Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 385

Количество 362 385

github логотип

GHSA-3hrv-h2gx-w5g3

3 месяца назад

Windows Kerberos Denial of Service Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hrv-ghrw-48w6

около 2 лет назад

In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3hrv-5j8v-742x

больше 4 лет назад

SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.

EPSS: Низкий
github логотип

GHSA-3hrr-xwvg-hxvr

больше 2 лет назад

Duplicate Advisory: Keycloak DoS via account lockout

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3hrr-gwwg-4mc5

3 месяца назад

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into HTML characters after sanitization has already been applied. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses the published post or the print view of an injected recipe.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3hrq-94cp-44pf

3 месяца назад

CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and launched.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3hrq-4v7v-gjm4

больше 4 лет назад

SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572.

EPSS: Низкий
github логотип

GHSA-3hrp-jhgv-872c

больше 4 лет назад

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3hrp-jghr-jv6p

больше 4 лет назад

jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hrp-9734-8xmp

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/msm/snapshot: fix dumping of the unaligned regions The snapshotting code internally aligns data segment to 16 bytes. This works fine for DPU code (where most of the regions are aligned), but fails for snapshotting of the DSI data (because DSI data region is shifted by 4 bytes). Fix the code by removing length alignment and by accurately printing last registers in the region. While reworking the code also fix the 16x memory overallocation in msm_disp_state_dump_regs(). Patchwork: https://patchwork.freedesktop.org/patch/725449/

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3hrp-72rj-vmgh

больше 4 лет назад

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that this is a stack-based buffer overflow in DBMS_AW.EXECUTE, which allows code execution via a long Current Directory Alias (CDA) command.

EPSS: Низкий
github логотип

GHSA-3hrm-jr5c-jm96

больше 4 лет назад

IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.

EPSS: Низкий
github логотип

GHSA-3hrm-h2m4-hcr8

около 1 месяца назад

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion degrades availability for other operations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hrj-frfj-gwp3

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hrj-c558-9fjq

около 4 лет назад

A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as a SYSTEM privilege.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hrh-pfw6-9m5x

3 месяца назад

Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hrh-p3gr-mv3p

больше 2 лет назад

A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7(775). This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258293 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hrg-r9w6-f7gq

больше 4 лет назад

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacker to obtain information such as user personal data. IBM X-Force ID: 128622.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hrf-pq5f-6637

больше 1 года назад

Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hrf-2gc2-mx32

около 1 месяца назад

Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hrv-h2gx-w5g3

Windows Kerberos Denial of Service Vulnerability

CVSS3: 5.3
1%
Низкий
3 месяца назад
github логотип
GHSA-3hrv-ghrw-48w6

In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

CVSS3: 7.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-3hrv-5j8v-742x

SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrr-xwvg-hxvr

Duplicate Advisory: Keycloak DoS via account lockout

CVSS3: 3.7
больше 2 лет назад
github логотип
GHSA-3hrr-gwwg-4mc5

The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into HTML characters after sanitization has already been applied. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses the published post or the print view of an injected recipe.

CVSS3: 6.4
0%
Низкий
3 месяца назад
github логотип
GHSA-3hrq-94cp-44pf

CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and launched.

CVSS3: 8.4
0%
Низкий
3 месяца назад
github логотип
GHSA-3hrq-4v7v-gjm4

SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrp-jhgv-872c

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default.

CVSS3: 8.8
15%
Средний
больше 4 лет назад
github логотип
GHSA-3hrp-jghr-jv6p

jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrp-9734-8xmp

In the Linux kernel, the following vulnerability has been resolved: drm/msm/snapshot: fix dumping of the unaligned regions The snapshotting code internally aligns data segment to 16 bytes. This works fine for DPU code (where most of the regions are aligned), but fails for snapshotting of the DSI data (because DSI data region is shifted by 4 bytes). Fix the code by removing length alignment and by accurately printing last registers in the region. While reworking the code also fix the 16x memory overallocation in msm_disp_state_dump_regs(). Patchwork: https://patchwork.freedesktop.org/patch/725449/

CVSS3: 7.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3hrp-72rj-vmgh

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that this is a stack-based buffer overflow in DBMS_AW.EXECUTE, which allows code execution via a long Current Directory Alias (CDA) command.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrm-jr5c-jm96

IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrm-h2m4-hcr8

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion degrades availability for other operations.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3hrj-frfj-gwp3

Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrj-c558-9fjq

A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as a SYSTEM privilege.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-3hrh-pfw6-9m5x

Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3hrh-p3gr-mv3p

A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7(775). This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258293 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3hrg-r9w6-f7gq

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacker to obtain information such as user personal data. IBM X-Force ID: 128622.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hrf-pq5f-6637

Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hrf-2gc2-mx32

Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection

1%
Низкий
около 1 месяца назад

Уязвимостей на страницу