Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-3q63-vj3h-7j3f

больше 4 лет назад

A potential vulnerability in some Lenovo ThinkPads may allow an attacker to execute arbitrary code under SMM under certain circumstances.

EPSS: Низкий
github логотип

GHSA-3q63-c3mx-rfx6

больше 4 лет назад

An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripting (XSS) via a field in the traffic group interface.

EPSS: Низкий
github логотип

GHSA-3q63-2qmj-vfp6

9 дней назад

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12145 .

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3q62-wpc2-x57g

больше 4 лет назад

The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allows callers to select arbitrary files to send to an arbitrary email address.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q62-h7x3-478p

больше 4 лет назад

XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3q62-89h6-6qhx

почти 4 года назад

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_Key` and `WL_DefaultKeyID` configuration values in the function located at offset `0x1c7d28` of firmware 6.9Z , and even more specifically on the command execution occuring at offset `0x1c7f6c`.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3q5x-7mxp-rp6j

почти 7 лет назад

Remote code execution via vulnerable Symphony dependecy injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3q5x-3fpw-pfv9

больше 4 лет назад

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q5v-jr96-99g5

больше 3 лет назад

Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3q5v-cqrv-2527

больше 4 лет назад

Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

EPSS: Низкий
github логотип

GHSA-3q5v-35pc-2r23

больше 4 лет назад

Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3q5r-w7pw-96xm

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Kvvaradha Kv TinyMCE Editor Add Fonts plugin <= 1.1 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3q5r-q6qf-qq6p

около 1 месяца назад

Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q5r-g7hx-jv3c

больше 2 лет назад

The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals, namely, Buffer.prototype.utf8Write, the application can modify the result of path.resolve(), which leads to a path traversal vulnerability. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-3q5r-87hx-pv77

почти 3 года назад

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 29051.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3q5q-j6r6-cgv8

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to avoid crash [Why] In the case where a dml allocation fails for any reason, the current state's dml contexts would no longer be valid. Then subsequent calls dc_state_copy_internal would shallow copy invalid memory and if the new state was released, a double free would occur. [How] Reset dml pointers in new_state to NULL and avoid invalid pointer (cherry picked from commit bcafdc61529a48f6f06355d78eb41b3aeda5296c)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3q5q-f79q-7hr2

около 8 лет назад

High severity vulnerability that affects rubyzip

EPSS: Низкий
github логотип

GHSA-3q5q-8rwq-gwp8

почти 3 года назад

Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3q5q-2qvx-5cm7

около 4 лет назад

HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3q5p-3558-364f

почти 3 года назад

Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q63-vj3h-7j3f

A potential vulnerability in some Lenovo ThinkPads may allow an attacker to execute arbitrary code under SMM under certain circumstances.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3q63-c3mx-rfx6

An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripting (XSS) via a field in the traffic group interface.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3q63-2qmj-vfp6

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12145 .

CVSS3: 8.1
0%
Низкий
9 дней назад
github логотип
GHSA-3q62-wpc2-x57g

The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allows callers to select arbitrary files to send to an arbitrary email address.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3q62-h7x3-478p

XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3q62-89h6-6qhx

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_Key` and `WL_DefaultKeyID` configuration values in the function located at offset `0x1c7d28` of firmware 6.9Z , and even more specifically on the command execution occuring at offset `0x1c7f6c`.

CVSS3: 10
3%
Низкий
почти 4 года назад
github логотип
GHSA-3q5x-7mxp-rp6j

Remote code execution via vulnerable Symphony dependecy injection

CVSS3: 9.8
2%
Низкий
почти 7 лет назад
github логотип
GHSA-3q5x-3fpw-pfv9

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3q5v-jr96-99g5

Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3q5v-cqrv-2527

Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3q5v-35pc-2r23

Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3q5r-w7pw-96xm

Cross-Site Request Forgery (CSRF) vulnerability in Kvvaradha Kv TinyMCE Editor Add Fonts plugin <= 1.1 versions.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3q5r-q6qf-qq6p

Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3q5r-g7hx-jv3c

The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implementation uses Buffer.from() to obtain a Buffer from the result of path.resolve(). By monkey-patching Buffer internals, namely, Buffer.prototype.utf8Write, the application can modify the result of path.resolve(), which leads to a path traversal vulnerability. This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

CVSS3: 7.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3q5r-87hx-pv77

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 29051.

CVSS3: 5.6
0%
Низкий
почти 3 года назад
github логотип
GHSA-3q5q-j6r6-cgv8

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to avoid crash [Why] In the case where a dml allocation fails for any reason, the current state's dml contexts would no longer be valid. Then subsequent calls dc_state_copy_internal would shallow copy invalid memory and if the new state was released, a double free would occur. [How] Reset dml pointers in new_state to NULL and avoid invalid pointer (cherry picked from commit bcafdc61529a48f6f06355d78eb41b3aeda5296c)

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3q5q-f79q-7hr2

High severity vulnerability that affects rubyzip

около 8 лет назад
github логотип
GHSA-3q5q-8rwq-gwp8

Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.

CVSS3: 8
1%
Низкий
почти 3 года назад
github логотип
GHSA-3q5q-2qvx-5cm7

HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3q5p-3558-364f

Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`

CVSS3: 5.3
1%
Низкий
почти 3 года назад

Уязвимостей на страницу