Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3w37-5p3p-jv92

больше 3 лет назад

Apache CXF vulnerable to Exposure of Sensitive Information

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w36-wf5x-rjfv

больше 4 лет назад

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-3w36-ppm5-2f9j

больше 3 лет назад

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w34-xv7m-phqr

больше 4 лет назад

Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w33-h749-fgfr

больше 4 лет назад

Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file.

EPSS: Низкий
github логотип

GHSA-3w32-vr93-jm7m

больше 4 лет назад

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w32-23wj-rxg3

2 месяца назад

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

EPSS: Низкий
github логотип

GHSA-3w2x-jhm7-3gw3

больше 4 лет назад

Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.

EPSS: Низкий
github логотип

GHSA-3w2x-9vcq-46w8

больше 4 лет назад

The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3w2w-p865-v7xr

6 месяцев назад

Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3w2w-73h7-hq3v

больше 4 лет назад

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.

EPSS: Низкий
github логотип

GHSA-3w2w-5pxh-222c

больше 4 лет назад

dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.

EPSS: Низкий
github логотип

GHSA-3w2w-4v6h-c6q9

больше 4 лет назад

The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.

EPSS: Низкий
github логотип

GHSA-3w2v-v5mv-qqrj

около 3 лет назад

A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w2v-f8x7-qc92

больше 1 года назад

Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3w2r-c4w7-whmh

4 дня назад

Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

EPSS: Низкий
github логотип

GHSA-3w2m-22gp-wc5v

больше 4 лет назад

phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.

EPSS: Низкий
github логотип

GHSA-3w2j-qqf9-7gjm

19 дней назад

Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of service for that node. An authenticated user holding only read-only privileges on a single searchable index can trigger the condition with one small search request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3w2j-mvmp-4vx3

больше 2 лет назад

Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w2j-jf2v-w2v3

больше 4 лет назад

The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

CVSS3: 2.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w37-5p3p-jv92

Apache CXF vulnerable to Exposure of Sensitive Information

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3w36-wf5x-rjfv

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

CVSS3: 8.1
46%
Средний
больше 4 лет назад
github логотип
GHSA-3w36-ppm5-2f9j

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3w34-xv7m-phqr

Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w33-h749-fgfr

Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w32-vr93-jm7m

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w32-23wj-rxg3

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

0%
Низкий
2 месяца назад
github логотип
GHSA-3w2x-jhm7-3gw3

Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3w2x-9vcq-46w8

The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3w2w-p865-v7xr

Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3w2w-73h7-hq3v

Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3w2w-5pxh-222c

dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3w2w-4v6h-c6q9

The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3w2v-v5mv-qqrj

A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVSS3: 8.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-3w2v-f8x7-qc92

Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3w2r-c4w7-whmh

Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

0%
Низкий
4 дня назад
github логотип
GHSA-3w2m-22gp-wc5v

phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3w2j-qqf9-7gjm

Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of service for that node. An authenticated user holding only read-only privileges on a single searchable index can trigger the condition with one small search request.

CVSS3: 6.5
0%
Низкий
19 дней назад
github логотип
GHSA-3w2j-mvmp-4vx3

Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3w2j-jf2v-w2v3

The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

CVSS3: 2.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу