Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 920

Количество 364 920

github логотип

GHSA-3rvc-qcwh-fhqv

10 месяцев назад

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3rvc-cvrv-gprh

больше 4 лет назад

A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This could allow the attacker to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicious input as the argument of the affected CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. An attacker would need valid administrator credentials to exploit these vulnerabilities.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3rvc-764q-q5rq

больше 3 лет назад

A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-224997 was assigned to this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rv9-f576-m286

больше 3 лет назад

Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Virames Vira-Investing allows Account Footprinting.This issue affects Vira-Investing: before 1.0.84.86.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3rv9-35j4-r85x

20 дней назад

A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rv7-vfgw-fvwj

больше 4 лет назад

Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Высокий
github логотип

GHSA-3rv7-4xwm-v96j

4 месяца назад

Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3rv7-4fgp-6q58

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3rv5-pgj2-5frg

больше 2 лет назад

A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3rv5-ggwr-m2p2

больше 4 лет назад

AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 allows OS Command Injection because of missing input validation on one of the parameters of an HTTP request.

EPSS: Низкий
github логотип

GHSA-3rv5-c9qq-6335

около 1 года назад

An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public components.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rv4-77xr-w6jx

почти 3 года назад

A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rv3-jp5p-3jhw

больше 4 лет назад

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rv3-73vp-853w

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3rrx-r28h-qh3c

почти 4 года назад

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34700.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rrx-pxh6-vf6v

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

EPSS: Низкий
github логотип

GHSA-3rrx-364r-6wf6

больше 3 лет назад

Cross-site Scripting in Jenkins Spring Config Plugin

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3rrw-pv9w-qgch

больше 4 лет назад

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rrw-2rpr-xr39

больше 4 лет назад

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, may arbitrarily change coming soon page layout.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rrv-jp9h-4vrq

больше 4 лет назад

A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-31244612. References: NVIDIA N-CVE-2016-6747.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rvc-qcwh-fhqv

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3rvc-cvrv-gprh

A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This could allow the attacker to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicious input as the argument of the affected CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. An attacker would need valid administrator credentials to exploit these vulnerabilities.

CVSS3: 6.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rvc-764q-q5rq

A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-224997 was assigned to this vulnerability.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rv9-f576-m286

Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Virames Vira-Investing allows Account Footprinting.This issue affects Vira-Investing: before 1.0.84.86.

CVSS3: 5.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rv9-35j4-r85x

A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
20 дней назад
github логотип
GHSA-3rv7-vfgw-fvwj

Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

81%
Высокий
больше 4 лет назад
github логотип
GHSA-3rv7-4xwm-v96j

Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.6
0%
Низкий
4 месяца назад
github логотип
GHSA-3rv7-4fgp-6q58

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-3rv5-pgj2-5frg

A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.

CVSS3: 10
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3rv5-ggwr-m2p2

AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 allows OS Command Injection because of missing input validation on one of the parameters of an HTTP request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rv5-c9qq-6335

An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public components.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3rv4-77xr-w6jx

A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3rv3-jp5p-3jhw

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rv3-73vp-853w

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrx-r28h-qh3c

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34700.

CVSS3: 8.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-3rrx-pxh6-vf6v

Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrx-364r-6wf6

Cross-site Scripting in Jenkins Spring Config Plugin

CVSS3: 8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rrw-pv9w-qgch

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.

CVSS3: 6.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrw-2rpr-xr39

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, may arbitrarily change coming soon page layout.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrv-jp9h-4vrq

A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-31244612. References: NVIDIA N-CVE-2016-6747.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу