Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 087

Количество 366 087

github логотип

GHSA-3xxc-c29x-7gmx

около 3 лет назад

Windows OLE Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3xx9-m5h3-7jrq

больше 4 лет назад

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear 19.3.0 library. A specially crafted GEM file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3xx9-5w7v-mp8g

больше 4 лет назад

A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then control what memory regions will be freed and cause use-after-free condition.

EPSS: Низкий
github логотип

GHSA-3xx8-v4vj-2v2m

больше 4 лет назад

Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3xx8-jmfq-qf34

больше 1 года назад

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3xx8-9wcm-jhmc

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersion parameter to server/admin_console/web/tools/bigRedButton.php; the (3) partnerId, (4) playerVersion, (5) secret, (6) entryId, (7) adminUiConfId, or (8) uiConfId parameter to server/admin_console/web/tools/bigRedButtonPtsPoc.php; the (9) streamUsername, (10) streamPassword, (11) streamRemoteId, (12) streamRemoteBackupId, or (13) entryId parameter to server/admin_console/web/tools/AkamaiBroadcaster.php; the (14) entryId parameter to server/admin_console/web/tools/XmlJWPlayer.php; or the (15) partnerId or (16) playerVersion parameter to server/alpha/web/lib/bigRedButtonPtsPocHlsjs.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3xx8-2m7h-8rhw

больше 4 лет назад

paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, (4) main.php, (5) viewall.php, (6) download.php, (7) email.php, (8) file.php, (9) rate.php, or (10) stats.php, which reveals the path in an error message.

EPSS: Низкий
github логотип

GHSA-3xx7-wxpj-hg7p

больше 4 лет назад

Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.

EPSS: Низкий
github логотип

GHSA-3xx7-g9gf-wrw5

больше 4 лет назад

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

EPSS: Низкий
github логотип

GHSA-3xx5-g4fv-w39v

больше 4 лет назад

A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a race condition could cause an object to be released before being operated on, leading to NULL pointer deference condition and causing the application to crash. An attacker could leverage this vulnerability to cause a Denial-of-Service condition in the application.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3xx3-2m5h-mj67

больше 4 лет назад

A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local attacker to access information stored in the file system of an affected system, aka Unauthorized Directory Access. More Information: CSCvd76286. Known Affected Releases: 2.2(9.76) 2.3(1).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3xx2-mqjm-hg9x

5 месяцев назад

Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3xwx-cwrm-pvfj

больше 4 лет назад

includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses.

EPSS: Низкий
github логотип

GHSA-3xww-gg44-m2qc

около 2 лет назад

An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3xwr-xcmc-7vq6

около 3 лет назад

A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the server's web server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xwr-pg9v-wcpj

больше 4 лет назад

Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-3xwr-fvj3-vh37

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in searchAction.do in ManageEngine EventLog Analyzer 5 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Fixed in EventLog Analyzer 10.0 Build 10000.

EPSS: Низкий
github логотип

GHSA-3xwr-f848-5v5p

почти 2 года назад

A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3xwr-94c9-8hpg

больше 4 лет назад

SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-3xwr-4jwq-c855

больше 4 лет назад

A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious DLL.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3xxc-c29x-7gmx

Windows OLE Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-3xx9-m5h3-7jrq

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear 19.3.0 library. A specially crafted GEM file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3xx9-5w7v-mp8g

A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then control what memory regions will be freed and cause use-after-free condition.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xx8-v4vj-2v2m

Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xx8-jmfq-qf34

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify application data. We have already fixed the vulnerability in the following versions: QTS 5.2.3.3006 build 20250108 and later QuTS hero h5.2.3.3006 build 20250108 and later

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3xx8-9wcm-jhmc

Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersion parameter to server/admin_console/web/tools/bigRedButton.php; the (3) partnerId, (4) playerVersion, (5) secret, (6) entryId, (7) adminUiConfId, or (8) uiConfId parameter to server/admin_console/web/tools/bigRedButtonPtsPoc.php; the (9) streamUsername, (10) streamPassword, (11) streamRemoteId, (12) streamRemoteBackupId, or (13) entryId parameter to server/admin_console/web/tools/AkamaiBroadcaster.php; the (14) entryId parameter to server/admin_console/web/tools/XmlJWPlayer.php; or the (15) partnerId or (16) playerVersion parameter to server/alpha/web/lib/bigRedButtonPtsPocHlsjs.php.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3xx8-2m7h-8rhw

paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, (4) main.php, (5) viewall.php, (6) download.php, (7) email.php, (8) file.php, (9) rate.php, or (10) stats.php, which reveals the path in an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xx7-wxpj-hg7p

Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xx7-g9gf-wrw5

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xx5-g4fv-w39v

A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a race condition could cause an object to be released before being operated on, leading to NULL pointer deference condition and causing the application to crash. An attacker could leverage this vulnerability to cause a Denial-of-Service condition in the application.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3xx3-2m5h-mj67

A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local attacker to access information stored in the file system of an affected system, aka Unauthorized Directory Access. More Information: CSCvd76286. Known Affected Releases: 2.2(9.76) 2.3(1).

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3xx2-mqjm-hg9x

Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise

CVSS3: 9.9
5 месяцев назад
github логотип
GHSA-3xwx-cwrm-pvfj

includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3xww-gg44-m2qc

An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

CVSS3: 8.8
14%
Средний
около 2 лет назад
github логотип
GHSA-3xwr-xcmc-7vq6

A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the server's web server.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-3xwr-pg9v-wcpj

Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3xwr-fvj3-vh37

Cross-site scripting (XSS) vulnerability in searchAction.do in ManageEngine EventLog Analyzer 5 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Fixed in EventLog Analyzer 10.0 Build 10000.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xwr-f848-5v5p

A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-3xwr-94c9-8hpg

SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xwr-4jwq-c855

A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious DLL.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу