Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 328

Количество 362 328

github логотип

GHSA-3h8x-jv2f-mmvp

больше 1 года назад

A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3h8w-7jg4-hcrw

больше 4 лет назад

upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.

CVSS3: 4.9
EPSS: Средний
github логотип

GHSA-3h8v-g624-hvxg

около 4 лет назад

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h8r-hv7f-jgcx

больше 4 лет назад

The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.

EPSS: Низкий
github логотип

GHSA-3h8r-f622-g36q

больше 4 лет назад

The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h8r-9w82-hxmh

около 2 месяцев назад

A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.14 is sufficient to fix this issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06. It is suggested to upgrade the affected component.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3h8r-96mm-7vvg

больше 1 года назад

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3h8r-6x68-6v9m

больше 4 лет назад

Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.

EPSS: Низкий
github логотип

GHSA-3h8q-f835-m698

3 месяца назад

A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h8p-v7v7-3333

больше 4 лет назад

Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.

EPSS: Средний
github логотип

GHSA-3h8p-48px-cj7r

больше 2 лет назад

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/IPV6/naborTable/add_commit.php. The manipulation of the argument ip_addr/mac_addr leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263113 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3h8p-2v2p-mc5x

больше 4 лет назад

An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h8m-q4x3-3fhw

около 4 лет назад

The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3h8m-mvxw-xrmm

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential corruption when moving a directory F2FS has the same issue in ext4_rename causing crash revealed by xfstests/generic/707. See also commit 0813299c586b ("ext4: Fix possible corruption when moving a directory")

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3h8m-483j-7xxm

больше 5 лет назад

Heap out of bounds read in `RequantizationRange`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-3h8h-mjhw-3m3h

около 4 лет назад

The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.

EPSS: Низкий
github логотип

GHSA-3h8h-469q-248f

больше 4 лет назад

Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h8g-q3cw-mr42

больше 4 лет назад

Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h8c-h67v-4vg7

больше 2 лет назад

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3h89-j8rf-vq88

10 месяцев назад

radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h8x-jv2f-mmvp

A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3h8w-7jg4-hcrw

upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.

CVSS3: 4.9
15%
Средний
больше 4 лет назад
github логотип
GHSA-3h8v-g624-hvxg

TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3h8r-hv7f-jgcx

The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-3h8r-f622-g36q

The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h8r-9w82-hxmh

A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.14 is sufficient to fix this issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06. It is suggested to upgrade the affected component.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3h8r-96mm-7vvg

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h8r-6x68-6v9m

Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h8q-f835-m698

A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-3h8p-v7v7-3333

Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control.

43%
Средний
больше 4 лет назад
github логотип
GHSA-3h8p-48px-cj7r

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/IPV6/naborTable/add_commit.php. The manipulation of the argument ip_addr/mac_addr leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263113 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
7%
Низкий
больше 2 лет назад
github логотип
GHSA-3h8p-2v2p-mc5x

An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h8m-q4x3-3fhw

The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-3h8m-mvxw-xrmm

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential corruption when moving a directory F2FS has the same issue in ext4_rename causing crash revealed by xfstests/generic/707. See also commit 0813299c586b ("ext4: Fix possible corruption when moving a directory")

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-3h8m-483j-7xxm

Heap out of bounds read in `RequantizationRange`

CVSS3: 2.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-3h8h-mjhw-3m3h

The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3h8h-469q-248f

Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-3h8g-q3cw-mr42

Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h8c-h67v-4vg7

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3h89-j8rf-vq88

radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

CVSS3: 7.5
0%
Низкий
10 месяцев назад

Уязвимостей на страницу