Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 060

Количество 365 060

github логотип

GHSA-3v6v-w2x6-55vq

больше 4 лет назад

Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.

EPSS: Низкий
github логотип

GHSA-3v6v-6vwq-2h95

20 дней назад

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3v6v-2x6p-32mc

больше 3 лет назад

pgadmin4 vulnerable to Code Injection

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-3v6r-vhg4-9m9j

больше 4 лет назад

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v6r-pw5p-6hc2

больше 4 лет назад

An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1021, CVE-2019-1022, CVE-2019-1026, CVE-2019-1027, CVE-2019-1028.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v6q-chwv-xhhp

больше 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3v6p-5m88-xqx6

больше 4 лет назад

Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v6p-5g46-w432

почти 2 года назад

Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v6m-8v49-4vvq

больше 4 лет назад

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.

EPSS: Низкий
github логотип

GHSA-3v6j-v3qc-cxff

около 3 лет назад

Denial of service from unlimited password lengths

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3v6j-pmgg-8c38

больше 4 лет назад

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private JPEG data. Successful exploitation could lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v6j-9mf5-wv3f

около 4 лет назад

The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v6h-ww3h-9h87

больше 4 лет назад

SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.

EPSS: Низкий
github логотип

GHSA-3v6h-m7q4-2c4g

почти 3 года назад

A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3v6h-hqm4-2rg6

около 8 лет назад

Arbitrary File Write in adm-zip

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-3v6h-4jjq-8c6c

около 1 года назад

A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3v6g-g235-cmv9

4 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through <= 1.1.7.1.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3v6f-w66g-3mv6

27 дней назад

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v6f-r45v-h8fj

около 3 лет назад

When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v6f-p2hc-xq2j

4 месяца назад

A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a pull request but has not reacted yet.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v6v-w2x6-55vq

Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6v-6vwq-2h95

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

CVSS3: 5.3
0%
Низкий
20 дней назад
github логотип
GHSA-3v6v-2x6p-32mc

pgadmin4 vulnerable to Code Injection

CVSS3: 8.8
80%
Высокий
больше 3 лет назад
github логотип
GHSA-3v6r-vhg4-9m9j

IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6r-pw5p-6hc2

An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1021, CVE-2019-1022, CVE-2019-1026, CVE-2019-1027, CVE-2019-1028.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6q-chwv-xhhp

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v6p-5m88-xqx6

Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6p-5g46-w432

Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3v6m-8v49-4vvq

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6j-v3qc-cxff

Denial of service from unlimited password lengths

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-3v6j-pmgg-8c38

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private JPEG data. Successful exploitation could lead to arbitrary code execution.

CVSS3: 8.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6j-9mf5-wv3f

The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3v6h-ww3h-9h87

SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v6h-m7q4-2c4g

A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 9.9
2%
Низкий
почти 3 года назад
github логотип
GHSA-3v6h-hqm4-2rg6

Arbitrary File Write in adm-zip

CVSS3: 5.5
15%
Средний
около 8 лет назад
github логотип
GHSA-3v6h-4jjq-8c6c

A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3v6g-g235-cmv9

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through <= 1.1.7.1.

CVSS3: 7.6
0%
Низкий
4 месяца назад
github логотип
GHSA-3v6f-w66g-3mv6

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.

CVSS3: 5.5
0%
Низкий
27 дней назад
github логотип
GHSA-3v6f-r45v-h8fj

When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-3v6f-p2hc-xq2j

A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a pull request but has not reacted yet.

CVSS3: 3.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу