Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-3f6j-956j-p8cx

больше 4 лет назад

Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80).

EPSS: Низкий
github логотип

GHSA-3f6j-2cc7-x3qx

больше 4 лет назад

Livingston portmaster machines could be rebooted via a series of commands.

EPSS: Низкий
github логотип

GHSA-3f6j-24pw-57fm

4 месяца назад

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f6h-wmwv-m6rx

больше 4 лет назад

The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may allow for remote code execution. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0; 7.12.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Deployment Kit: versions up to and including 7.8.0; 7.9.0;7.9.1;7.10.0;7.10.1;7.11.0; 7.12.0, TIBCO Spotfire Desktop: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0;7.12.0, TIBCO Spotfire Desktop Language Packs: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f6h-6ch9-p8jv

около 4 лет назад

libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.

EPSS: Низкий
github логотип

GHSA-3f6h-2hrp-w5wx

4 месяца назад

@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

EPSS: Низкий
github логотип

GHSA-3f6g-r82m-2vg5

больше 4 лет назад

Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.

EPSS: Средний
github логотип

GHSA-3f6g-q6j8-gjpg

больше 4 лет назад

Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.

EPSS: Низкий
github логотип

GHSA-3f6g-m4hr-59h8

около 2 лет назад

OpenFGA Authorization Bypass

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3f6g-6p3h-q27p

больше 4 лет назад

PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.

EPSS: Низкий
github логотип

GHSA-3f6c-mv48-pf3v

больше 4 лет назад

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3f6c-7fw2-ppm4

11 месяцев назад

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3f69-xhq6-c8m8

около 4 лет назад

Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3f69-f27h-f53w

почти 2 года назад

The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.

EPSS: Низкий
github логотип

GHSA-3f68-rg4r-xc3q

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f68-9fxg-g2j6

больше 4 лет назад

The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.

EPSS: Низкий
github логотип

GHSA-3f68-6wxq-x593

3 месяца назад

Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3f67-9787-pwrh

больше 3 лет назад

Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption situation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3f67-8v72-vm9p

5 месяцев назад

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the argument cid results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3f66-qjp3-gfq9

около 4 лет назад

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511132; Issue ID: ALPS06511132.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f6j-956j-p8cx

Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80).

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3f6j-2cc7-x3qx

Livingston portmaster machines could be rebooted via a series of commands.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3f6j-24pw-57fm

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-3f6h-wmwv-m6rx

The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may allow for remote code execution. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0; 7.12.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Deployment Kit: versions up to and including 7.8.0; 7.9.0;7.9.1;7.10.0;7.10.1;7.11.0; 7.12.0, TIBCO Spotfire Desktop: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0;7.12.0, TIBCO Spotfire Desktop Language Packs: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3f6h-6ch9-p8jv

libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.

3%
Низкий
около 4 лет назад
github логотип
GHSA-3f6h-2hrp-w5wx

@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

0%
Низкий
4 месяца назад
github логотип
GHSA-3f6g-r82m-2vg5

Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.

34%
Средний
больше 4 лет назад
github логотип
GHSA-3f6g-q6j8-gjpg

Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3f6g-m4hr-59h8

OpenFGA Authorization Bypass

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3f6g-6p3h-q27p

PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3f6c-mv48-pf3v

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.

CVSS3: 9.8
50%
Средний
больше 4 лет назад
github логотип
GHSA-3f6c-7fw2-ppm4

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3f69-xhq6-c8m8

Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-3f69-f27h-f53w

The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.

0%
Низкий
почти 2 года назад
github логотип
GHSA-3f68-rg4r-xc3q

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due to excessive resource consumption when handling certain CI-related inputs.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3f68-9fxg-g2j6

The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3f68-6wxq-x593

Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3f67-9787-pwrh

Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption situation.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f67-8v72-vm9p

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the argument cid results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3f66-qjp3-gfq9

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511132; Issue ID: ALPS06511132.

CVSS3: 6.7
0%
Низкий
около 4 лет назад

Уязвимостей на страницу