Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 342 247

Количество 342 247

github логотип

GHSA-2jx9-cx6r-jg2x

почти 4 года назад

Microsoft Word Remote Code Execution Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jx8-v4hv-gx3h

около 5 лет назад

XXE vulnerability in Launch import

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jx8-662q-2wpq

больше 4 лет назад

The web portal in TC software on Cisco TelePresence endpoints does not require an exact password match during a login attempt by a user who has not configured a password, which allows remote attackers to bypass authentication by sending an arbitrary password, aka Bug ID CSCud96071.

EPSS: Низкий
github логотип

GHSA-2jx7-xg83-j2m7

около 2 лет назад

Zendframework Denial of Service vector via XEE injection

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jx7-jqgc-hgxg

больше 4 лет назад

Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.

EPSS: Низкий
github логотип

GHSA-2jx6-v8vf-jjp6

больше 1 года назад

Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a single email to contain upper and lower case characters in order to access the application and win prizes as many times as wanted.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jx5-wrfm-w8mv

10 месяцев назад

Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2jx5-39j8-fv56

больше 4 лет назад

Unspecified vulnerability in HP IceWall SSO 10.0 Dfw and IceWall MCRP 2.1 and 3.0 allows remote attackers to cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2jx4-xmvj-hmcw

около 3 лет назад

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jx4-mmr5-ww75

около 1 года назад

BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path and potentially lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jx4-7qpj-c9gc

больше 4 лет назад

Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information.

EPSS: Средний
github логотип

GHSA-2jx3-rgf3-fqhj

почти 4 года назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.38. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-2jx3-p89p-3f69

больше 3 лет назад

An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jx3-m5vv-rvc6

больше 4 лет назад

Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.

EPSS: Низкий
github логотип

GHSA-2jx3-fx5f-r2c6

около 3 лет назад

FFmpeg discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jx3-65f3-xr8r

2 месяца назад

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError

EPSS: Низкий
github логотип

GHSA-2jx3-5j9v-prpp

около 4 лет назад

BlockWishList SQL Injection vulnerability

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-2jx2-x46f-wj52

больше 1 года назад

**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affected device.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2jx2-r7f9-93pw

больше 2 лет назад

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege may execute an arbitrary script on the web browser of the user who accessed the website using the product.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2jx2-qcm4-rf9h

около 3 лет назад

Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jx9-cx6r-jg2x

Microsoft Word Remote Code Execution Vulnerability.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2jx8-v4hv-gx3h

XXE vulnerability in Launch import

CVSS3: 7.5
1%
Низкий
около 5 лет назад
github логотип
GHSA-2jx8-662q-2wpq

The web portal in TC software on Cisco TelePresence endpoints does not require an exact password match during a login attempt by a user who has not configured a password, which allows remote attackers to bypass authentication by sending an arbitrary password, aka Bug ID CSCud96071.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2jx7-xg83-j2m7

Zendframework Denial of Service vector via XEE injection

CVSS3: 7.5
около 2 лет назад
github логотип
GHSA-2jx7-jqgc-hgxg

Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2jx6-v8vf-jjp6

Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a single email to contain upper and lower case characters in order to access the application and win prizes as many times as wanted.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jx5-wrfm-w8mv

Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.7
0%
Низкий
10 месяцев назад
github логотип
GHSA-2jx5-39j8-fv56

Unspecified vulnerability in HP IceWall SSO 10.0 Dfw and IceWall MCRP 2.1 and 3.0 allows remote attackers to cause a denial of service via unknown vectors.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2jx4-xmvj-hmcw

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2jx4-mmr5-ww75

BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path and potentially lead to arbitrary code execution.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-2jx4-7qpj-c9gc

Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information.

12%
Средний
больше 4 лет назад
github логотип
GHSA-2jx3-rgf3-fqhj

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.38. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).

CVSS3: 6
1%
Низкий
почти 4 года назад
github логотип
GHSA-2jx3-p89p-3f69

An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2jx3-m5vv-rvc6

Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2jx3-fx5f-r2c6

FFmpeg discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2jx3-65f3-xr8r

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError

2 месяца назад
github логотип
GHSA-2jx3-5j9v-prpp

BlockWishList SQL Injection vulnerability

CVSS3: 8.1
24%
Средний
около 4 лет назад
github логотип
GHSA-2jx2-x46f-wj52

**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affected device.

CVSS3: 4.9
9%
Низкий
больше 1 года назад
github логотип
GHSA-2jx2-r7f9-93pw

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege may execute an arbitrary script on the web browser of the user who accessed the website using the product.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jx2-qcm4-rf9h

Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec

2%
Низкий
около 3 лет назад

Уязвимостей на страницу