Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 328

Количество 362 328

github логотип

GHSA-3h6w-w73g-4wv9

больше 4 лет назад

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.

EPSS: Низкий
github логотип

GHSA-3h6w-hjgc-hx7q

больше 1 года назад

Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3h6w-92g2-xgrr

4 дня назад

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3h6v-4pff-pgf4

больше 1 года назад

This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A download's origin may be incorrectly associated.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h6r-gqmp-9v88

больше 4 лет назад

Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.

EPSS: Низкий
github логотип

GHSA-3h6p-jvww-q7w3

больше 4 лет назад

Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.

EPSS: Низкий
github логотип

GHSA-3h6m-v52v-hvmw

около 4 лет назад

Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3h6m-4cmj-f665

2 месяца назад

Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h6m-3jhx-cfg9

около 4 лет назад

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions.

EPSS: Низкий
github логотип

GHSA-3h6j-9x8m-rg3g

5 месяцев назад

Graby has stored XSS via iframe srcdoc Attribute in htmLawed Sanitization Config

EPSS: Низкий
github логотип

GHSA-3h6h-wq56-3w89

больше 3 лет назад

The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h6h-v2q2-7mx9

больше 4 лет назад

WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h6h-8756-mj4f

больше 4 лет назад

A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2.0. Known Fixed Releases: 6.2.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h6h-67x3-cv5x

3 месяца назад

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-3h6g-vwfm-p62q

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.

EPSS: Низкий
github логотип

GHSA-3h6g-r953-7g4p

около 4 лет назад

An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3h6g-63ch-8mwf

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: net: ftgmac100: fix ring allocation unwind on open failure ftgmac100_alloc_rings() allocates rx_skbs, tx_skbs, rxdes, txdes, and rx_scratch in stages. On intermediate failures it returned -ENOMEM directly, leaking resources allocated earlier in the function. Rework the failure path to use staged local unwind labels and free allocated resources in reverse order before returning -ENOMEM. This matches common netdev allocation cleanup style.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h6f-g5f3-gc4w

около 3 лет назад

Access Control Bypass in Spring Security

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3h6c-fr7r-7jmg

больше 2 лет назад

TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h6c-c475-jm7v

больше 2 лет назад

Arbitrary Code Execution in Gitea

CVSS3: 7.2
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h6w-w73g-4wv9

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h6w-hjgc-hx7q

Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h6w-92g2-xgrr

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.

CVSS3: 5.4
0%
Низкий
4 дня назад
github логотип
GHSA-3h6v-4pff-pgf4

This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A download's origin may be incorrectly associated.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3h6r-gqmp-9v88

Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h6p-jvww-q7w3

Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3h6m-v52v-hvmw

Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVSS3: 9.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-3h6m-4cmj-f665

Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-3h6m-3jhx-cfg9

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3h6j-9x8m-rg3g

Graby has stored XSS via iframe srcdoc Attribute in htmLawed Sanitization Config

5 месяцев назад
github логотип
GHSA-3h6h-wq56-3w89

The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h6h-v2q2-7mx9

WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3h6h-8756-mj4f

A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2.0. Known Fixed Releases: 6.2.0.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h6h-67x3-cv5x

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

CVSS3: 6.9
0%
Низкий
3 месяца назад
github логотип
GHSA-3h6g-vwfm-p62q

Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h6g-r953-7g4p

An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-3h6g-63ch-8mwf

In the Linux kernel, the following vulnerability has been resolved: net: ftgmac100: fix ring allocation unwind on open failure ftgmac100_alloc_rings() allocates rx_skbs, tx_skbs, rxdes, txdes, and rx_scratch in stages. On intermediate failures it returned -ENOMEM directly, leaking resources allocated earlier in the function. Rework the failure path to use staged local unwind labels and free allocated resources in reverse order before returning -ENOMEM. This matches common netdev allocation cleanup style.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3h6f-g5f3-gc4w

Access Control Bypass in Spring Security

CVSS3: 9.1
4%
Низкий
около 3 лет назад
github логотип
GHSA-3h6c-fr7r-7jmg

TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.

CVSS3: 9.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3h6c-c475-jm7v

Arbitrary Code Execution in Gitea

CVSS3: 7.2
95%
Критический
больше 2 лет назад

Уязвимостей на страницу