Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 078

Количество 362 078

github логотип

GHSA-3ghv-w9fm-536c

больше 4 лет назад

IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ghv-qqmp-p6c4

9 месяцев назад

The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3ghv-75mw-fc8f

больше 4 лет назад

Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3ghq-rfpw-jhqx

11 месяцев назад

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3ghq-g9vp-wwq2

почти 3 года назад

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3ghq-53cj-qqmp

10 месяцев назад

An issue was discovered in AnyDesk through 9.0.4. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3ghq-3f49-fr98

почти 4 года назад

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ghp-8r47-4gj4

5 месяцев назад

FoundationAgents MetaGPT vulnerable to eval injection

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3ghp-2qxv-j2hr

больше 4 лет назад

Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.

EPSS: Низкий
github логотип

GHSA-3ghj-wv9w-7vp9

больше 2 лет назад

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3ghj-f9w6-vh8h

больше 4 лет назад

SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.php.

EPSS: Низкий
github логотип

GHSA-3ghh-rm9h-rjcv

больше 4 лет назад

Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long ID3 tag in an MP3 file. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3ghh-mq29-47m6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.

EPSS: Низкий
github логотип

GHSA-3ghh-4p87-43pm

больше 4 лет назад

An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7, and 8000 PC unit. An unauthorized user with physical access to an affected Alaris PC unit may be able to obtain unencrypted wireless network authentication credentials and other sensitive technical data by disassembling the PC unit and accessing the device's flash memory. The Alaris 8015 PC unit, Version 9.7, and the 8000 PC unit store wireless network authentication credentials and other sensitive technical data on internal flash memory. Accessing the internal flash memory of the affected device would require special tools to extract data and carrying out this attack at a healthcare facility would increase the likelihood of detection.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3ghg-3787-w2xr

8 месяцев назад

Spree API has Unauthenticated IDOR - Guest Address

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3ghf-mqfr-9xvw

больше 3 лет назад

A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226272.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3ghf-f72w-2g9p

больше 4 лет назад

AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request

EPSS: Низкий
github логотип

GHSA-3ghf-chw5-4mxm

больше 4 лет назад

The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3ghc-cw76-h292

около 4 лет назад

Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3ghc-2486-hrxh

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd If the power domains are registered first with genpd and *after that* the driver attempts to power them on in the probe sequence, then it is possible that a race condition occurs if genpd tries to power them on in the same time. The same is valid for powering them off before unregistering them from genpd. Attempt to fix race conditions by first removing the domains from genpd and *after that* powering down domains. Also first power up the domains and *after that* register them to genpd.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3ghv-w9fm-536c

IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3ghv-qqmp-p6c4

The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or administrator-privileged service account.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3ghv-75mw-fc8f

Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ghq-rfpw-jhqx

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.

CVSS3: 8.8
24%
Средний
11 месяцев назад
github логотип
GHSA-3ghq-g9vp-wwq2

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-3ghq-53cj-qqmp

An issue was discovered in AnyDesk through 9.0.4. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3ghq-3f49-fr98

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-3ghp-8r47-4gj4

FoundationAgents MetaGPT vulnerable to eval injection

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3ghp-2qxv-j2hr

Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3ghj-wv9w-7vp9

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

CVSS3: 9.8
4%
Низкий
больше 2 лет назад
github логотип
GHSA-3ghj-f9w6-vh8h

SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ghh-rm9h-rjcv

Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long ID3 tag in an MP3 file. NOTE: some of these details are obtained from third party information.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3ghh-mq29-47m6

Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3ghh-4p87-43pm

An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7, and 8000 PC unit. An unauthorized user with physical access to an affected Alaris PC unit may be able to obtain unencrypted wireless network authentication credentials and other sensitive technical data by disassembling the PC unit and accessing the device's flash memory. The Alaris 8015 PC unit, Version 9.7, and the 8000 PC unit store wireless network authentication credentials and other sensitive technical data on internal flash memory. Accessing the internal flash memory of the affected device would require special tools to extract data and carrying out this attack at a healthcare facility would increase the likelihood of detection.

CVSS3: 4.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ghg-3787-w2xr

Spree API has Unauthenticated IDOR - Guest Address

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3ghf-mqfr-9xvw

A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226272.

CVSS3: 6.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3ghf-f72w-2g9p

AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3ghf-chw5-4mxm

The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ghc-cw76-h292

Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-3ghc-2486-hrxh

In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd If the power domains are registered first with genpd and *after that* the driver attempts to power them on in the probe sequence, then it is possible that a race condition occurs if genpd tries to power them on in the same time. The same is valid for powering them off before unregistering them from genpd. Attempt to fix race conditions by first removing the domains from genpd and *after that* powering down domains. Also first power up the domains and *after that* register them to genpd.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу