Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3wvh-wgv4-8fvc

почти 3 года назад

IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation on DPF. IBM X-Force ID: 261607.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-3wvh-ff74-hr6f

больше 4 лет назад

Unspecified vulnerability in the Oracle Application Express component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3wvg-mj6g-m9cv

больше 5 лет назад

Pillow Uncontrolled Resource Consumption

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wvg-3mmq-332j

около 2 лет назад

This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP. Successful exploitation of this vulnerability could allow the attacker to cause Evil Twin attack on the targeted system.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wvf-vrwq-272g

больше 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

EPSS: Низкий
github логотип

GHSA-3wvf-6466-g57r

больше 4 лет назад

PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.

EPSS: Низкий
github логотип

GHSA-3wvf-5qf9-45fj

больше 4 лет назад

IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited directly by authenticated users, or through CSRF.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3wvc-4hf7-ch8v

больше 4 лет назад

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wv8-w3p3-hq59

больше 4 лет назад

gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.

EPSS: Средний
github логотип

GHSA-3wv8-q6g7-7frh

больше 1 года назад

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wv8-g2rv-3w65

больше 4 лет назад

Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now".

EPSS: Низкий
github логотип

GHSA-3wv8-c9pw-2c36

больше 4 лет назад

Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.

EPSS: Средний
github логотип

GHSA-3wv6-pjqx-6927

больше 4 лет назад

The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-3wv5-vww2-4hrq

около 1 месяца назад

Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wv5-4298-pwwf

больше 4 лет назад

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.

EPSS: Низкий
github логотип

GHSA-3wv4-w236-472m

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tomas WordPress Tooltips.This issue affects WordPress Tooltips: from n/a before 9.4.5.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3wv4-m62m-7h6v

почти 4 года назад

Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3wv3-mxjf-7mwp

3 месяца назад

Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wv2-ww7w-98gm

больше 2 лет назад

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view/student_payment_invoice.php. The manipulation of the argument index leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265100.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3wv2-v64p-7q7m

больше 4 лет назад

A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow injections that could lead to XSS attacks if unsuspecting users are tricked into accessing a malicious link.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wvh-wgv4-8fvc

IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation on DPF. IBM X-Force ID: 261607.

CVSS3: 5.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3wvh-ff74-hr6f

Unspecified vulnerability in the Oracle Application Express component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wvg-mj6g-m9cv

Pillow Uncontrolled Resource Consumption

CVSS3: 7.5
5%
Низкий
больше 5 лет назад
github логотип
GHSA-3wvg-3mmq-332j

This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plain text during AP pairing mode. An attacker in close proximity could exploit this vulnerability by capturing Wi-Fi traffic of Airveda-AP. Successful exploitation of this vulnerability could allow the attacker to cause Evil Twin attack on the targeted system.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wvf-vrwq-272g

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wvf-6466-g57r

PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3wvf-5qf9-45fj

IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited directly by authenticated users, or through CSRF.

CVSS3: 8.8
37%
Средний
больше 4 лет назад
github логотип
GHSA-3wvc-4hf7-ch8v

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wv8-w3p3-hq59

gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.

17%
Средний
больше 4 лет назад
github логотип
GHSA-3wv8-q6g7-7frh

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3wv8-g2rv-3w65

Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now".

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wv8-c9pw-2c36

Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.

13%
Средний
больше 4 лет назад
github логотип
GHSA-3wv6-pjqx-6927

The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.

CVSS3: 9.8
72%
Высокий
больше 4 лет назад
github логотип
GHSA-3wv5-vww2-4hrq

Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3wv5-4298-pwwf

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3wv4-w236-472m

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tomas WordPress Tooltips.This issue affects WordPress Tooltips: from n/a before 9.4.5.

CVSS3: 8.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3wv4-m62m-7h6v

Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS3: 6.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3wv3-mxjf-7mwp

Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3wv2-ww7w-98gm

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view/student_payment_invoice.php. The manipulation of the argument index leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265100.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wv2-v64p-7q7m

A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow injections that could lead to XSS attacks if unsuspecting users are tricked into accessing a malicious link.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу