Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 920

Количество 364 920

github логотип

GHSA-3rrv-j65x-53qp

больше 4 лет назад

An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the startProcess command. The command takes a user-supplied script argument and executes it under root context. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine for a successful exploit.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rrv-gxmq-5643

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-3rrr-jr9j-h3q3

25 дней назад

Mermaid Architecture diagrams are vulnerable to prototype pollution

EPSS: Низкий
github логотип

GHSA-3rrr-cqqf-5xqm

больше 4 лет назад

VirtueMart before 1.0.1 does not properly handle errors when a user is forbidden to read a requested page, which has unknown impact and remote attack vectors.

EPSS: Низкий
github логотип

GHSA-3rrr-6hj5-967g

больше 1 года назад

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ownersignup.php. The manipulation of the argument f/e/p/m/o/n/c/s/ci/a leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "m" to be affected. But it must be assumed that many other parameters are affected as well.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3rrq-p5gv-7828

больше 4 лет назад

Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rrq-mwrq-44vc

больше 4 лет назад

Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.

EPSS: Низкий
github логотип

GHSA-3rrq-fwhx-9wq4

5 месяцев назад

Race condition, use-after-free in the Graphics: WebRender component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rrq-93q9-g68g

больше 4 лет назад

SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter.

EPSS: Низкий
github логотип

GHSA-3rrm-g9g7-qh35

больше 4 лет назад

Multiple SQL injection vulnerabilities in Fortibus CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via (1) the username or password to logon.asp, (2) WeeklyNotesDisplay.asp, or (3) the Search page.

EPSS: Низкий
github логотип

GHSA-3rrm-945c-3g7m

12 месяцев назад

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of the argument ProductImage leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3rrj-xq44-843h

3 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rrh-rx2j-x9xj

больше 4 лет назад

CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation.

EPSS: Низкий
github логотип

GHSA-3rrh-jvpr-5pv8

больше 4 лет назад

In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-167663878

EPSS: Низкий
github логотип

GHSA-3rrh-hp3f-9r6p

почти 2 года назад

A vulnerability in Cisco&nbsp;RCM for Cisco&nbsp;StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges&nbsp;in the context of the configured container. This vulnerability exists because the debug mode is incorrectly enabled for specific services. An attacker could exploit this vulnerability by connecting to the device and navigating to the service with debug mode enabled. A successful exploit could allow the attacker to execute arbitrary commands as the root user. The attacker would need to perform detailed reconnaissance to allow for unauthenticated access. The vulnerability can also be exploited by an authenticated attacker. Cisco&nbsp;has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-3rrg-p8xc-3457

больше 4 лет назад

Stored cross-site scripting vulnerability in Jenkins TestLink Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rrg-mmq3-p43v

больше 4 лет назад

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.

EPSS: Низкий
github логотип

GHSA-3rrg-9ph6-24px

около 4 лет назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, granting root privileges to an attacker.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rrf-jrxv-9vpm

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: iio: light: as73211: Ensure buffer holes are zeroed Given that the buffer is copied to a kfifo that ultimately user space can read, ensure we zero it.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3rrc-wwp9-v95c

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Typing Text allows Stored XSS.This issue affects Typing Text: from n/a through 1.2.5.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rrv-j65x-53qp

An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in the startProcess command. The command takes a user-supplied script argument and executes it under root context. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine for a successful exploit.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrv-gxmq-5643

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

CVSS3: 6.1
25%
Средний
больше 4 лет назад
github логотип
GHSA-3rrr-jr9j-h3q3

Mermaid Architecture diagrams are vulnerable to prototype pollution

0%
Низкий
25 дней назад
github логотип
GHSA-3rrr-cqqf-5xqm

VirtueMart before 1.0.1 does not properly handle errors when a user is forbidden to read a requested page, which has unknown impact and remote attack vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrr-6hj5-967g

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ownersignup.php. The manipulation of the argument f/e/p/m/o/n/c/s/ci/a leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "m" to be affected. But it must be assumed that many other parameters are affected as well.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3rrq-p5gv-7828

Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrq-mwrq-44vc

Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrq-fwhx-9wq4

Race condition, use-after-free in the Graphics: WebRender component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3rrq-93q9-g68g

SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrm-g9g7-qh35

Multiple SQL injection vulnerabilities in Fortibus CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via (1) the username or password to logon.asp, (2) WeeklyNotesDisplay.asp, or (3) the Search page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrm-945c-3g7m

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of the argument ProductImage leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 6.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-3rrj-xq44-843h

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS3: 5.4
1%
Низкий
3 месяца назад
github логотип
GHSA-3rrh-rx2j-x9xj

CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrh-jvpr-5pv8

In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-167663878

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrh-hp3f-9r6p

A vulnerability in Cisco&nbsp;RCM for Cisco&nbsp;StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges&nbsp;in the context of the configured container. This vulnerability exists because the debug mode is incorrectly enabled for specific services. An attacker could exploit this vulnerability by connecting to the device and navigating to the service with debug mode enabled. A successful exploit could allow the attacker to execute arbitrary commands as the root user. The attacker would need to perform detailed reconnaissance to allow for unauthenticated access. The vulnerability can also be exploited by an authenticated attacker. Cisco&nbsp;has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVSS3: 8.1
12%
Средний
почти 2 года назад
github логотип
GHSA-3rrg-p8xc-3457

Stored cross-site scripting vulnerability in Jenkins TestLink Plugin

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrg-mmq3-p43v

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrg-9ph6-24px

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, granting root privileges to an attacker.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-3rrf-jrxv-9vpm

In the Linux kernel, the following vulnerability has been resolved: iio: light: as73211: Ensure buffer holes are zeroed Given that the buffer is copied to a kfifo that ultimately user space can read, ensure we zero it.

CVSS3: 7.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-3rrc-wwp9-v95c

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Typing Text allows Stored XSS.This issue affects Typing Text: from n/a through 1.2.5.

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу