Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 342 247

Количество 342 247

github логотип

GHSA-2pj3-3r8x-phjq

больше 1 года назад

A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2pj2-w39h-8vvq

больше 4 лет назад

Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.

EPSS: Низкий
github логотип

GHSA-2pj2-gchf-wmw7

больше 3 лет назад

Zip4j Origin Validation Error

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2pj2-82cm-7r39

больше 4 лет назад

PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.

EPSS: Низкий
github логотип

GHSA-2phx-w35g-x9vm

больше 4 лет назад

Moodle Weak Password Recovery Mechanism for Forgotten Password

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2phx-jm8v-c5v7

больше 4 лет назад

A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software. The vulnerability is due to incomplete validation of certain commands. An attacker could exploit this vulnerability by first accessing the Guest Shell and then entering specific commands. A successful exploit could allow the attacker to execute arbitrary code on the base Linux operating system.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2phx-frhf-xr55

7 месяцев назад

Mattermost Plugin Zoom allows any logged-in user to change Zoom meeting restrictions for arbitrary channels

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2phw-rgr7-5pvh

больше 3 лет назад

Information Cards Module vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2phw-mm8g-9jp8

около 3 лет назад

OPNsense before 23.7 was discovered to contain insecure permissions in the directory /tmp.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2phw-fwxh-2fw8

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.

EPSS: Низкий
github логотип

GHSA-2phv-qp8w-5cv7

больше 4 лет назад

Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".

EPSS: Низкий
github логотип

GHSA-2phv-j68v-wwqx

8 месяцев назад

pnpm vulnerable to Command Injection via environment variable substitution

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2phr-4qpj-wc46

больше 4 лет назад

Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.

EPSS: Низкий
github логотип

GHSA-2phr-482w-4ppv

почти 4 года назад

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2phq-x5jx-m4c3

больше 4 лет назад

A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2phq-jg7h-ghf4

больше 4 лет назад

Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.

EPSS: Высокий
github логотип

GHSA-2phq-ghf8-6586

больше 4 лет назад

Jenkins Snow Commander Plugin prior to 2.0 vulnerable to Missing Authorization

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2php-v593-f386

11 месяцев назад

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is related to the `ipaddr` request parameter for composing the `"ping -c <counts> <ipaddr> 2>&1 > %s &"` string.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2php-rv2v-c3w8

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a through 1.10.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2php-mg3p-mcqg

больше 3 лет назад

The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pj3-3r8x-phjq

A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2pj2-w39h-8vvq

Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2pj2-gchf-wmw7

Zip4j Origin Validation Error

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2pj2-82cm-7r39

PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2phx-w35g-x9vm

Moodle Weak Password Recovery Mechanism for Forgotten Password

CVSS3: 7.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2phx-jm8v-c5v7

A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software. The vulnerability is due to incomplete validation of certain commands. An attacker could exploit this vulnerability by first accessing the Guest Shell and then entering specific commands. A successful exploit could allow the attacker to execute arbitrary code on the base Linux operating system.

CVSS3: 6.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2phx-frhf-xr55

Mattermost Plugin Zoom allows any logged-in user to change Zoom meeting restrictions for arbitrary channels

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2phw-rgr7-5pvh

Information Cards Module vulnerable to Cross-site Scripting

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2phw-mm8g-9jp8

OPNsense before 23.7 was discovered to contain insecure permissions in the directory /tmp.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2phw-fwxh-2fw8

Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2phv-qp8w-5cv7

Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2phv-j68v-wwqx

pnpm vulnerable to Command Injection via environment variable substitution

CVSS3: 7.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-2phr-4qpj-wc46

Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2phr-482w-4ppv

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2phq-x5jx-m4c3

A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2phq-jg7h-ghf4

Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.

79%
Высокий
больше 4 лет назад
github логотип
GHSA-2phq-ghf8-6586

Jenkins Snow Commander Plugin prior to 2.0 vulnerable to Missing Authorization

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2php-v593-f386

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is related to the `ipaddr` request parameter for composing the `"ping -c <counts> <ipaddr> 2>&1 > %s &"` string.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-2php-rv2v-c3w8

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a through 1.10.1.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2php-mg3p-mcqg

The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу