf4q

больше 4 лет назад

SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-43mp-m7qp-jhq5

больше 4 лет назад

In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result in stack overflow.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-43mm-w7h4-j7r2

11 месяцев назад

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce verification on the `login_form_indieauth()` function and the authorization endpoint at wp-login.php?action=indieauth. This makes it possible for unauthenticated attackers to force authenticated users to approve OAuth authorization requests for attacker-controlled applications via a forged request granted they can trick a user into performing an action such as clicking on a link or visiting a malicious page while logged in. The attacker can then exchange the stolen authorization code for an access token, effectively taking over the victim's account with the granted scopes (create, update, delete).

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43p3-6ww8-9fwv

An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content during installation.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-43p2-q7g7-857m

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2730.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-43mx-p8wf-wh27

An Unimplemented or Unsupported Feature in UI vulnerability in the CLI of Juniper Networks Junos OS Evolved on QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). Several configuration statements meant to enforce limits on MAC learning and moves can be configured but do not take effect. This can lead to control plane overload situations which will severely impact the ability of the device to processes legitimate traffic. This issue affects Junos OS Evolved on QFX5000 Series: * All versions before 21.4R3-S8-EVO, * 22.2-EVO versions before 22.2R3-S5-EVO, * 22.4-EVO versions before 22.4R3-EVO, * 23.2-EVO versions before 23.2R2-EVO.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-43mx-8xm7-7p46

AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43mx-35xv-4r2v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation allows Reflected XSS. This issue affects ReDi Restaurant Reservation: from n/a through 24.1209.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-43mw-w97r-j4p7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tomroyal Stop Registration Spam allows Reflected XSS. This issue affects Stop Registration Spam: from n/a through 1.24.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-43mw-858p-8pf4

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system wide instead of an account-by-account basis, potentially leading to a Denial of Service (DoS) via resource exhaustion.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-43mw-6w68-5pvw

Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified vectors.

92%
Критический
больше 4 лет назад
github логотип
GHSA-43mv-m2vr-rqqc

An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.

CVSS3: 7.5
39%
Средний
больше 4 лет назад
github логотип
GHSA-43mv-gcv3-rmpw

Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43mv-f787-vp98

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-43mv-86p8-mrjm

WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-43mv-63pp-x6jr

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-43mv-4mpj-gj4v

Visual Studio Remote Code Execution Vulnerability

CVSS3: 8.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43mr-mm46-m2qq

A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.

CVSS3: 8.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-43mr-gg87-qwf3

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43mq-6xmg-29vm

Apache Struts file upload logic is flawed

CVSS3: 9.8
78%
Высокий
больше 1 года назад
github логотип
GHSA-43mp-rw63-xf4q

SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-43mp-m7qp-jhq5

In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result in stack overflow.

CVSS3: 7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43mm-w7h4-j7r2

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce verification on the `login_form_indieauth()` function and the authorization endpoint at wp-login.php?action=indieauth. This makes it possible for unauthenticated attackers to force authenticated users to approve OAuth authorization requests for attacker-controlled applications via a forged request granted they can trick a user into performing an action such as clicking on a link or visiting a malicious page while logged in. The attacker can then exchange the stolen authorization code for an access token, effectively taking over the victim's account with the granted scopes (create, update, delete).

CVSS3: 8.8
0%
Низкий
11 месяцев назад

Уязвимостей на страницу