Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-3829-mgmw-jcg4

около 4 лет назад

Prototype Pollution in deep.assign

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3828-pjxx-wp2j

9 месяцев назад

Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3828-jgm6-f988

больше 4 лет назад

Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.

EPSS: Низкий
github логотип

GHSA-3827-x3c5-9qvc

больше 4 лет назад

Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization.

EPSS: Низкий
github логотип

GHSA-3827-2vw5-3pm3

больше 1 года назад

An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by sending a malicious RPC packet.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3826-wfx9-8758

3 месяца назад

A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3826-h8f4-w96h

почти 2 года назад

The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all versions up to, and including, 11.1.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3825-9v33-mrxq

больше 1 года назад

A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3825-537p-gqw4

почти 3 года назад

Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3825-4xhp-w9cc

около 4 лет назад

Windows Backup Engine Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3824-qmfq-2qv7

больше 1 года назад

SurrealDB no JavaScript script function default timeout could facilitate DoS

EPSS: Низкий
github логотип

GHSA-3823-wj6r-jpc9

больше 4 лет назад

gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-3823-hjpv-24g4

больше 4 лет назад

An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3823-3p6j-72p3

больше 4 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3822-wwjm-jgg2

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3822-8jq8-pqhh

6 месяцев назад

The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in the victim's browser if the victim opens a URL prepared by the attacker.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37xx-h5fj-hm7p

около 4 лет назад

A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remote code execution by an authenticated attacker. This is similar to CVE-2018-17317.

EPSS: Низкий
github логотип

GHSA-37xx-h4m8-x8wx

больше 4 лет назад

Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.

EPSS: Низкий
github логотип

GHSA-37xx-8cjj-f57x

около 4 лет назад

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182283.

EPSS: Низкий
github логотип

GHSA-37xx-7qg6-2w7h

больше 4 лет назад

Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3829-mgmw-jcg4

Prototype Pollution in deep.assign

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-3828-pjxx-wp2j

Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3828-jgm6-f988

Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-3827-x3c5-9qvc

Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3827-2vw5-3pm3

An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by sending a malicious RPC packet.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3826-wfx9-8758

A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3826-h8f4-w96h

The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all versions up to, and including, 11.1.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3825-9v33-mrxq

A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3825-537p-gqw4

Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3825-4xhp-w9cc

Windows Backup Engine Information Disclosure Vulnerability

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3824-qmfq-2qv7

SurrealDB no JavaScript script function default timeout could facilitate DoS

больше 1 года назад
github логотип
GHSA-3823-wj6r-jpc9

gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3823-hjpv-24g4

An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3823-3p6j-72p3

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3822-wwjm-jgg2

Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3822-8jq8-pqhh

The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in the victim's browser if the victim opens a URL prepared by the attacker.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-37xx-h5fj-hm7p

A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remote code execution by an authenticated attacker. This is similar to CVE-2018-17317.

3%
Низкий
около 4 лет назад
github логотип
GHSA-37xx-h4m8-x8wx

Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37xx-8cjj-f57x

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182283.

1%
Низкий
около 4 лет назад
github логотип
GHSA-37xx-7qg6-2w7h

Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу