Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3wjq-jhph-jc7q

больше 1 года назад

A vulnerability, which was classified as problematic, was found in Trimble SPS851 488.01. This affects an unknown part of the component Ethernet Configuration Menu. The manipulation of the argument Hostname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-3wjq-88q9-5hmg

больше 4 лет назад

An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.18. Android ID: A-31251973. References: N-CVE-2016-6789.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wjp-x9vq-q628

6 месяцев назад

A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php. This manipulation of the argument st_name causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-3wjp-mcmp-h4xw

больше 4 лет назад

Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275.

EPSS: Низкий
github логотип

GHSA-3wjp-87jx-r4pv

6 месяцев назад

A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/models/TodoList.ts of the component API Endpoint. The manipulation of the argument userId leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3wjp-7h53-cfv8

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix hang in usb_kill_urb by adding memory barriers The syzbot fuzzer has identified a bug in which processes hang waiting for usb_kill_urb() to return. It turns out the issue is not unlinking the URB; that works just fine. Rather, the problem arises when the wakeup notification that the URB has completed is not received. The reason is memory-access ordering on SMP systems. In outline form, usb_kill_urb() and __usb_hcd_giveback_urb() operating concurrently on different CPUs perform the following actions: CPU 0 CPU 1 ---------------------------- --------------------------------- usb_kill_urb(): __usb_hcd_giveback_urb(): ... ... atomic_inc(&urb->reject); atomic_dec(&urb->use_count); ... ... wait_event(usb_kill_urb_queue, atomic_read(&urb->use_count) == 0); if (atomic_read(&urb->reject)) wake_up(&usb_kill_urb_queue); Confining your attention to urb->reject ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3wjp-774c-xvqr

2 месяца назад

Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wjm-qx5r-4845

больше 2 лет назад

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-3wjm-5g86-c6p3

4 месяца назад

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3wjm-33mw-h388

около 6 лет назад

Malicious Package in s3asy

EPSS: Низкий
github логотип

GHSA-3wjj-6pp2-788h

3 месяца назад

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This issue affects ArcGIS Server 12.0 and earlier.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wjh-xpx4-2h8c

больше 4 лет назад

PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.

EPSS: Низкий
github логотип

GHSA-3wjh-qhxw-f3h6

больше 4 лет назад

Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wjh-7493-7f9f

больше 4 лет назад

Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3wjh-5vc5-vjrv

8 месяцев назад

Missing Authorization vulnerability in Extend Themes Vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through 1.0.24.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wjg-cv7j-pjw6

около 2 лет назад

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wjg-5c66-hpr4

больше 4 лет назад

Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.

EPSS: Низкий
github логотип

GHSA-3wjf-q9cx-m892

14 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-3wjf-h5p8-gcg3

больше 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3wjc-g785-xjp8

больше 2 лет назад

Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wjq-jhph-jc7q

A vulnerability, which was classified as problematic, was found in Trimble SPS851 488.01. This affects an unknown part of the component Ethernet Configuration Menu. The manipulation of the argument Hostname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wjq-88q9-5hmg

An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.18. Android ID: A-31251973. References: N-CVE-2016-6789.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wjp-x9vq-q628

A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /admin_single_student_update.php. This manipulation of the argument st_name causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 2.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-3wjp-mcmp-h4xw

Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3wjp-87jx-r4pv

A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/models/TodoList.ts of the component API Endpoint. The manipulation of the argument userId leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3wjp-7h53-cfv8

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix hang in usb_kill_urb by adding memory barriers The syzbot fuzzer has identified a bug in which processes hang waiting for usb_kill_urb() to return. It turns out the issue is not unlinking the URB; that works just fine. Rather, the problem arises when the wakeup notification that the URB has completed is not received. The reason is memory-access ordering on SMP systems. In outline form, usb_kill_urb() and __usb_hcd_giveback_urb() operating concurrently on different CPUs perform the following actions: CPU 0 CPU 1 ---------------------------- --------------------------------- usb_kill_urb(): __usb_hcd_giveback_urb(): ... ... atomic_inc(&urb->reject); atomic_dec(&urb->use_count); ... ... wait_event(usb_kill_urb_queue, atomic_read(&urb->use_count) == 0); if (atomic_read(&urb->reject)) wake_up(&usb_kill_urb_queue); Confining your attention to urb->reject ...

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wjp-774c-xvqr

Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3wjm-qx5r-4845

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.

CVSS3: 2.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wjm-5g86-c6p3

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVSS3: 8
1%
Низкий
4 месяца назад
github логотип
GHSA-3wjm-33mw-h388

Malicious Package in s3asy

около 6 лет назад
github логотип
GHSA-3wjj-6pp2-788h

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This issue affects ArcGIS Server 12.0 and earlier.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3wjh-xpx4-2h8c

PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wjh-qhxw-f3h6

Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3wjh-7493-7f9f

Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).

CVSS3: 9.8
15%
Средний
больше 4 лет назад
github логотип
GHSA-3wjh-5vc5-vjrv

Missing Authorization vulnerability in Extend Themes Vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through 1.0.24.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3wjg-cv7j-pjw6

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS3: 7.8
4%
Низкий
около 2 лет назад
github логотип
GHSA-3wjg-5c66-hpr4

Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wjf-q9cx-m892

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

14 дней назад
github логотип
GHSA-3wjf-h5p8-gcg3

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3wjc-g785-xjp8

Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу