Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3w8p-p9qm-vg44

больше 4 лет назад

crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3w8p-gqqp-6g99

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in phpXplorer 0.9.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the address bar field.

EPSS: Низкий
github логотип

GHSA-3w8p-5pg9-6v3j

около 1 года назад

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3w8p-33h3-h7v6

больше 4 лет назад

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3w8m-pw3c-4478

больше 4 лет назад

admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211.

EPSS: Низкий
github логотип

GHSA-3w8m-3w76-f6mh

4 месяца назад

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3w8h-vhc9-93cj

около 2 лет назад

A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_personalities_infos.py' file. This vulnerability allows attackers to read arbitrary files by manipulating the 'category' and 'name' parameters during the 'Copy to custom personas folder for editing' process. By inserting '../' sequences in these parameters, attackers can traverse the directory structure and access files outside of the intended directory. Successful exploitation results in unauthorized access to sensitive information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w8g-xr3f-2mp8

около 5 лет назад

Out of bounds write in nalgebra

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3w8g-xqh4-qqfx

больше 4 лет назад

An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrator password or adding a new administrator account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w8f-65wc-4gh4

около 1 месяца назад

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w8c-pp2g-pw99

больше 4 лет назад

myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the URL, which are not properly handled as part of the PATH_INFO environment variable.

EPSS: Низкий
github логотип

GHSA-3w8c-hmvh-m87g

больше 4 лет назад

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671.

EPSS: Средний
github логотип

GHSA-3w8c-ghf8-rmwq

больше 4 лет назад

The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3w89-xp68-5ffh

больше 4 лет назад

A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.

EPSS: Низкий
github логотип

GHSA-3w89-hgwc-85v8

около 2 лет назад

Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3w88-gmx5-rx4v

около 4 лет назад

Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3w88-854j-p487

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hussam Hussien Popup Image allows Stored XSS.This issue affects Popup Image: from n/a through 1.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3w87-pggf-mwm8

больше 4 лет назад

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0783.

EPSS: Низкий
github логотип

GHSA-3w87-fgr4-8m86

больше 4 лет назад

Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.

EPSS: Низкий
github логотип

GHSA-3w87-5jwj-39vh

больше 4 лет назад

USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w8p-p9qm-vg44

crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w8p-gqqp-6g99

Cross-site scripting (XSS) vulnerability in phpXplorer 0.9.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the address bar field.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w8p-5pg9-6v3j

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3w8p-33h3-h7v6

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.8
13%
Средний
больше 4 лет назад
github логотип
GHSA-3w8m-pw3c-4478

admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3w8m-3w76-f6mh

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue.

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-3w8h-vhc9-93cj

A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_personalities_infos.py' file. This vulnerability allows attackers to read arbitrary files by manipulating the 'category' and 'name' parameters during the 'Copy to custom personas folder for editing' process. By inserting '../' sequences in these parameters, attackers can traverse the directory structure and access files outside of the intended directory. Successful exploitation results in unauthorized access to sensitive information.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3w8g-xr3f-2mp8

Out of bounds write in nalgebra

CVSS3: 9.8
1%
Низкий
около 5 лет назад
github логотип
GHSA-3w8g-xqh4-qqfx

An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrator password or adding a new administrator account.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w8f-65wc-4gh4

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3w8c-pp2g-pw99

myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the URL, which are not properly handled as part of the PATH_INFO environment variable.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3w8c-hmvh-m87g

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671.

26%
Средний
больше 4 лет назад
github логотип
GHSA-3w8c-ghf8-rmwq

The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w89-xp68-5ffh

A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-3w89-hgwc-85v8

Missing Authorization vulnerability in Aspose.Cloud Marketplace Aspose.Words Exporter.This issue affects Aspose.Words Exporter: from n/a through 6.3.1.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3w88-gmx5-rx4v

Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)

CVSS3: 8.2
7%
Низкий
около 4 лет назад
github логотип
GHSA-3w88-854j-p487

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hussam Hussien Popup Image allows Stored XSS.This issue affects Popup Image: from n/a through 1.0.1.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3w87-pggf-mwm8

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0783.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w87-fgr4-8m86

Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w87-5jwj-39vh

USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу