Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-37w8-9qwc-jx4h

около 3 лет назад

Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-37w7-m62f-9cgm

4 месяца назад

Missing Authorization vulnerability in acmethemes Education Base education-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Base: from n/a through <= 3.0.8.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-37w7-4pw6-w57q

больше 1 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-25724. Reason: This candidate is a reservation duplicate of CVE-2025-25724. Notes: All CVE users should reference CVE-2025-25724 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

EPSS: Низкий
github логотип

GHSA-37w6-6x86-9rw5

больше 4 лет назад

Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

EPSS: Низкий
github логотип

GHSA-37w5-p3r5-mfjp

больше 4 лет назад

Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.

EPSS: Низкий
github логотип

GHSA-37w5-m4jw-wvfc

больше 1 года назад

A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. This issue affects some unknown processing of the file /admin/admin_action.php. The manipulation of the argument admin_user_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-37w4-w4g6-8f3q

около 4 лет назад

An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (aka VIOM) Windows Management Server 7.x through 7.4.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the \usr\local\ssl\openssl.cnf configuration file, which may not exist. On Windows systems, this path could translate to <drive>:\usr\local\ssl\openssl.cnf, where <drive> could be the default Windows installation drive such as C:\ or the drive where a Veritas product is installed. By default, on Windows systems, users can create directories under any top-level directory. A low privileged user can create a <drive>:\usr\local\ssl\openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attack...

EPSS: Низкий
github логотип

GHSA-37w4-hwhx-4rc4

3 месяца назад

JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37w4-g5xj-jwm8

больше 4 лет назад

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.

EPSS: Низкий
github логотип

GHSA-37w4-f5m7-vm83

больше 4 лет назад

Unspecified vulnerability in the AContact (com.movester.quickcontact) application 1.8.2 for Android has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-37w3-fgfh-xjrf

почти 4 года назад

In vow, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032634; Issue ID: ALPS07032634.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-37w2-vq57-6j63

больше 4 лет назад

eupdatedb in esearch 0.6.1 and earlier allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file.

EPSS: Низкий
github логотип

GHSA-37w2-q6vh-45v6

4 месяца назад

Spring gRPC AuthenticationException messages are reflected to remote client

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-37w2-86g3-h4qh

около 1 месяца назад

Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37vx-v53j-77pr

около 3 лет назад

Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 all versions allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected module by connecting to it via telnet which is hidden function and is enabled by default when shipped from the factory. As a result, a remote attacker with unauthorized login can reset the module, and if certain conditions are met, he/she can disclose or tamper with the module's configuration or rewrite the firmware.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37vv-xjjq-53p5

больше 4 лет назад

Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.

EPSS: Средний
github логотип

GHSA-37vv-65j3-r854

больше 3 лет назад

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of the driver

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-37vr-vmg4-jwpw

больше 2 лет назад

Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-37vr-rqxp-v3j3

6 месяцев назад

DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37vr-rg2q-2j7c

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15538.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37w8-9qwc-jx4h

Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device.

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-37w7-m62f-9cgm

Missing Authorization vulnerability in acmethemes Education Base education-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Base: from n/a through <= 3.0.8.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-37w7-4pw6-w57q

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-25724. Reason: This candidate is a reservation duplicate of CVE-2025-25724. Notes: All CVE users should reference CVE-2025-25724 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

больше 1 года назад
github логотип
GHSA-37w6-6x86-9rw5

Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-37w5-p3r5-mfjp

Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37w5-m4jw-wvfc

A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. This issue affects some unknown processing of the file /admin/admin_action.php. The manipulation of the argument admin_user_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-37w4-w4g6-8f3q

An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (aka VIOM) Windows Management Server 7.x through 7.4.2. On start-up, it loads the OpenSSL library from \usr\local\ssl. This library attempts to load the \usr\local\ssl\openssl.cnf configuration file, which may not exist. On Windows systems, this path could translate to <drive>:\usr\local\ssl\openssl.cnf, where <drive> could be the default Windows installation drive such as C:\ or the drive where a Veritas product is installed. By default, on Windows systems, users can create directories under any top-level directory. A low privileged user can create a <drive>:\usr\local\ssl\openssl.cnf configuration file to load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing the attack...

0%
Низкий
около 4 лет назад
github логотип
GHSA-37w4-hwhx-4rc4

JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-37w4-g5xj-jwm8

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-37w4-f5m7-vm83

Unspecified vulnerability in the AContact (com.movester.quickcontact) application 1.8.2 for Android has unknown impact and attack vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37w3-fgfh-xjrf

In vow, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032634; Issue ID: ALPS07032634.

CVSS3: 4.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-37w2-vq57-6j63

eupdatedb in esearch 0.6.1 and earlier allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-37w2-q6vh-45v6

Spring gRPC AuthenticationException messages are reflected to remote client

CVSS3: 3.7
0%
Низкий
4 месяца назад
github логотип
GHSA-37w2-86g3-h4qh

Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-37vx-v53j-77pr

Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 all versions allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected module by connecting to it via telnet which is hidden function and is enabled by default when shipped from the factory. As a result, a remote attacker with unauthorized login can reset the module, and if certain conditions are met, he/she can disclose or tamper with the module's configuration or rewrite the firmware.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-37vv-xjjq-53p5

Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.

57%
Средний
больше 4 лет назад
github логотип
GHSA-37vv-65j3-r854

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of the driver

CVSS3: 2.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-37vr-vmg4-jwpw

Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets

CVSS3: 8.8
84%
Высокий
больше 2 лет назад
github логотип
GHSA-37vr-rqxp-v3j3

DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-37vr-rg2q-2j7c

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15538.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу