Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 543

Количество 364 543

github логотип

GHSA-3qcr-p3xq-5c4r

больше 4 лет назад

RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qcq-w2m6-vwwx

больше 4 лет назад

An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.

EPSS: Низкий
github логотип

GHSA-3qcq-p3m2-3c4p

7 месяцев назад

Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qcq-28jc-g3f4

больше 2 лет назад

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qcp-g78m-7jv9

больше 4 лет назад

A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3qcp-9v8c-6jp7

10 месяцев назад

Piranha CMS vulnerable to stored cross-site scripting (XSS)

EPSS: Низкий
github логотип

GHSA-3qcm-pj6q-w4c5

5 месяцев назад

Nodcms contains a cross-site request forgery vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qcj-r6mr-vw7f

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qch-fgcw-x72h

больше 4 лет назад

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455

EPSS: Низкий
github логотип

GHSA-3qcg-h4xg-5jrg

4 месяца назад

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before saving schedule data. This makes it possible for authenticated attackers, with subscriber-level access and above, to create scheduled export jobs and send backup notifications to attacker-controlled email addresses. Because such notifications include the random backup filename, full site backups can subsequently be downloaded from the target site, resulting in sensitive information exposure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qcg-4hp6-rx66

больше 4 лет назад

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack.

EPSS: Низкий
github логотип

GHSA-3qcf-jc2v-r99h

больше 4 лет назад

Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

EPSS: Низкий
github логотип

GHSA-3qcf-hphp-2m63

больше 2 лет назад

In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3qcf-857g-5p4x

почти 2 года назад

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3qcc-hgxf-jmc5

больше 4 лет назад

IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands.

EPSS: Низкий
github логотип

GHSA-3qcc-7w94-cc7w

больше 4 лет назад

SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter to the /search URI.

EPSS: Низкий
github логотип

GHSA-3qc9-35qv-7xpj

больше 3 лет назад

To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

EPSS: Низкий
github логотип

GHSA-3qc8-c2c9-9pgw

больше 4 лет назад

Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3qc8-39jf-7268

больше 4 лет назад

libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" value, which causes a divide-by-zero error in (1) tif_strip.c and (2) tif_tile.c, a different vulnerability than CVE-2004-0804.

EPSS: Низкий
github логотип

GHSA-3qc6-x7mq-579v

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Roberto Alicata ra_qrcode allows Stored XSS.This issue affects ra_qrcode: from n/a through 2.1.0.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qcr-p3xq-5c4r

RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3qcq-w2m6-vwwx

An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3qcq-p3m2-3c4p

Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3qcq-28jc-g3f4

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3qcp-g78m-7jv9

A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.

CVSS3: 8.8
66%
Средний
больше 4 лет назад
github логотип
GHSA-3qcp-9v8c-6jp7

Piranha CMS vulnerable to stored cross-site scripting (XSS)

0%
Низкий
10 месяцев назад
github логотип
GHSA-3qcm-pj6q-w4c5

Nodcms contains a cross-site request forgery vulnerability

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3qcj-r6mr-vw7f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-3qch-fgcw-x72h

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3qcg-h4xg-5jrg

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before saving schedule data. This makes it possible for authenticated attackers, with subscriber-level access and above, to create scheduled export jobs and send backup notifications to attacker-controlled email addresses. Because such notifications include the random backup filename, full site backups can subsequently be downloaded from the target site, resulting in sensitive information exposure.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3qcg-4hp6-rx66

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qcf-jc2v-r99h

Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qcf-hphp-2m63

In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qcf-857g-5p4x

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVSS3: 8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3qcc-hgxf-jmc5

IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qcc-7w94-cc7w

SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter to the /search URI.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qc9-35qv-7xpj

To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

больше 3 лет назад
github логотип
GHSA-3qc8-c2c9-9pgw

Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.

CVSS3: 9.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qc8-39jf-7268

libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" value, which causes a divide-by-zero error in (1) tif_strip.c and (2) tif_tile.c, a different vulnerability than CVE-2004-0804.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qc6-x7mq-579v

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Roberto Alicata ra_qrcode allows Stored XSS.This issue affects ra_qrcode: from n/a through 2.1.0.

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу