Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 895

Количество 361 895

github логотип

GHSA-3g64-fqmg-p75w

больше 4 лет назад

Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets on the SSH port, aka Bug ID CSCuu13476.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g64-6hgp-5m64

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3g64-2wg6-7p8r

больше 2 лет назад

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g63-p2hp-v8xg

больше 4 лет назад

eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.

EPSS: Низкий
github логотип

GHSA-3g63-2rpp-wc2m

больше 1 года назад

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g62-vr55-m6hc

больше 3 лет назад

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3g62-9qpr-j338

около 4 лет назад

In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.

EPSS: Низкий
github логотип

GHSA-3g62-98rr-25fp

около 4 лет назад

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3g5x-2qp3-gm68

около 2 лет назад

The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g5w-ccf9-qgvg

больше 3 лет назад

In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323133References: N/A

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g5w-6pw7-6hrp

больше 3 лет назад

Path Traversal In Eclipse GlassFish

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g5w-3hx7-q6vh

27 дней назад

In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF in binder_free_transaction() In binder_free_transaction(), the t->to_proc is read under the t->lock. However, once the t->lock is dropped, the to_proc can die in parallel. This leads to a use-after-free error when we attempt to acquire its inner lock right afterwards: ================================================================== BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x1a0 Write of size 4 at addr ffff00001125da70 by task B/672 CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT Hardware name: linux,dummy-virt (DT) Call trace: _raw_spin_lock+0xe4/0x1a0 binder_free_transaction+0x8c/0x320 binder_send_failed_reply+0x21c/0x2f8 binder_thread_release+0x488/0x7e0 binder_ioctl+0x12c0/0x29a0 [...] Allocated by task 675: __kmalloc_cache_noprof+0x174/0x444 binder_open+0x118/0xb70 do_dentry_open+0x374/0x1040 vfs_...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3g5v-m9jm-mw8w

около 4 лет назад

The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g5v-7qvh-xxq4

1 день назад

ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP environment permits URL wrappers. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

EPSS: Низкий
github логотип

GHSA-3g5v-28p4-h3v9

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need to initialize the whole buffer to prevent information leaks. Just use memdup_user().

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3g5r-c4ph-rc9c

больше 1 года назад

A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3g5r-3c4p-wrgj

больше 4 лет назад

A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g5p-qv44-mwhx

3 месяца назад

A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/GetDBDataEx.jsp. Performing a manipulation of the argument strTBName results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3g5p-5p6j-r9qp

больше 2 лет назад

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3g5m-g7r7-6pwf

больше 4 лет назад

get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g64-fqmg-p75w

Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets on the SSH port, aka Bug ID CSCuu13476.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3g64-6hgp-5m64

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6.

CVSS3: 10
1%
Низкий
больше 1 года назад
github логотип
GHSA-3g64-2wg6-7p8r

Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3g63-p2hp-v8xg

eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3g63-2rpp-wc2m

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3g62-vr55-m6hc

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g62-9qpr-j338

In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3g62-98rr-25fp

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

CVSS3: 9.8
19%
Средний
около 4 лет назад
github логотип
GHSA-3g5x-2qp3-gm68

The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' function in versions up to, and including, 2.2.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-3g5w-ccf9-qgvg

In s2mpg11_pmic_probe of s2mpg11-regulator.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-259323133References: N/A

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5w-6pw7-6hrp

Path Traversal In Eclipse GlassFish

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g5w-3hx7-q6vh

In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF in binder_free_transaction() In binder_free_transaction(), the t->to_proc is read under the t->lock. However, once the t->lock is dropped, the to_proc can die in parallel. This leads to a use-after-free error when we attempt to acquire its inner lock right afterwards: ================================================================== BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x1a0 Write of size 4 at addr ffff00001125da70 by task B/672 CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT Hardware name: linux,dummy-virt (DT) Call trace: _raw_spin_lock+0xe4/0x1a0 binder_free_transaction+0x8c/0x320 binder_send_failed_reply+0x21c/0x2f8 binder_thread_release+0x488/0x7e0 binder_ioctl+0x12c0/0x29a0 [...] Allocated by task 675: __kmalloc_cache_noprof+0x174/0x444 binder_open+0x118/0xb70 do_dentry_open+0x374/0x1040 vfs_...

CVSS3: 7.8
0%
Низкий
27 дней назад
github логотип
GHSA-3g5v-m9jm-mw8w

The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-3g5v-7qvh-xxq4

ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP environment permits URL wrappers. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

1 день назад
github логотип
GHSA-3g5v-28p4-h3v9

In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need to initialize the whole buffer to prevent information leaks. Just use memdup_user().

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3g5r-c4ph-rc9c

A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3g5r-3c4p-wrgj

A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3g5p-qv44-mwhx

A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/GetDBDataEx.jsp. Performing a manipulation of the argument strTBName results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3g5p-5p6j-r9qp

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3g5m-g7r7-6pwf

get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу