Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 937

Количество 360 937

github логотип

GHSA-3c7c-p4m9-gwhc

больше 3 лет назад

Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3c7c-8hj4-v9qh

почти 2 года назад

In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.

EPSS: Низкий
github логотип

GHSA-3c7c-8h8f-3p6v

больше 4 лет назад

Use After Free in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3c79-rgf5-v4gg

больше 4 лет назад

Stack-based buffer overflow in the request handling implementation in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary code via an unspecified string field.

EPSS: Низкий
github логотип

GHSA-3c78-wrg5-fqxr

около 2 лет назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3c78-m682-8wp9

больше 4 лет назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3c77-w2fc-xqrh

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3c77-6pw4-hr87

около 2 лет назад

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3c76-p447-jmg2

почти 2 года назад

HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3c75-fpmc-wjhf

больше 2 лет назад

Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3c75-76g3-hcrx

8 месяцев назад

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3c74-p5qr-hhhx

10 месяцев назад

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3c74-j4f2-pjxv

около 2 лет назад

A vulnerability has been found in Mp3tag up to 3.26d and classified as problematic. This vulnerability affects unknown code in the library tak_deco_lib.dll of the component DLL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 3.26e is able to address this issue. It is recommended to upgrade the affected component. VDB-272614 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3c74-ghrj-c3gp

около 4 лет назад

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3c73-87fp-87pp

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xylus Themes WP Event Aggregator allows Stored XSS.This issue affects WP Event Aggregator: from n/a through 1.7.9.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3c73-5g33-8g22

9 месяцев назад

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the the BIOS menu because is has no password.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-3c72-cvwm-9gqx

22 дня назад

Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol path within the standard FTP listener pre-authentication to leak timing information from the FTP 331 response without requiring a separate port or configuration change.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3c6v-c67v-hx4q

около 4 лет назад

UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3c6v-88wh-34ph

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: do not write to msg_get_inq in callee NULL pointer dereference fix. msg_get_inq is an input field from caller to callee. Don't set it in the callee, as the caller may not clear it on struct reuse. This is a kernel-internal variant of msghdr only, and the only user does reinitialize the field. So this is not critical for that reason. But it is more robust to avoid the write, and slightly simpler code. And it fixes a bug, see below. Callers set msg_get_inq to request the input queue length to be returned in msg_inq. This is equivalent to but independent from the SO_INQ request to return that same info as a cmsg (tp->recvmsg_inq). To reduce branching in the hot path the second also sets the msg_inq. That is WAI. This is a fix to commit 4d1442979e4a ("af_unix: don't post cmsg for SO_INQ unless explicitly asked for"), which fixed the inverse. Also avoid NULL pointer dereference in unix_stream_read_generic if ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3c6r-mxqj-c794

больше 4 лет назад

The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of service (tunnel crash) via crafted (1) DELETE (ISAKMP_NPTYPE_D) and (2) NOTIFY (ISAKMP_NPTYPE_N) messages.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3c7c-p4m9-gwhc

Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c7c-8hj4-v9qh

In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.

0%
Низкий
почти 2 года назад
github логотип
GHSA-3c7c-8h8f-3p6v

Use After Free in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3c79-rgf5-v4gg

Stack-based buffer overflow in the request handling implementation in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary code via an unspecified string field.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3c78-wrg5-fqxr

The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 6.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-3c78-m682-8wp9

ChakraCore RCE Vulnerability

CVSS3: 7.5
9%
Низкий
больше 4 лет назад
github логотип
GHSA-3c77-w2fc-xqrh

Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3c77-6pw4-hr87

Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

CVSS3: 8.3
3%
Низкий
около 2 лет назад
github логотип
GHSA-3c76-p447-jmg2

HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.

CVSS3: 5.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3c75-fpmc-wjhf

Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3c75-76g3-hcrx

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.

CVSS3: 9.9
4%
Низкий
8 месяцев назад
github логотип
GHSA-3c74-p5qr-hhhx

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3c74-j4f2-pjxv

A vulnerability has been found in Mp3tag up to 3.26d and classified as problematic. This vulnerability affects unknown code in the library tak_deco_lib.dll of the component DLL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Upgrading to version 3.26e is able to address this issue. It is recommended to upgrade the affected component. VDB-272614 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3c74-ghrj-c3gp

GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3c73-87fp-87pp

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xylus Themes WP Event Aggregator allows Stored XSS.This issue affects WP Event Aggregator: from n/a through 1.7.9.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3c73-5g33-8g22

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the the BIOS menu because is has no password.

CVSS3: 4.6
0%
Низкий
9 месяцев назад
github логотип
GHSA-3c72-cvwm-9gqx

Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol path within the standard FTP listener pre-authentication to leak timing information from the FTP 331 response without requiring a separate port or configuration change.

CVSS3: 5.3
0%
Низкий
22 дня назад
github логотип
GHSA-3c6v-c67v-hx4q

UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-3c6v-88wh-34ph

In the Linux kernel, the following vulnerability has been resolved: net: do not write to msg_get_inq in callee NULL pointer dereference fix. msg_get_inq is an input field from caller to callee. Don't set it in the callee, as the caller may not clear it on struct reuse. This is a kernel-internal variant of msghdr only, and the only user does reinitialize the field. So this is not critical for that reason. But it is more robust to avoid the write, and slightly simpler code. And it fixes a bug, see below. Callers set msg_get_inq to request the input queue length to be returned in msg_inq. This is equivalent to but independent from the SO_INQ request to return that same info as a cmsg (tp->recvmsg_inq). To reduce branching in the hot path the second also sets the msg_inq. That is WAI. This is a fix to commit 4d1442979e4a ("af_unix: don't post cmsg for SO_INQ unless explicitly asked for"), which fixed the inverse. Also avoid NULL pointer dereference in unix_stream_read_generic if ...

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-3c6r-mxqj-c794

The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of service (tunnel crash) via crafted (1) DELETE (ISAKMP_NPTYPE_D) and (2) NOTIFY (ISAKMP_NPTYPE_N) messages.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу