Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 060

Количество 365 060

github логотип

GHSA-3vhm-q4w3-rw8q

больше 2 лет назад

OroPlatform Forced Redirect to External Website

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3vhm-28vh-hww9

больше 4 лет назад

Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.

EPSS: Высокий
github логотип

GHSA-3vhj-m86h-3wmf

больше 4 лет назад

IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834.

EPSS: Низкий
github логотип

GHSA-3vhj-7fhw-rq33

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3vhh-8wwm-whvg

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame() It is preferable to exit through the out: label because internal debugging functions are located there.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3vhh-58w3-43m4

больше 4 лет назад

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVE-2018-2938 addresses CVE-2018-1313. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3vhg-jg9c-c6r7

больше 4 лет назад

ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vhg-2gj6-mm5q

больше 3 лет назад

A vulnerability, which was classified as problematic, has been found in Shoplazza 1.1. This issue affects some unknown processing of the file /admin/api/admin/articles/ of the component Add Blog Post Handler. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-216191.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3vhf-gvj3-rcch

около 2 лет назад

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3vhc-wxjg-c7wf

больше 4 лет назад

An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access and device reset via a 4K wallpaper image because ImageProcessHelper mishandles boundary checks. The Samsung ID is SVE-2020-18056 (July 2020).

EPSS: Низкий
github логотип

GHSA-3vhc-576x-3qv4

8 месяцев назад

Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3vhc-4mgh-2vvp

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vh9-fqgx-vjph

около 1 года назад

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vh9-9frp-jhqv

16 дней назад

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3vh9-8p9q-8wmw

больше 4 лет назад

Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vh8-f4xf-hgr4

больше 4 лет назад

The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.

EPSS: Низкий
github логотип

GHSA-3vh8-3f6g-98cq

больше 4 лет назад

The examapp plugin 1.0 for WordPress has XSS via exam input text fields.

EPSS: Низкий
github логотип

GHSA-3vh7-ff9w-cqhq

больше 2 лет назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.4, watchOS 10.3, tvOS 17.3, macOS Ventura 13.6.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3. An app may be able to cause a denial-of-service.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-3vh6-pp7q-5xhf

около 1 года назад

A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SessionID parameter at query.asp.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3vh6-2h2q-2g33

почти 2 года назад

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vhm-q4w3-rw8q

OroPlatform Forced Redirect to External Website

CVSS3: 6.1
больше 2 лет назад
github логотип
GHSA-3vhm-28vh-hww9

Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.

83%
Высокий
больше 4 лет назад
github логотип
GHSA-3vhj-m86h-3wmf

IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3vhj-7fhw-rq33

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

больше 1 года назад
github логотип
GHSA-3vhh-8wwm-whvg

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame() It is preferable to exit through the out: label because internal debugging functions are located there.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3vhh-58w3-43m4

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVE-2018-2938 addresses CVE-2018-1313. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3vhg-jg9c-c6r7

ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3vhg-2gj6-mm5q

A vulnerability, which was classified as problematic, has been found in Shoplazza 1.1. This issue affects some unknown processing of the file /admin/api/admin/articles/ of the component Add Blog Post Handler. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-216191.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vhf-gvj3-rcch

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3vhc-wxjg-c7wf

An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access and device reset via a 4K wallpaper image because ImageProcessHelper mishandles boundary checks. The Samsung ID is SVE-2020-18056 (July 2020).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3vhc-576x-3qv4

Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)

CVSS3: 8.2
0%
Низкий
8 месяцев назад
github логотип
GHSA-3vhc-4mgh-2vvp

In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.

CVSS3: 7.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3vh9-fqgx-vjph

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
1%
Низкий
около 1 года назад
github логотип
GHSA-3vh9-9frp-jhqv

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.

CVSS3: 3.1
0%
Низкий
16 дней назад
github логотип
GHSA-3vh9-8p9q-8wmw

Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3vh8-f4xf-hgr4

The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3vh8-3f6g-98cq

The examapp plugin 1.0 for WordPress has XSS via exam input text fields.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3vh7-ff9w-cqhq

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.4, watchOS 10.3, tvOS 17.3, macOS Ventura 13.6.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3. An app may be able to cause a denial-of-service.

CVSS3: 6.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3vh6-pp7q-5xhf

A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SessionID parameter at query.asp.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3vh6-2h2q-2g33

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.

CVSS3: 3.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу