Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-36fv-g9xp-84xv

6 месяцев назад

Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36fv-7fxv-xr4g

больше 4 лет назад

Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.

EPSS: Средний
github логотип

GHSA-36fv-6vjc-jf92

больше 1 года назад

If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-36fr-xc4j-fmhw

около 4 лет назад

Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.

EPSS: Низкий
github логотип

GHSA-36fr-w5h7-5f28

больше 4 лет назад

Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005.

EPSS: Низкий
github логотип

GHSA-36fr-3wg8-q5v8

больше 2 лет назад

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-36fr-2gcj-778v

больше 3 лет назад

A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_parser::Elf_parser::get_segments of the file elf_parser.cpp. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-222222 is the identifier assigned to this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36fq-jgmw-4r9c

11 месяцев назад

Keras is vulnerable to Deserialization of Untrusted Data

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-36fq-6c6v-89gr

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-36fq-3276-7898

почти 2 года назад

A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-36fp-xj79-95mx

больше 4 лет назад

Links may not be rewritten according to policy in some specially formatted emails.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36fm-v9wv-56jf

больше 5 лет назад

Cross-site Scripting in OpenCart

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36fm-j33w-c25f

больше 3 лет назад

Privilege escalation (PR)/RCE from account through class sheet

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-36fm-f9h6-j5xh

около 1 года назад

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36fh-9j3c-fp3f

17 дней назад

Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-36fh-84j7-cv5h

больше 3 лет назад

JSZip contains Path Traversal via loadAsync

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-36fh-2j8m-mpcw

больше 4 лет назад

Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

EPSS: Низкий
github логотип

GHSA-36fg-whr2-g999

почти 3 года назад

Jenkins NodeJS Plugin improper credential masking vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-36fg-v524-g4r4

около 1 года назад

A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-36fg-r84v-4px6

12 месяцев назад

A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36fv-g9xp-84xv

Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-36fv-7fxv-xr4g

Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.

16%
Средний
больше 4 лет назад
github логотип
GHSA-36fv-6vjc-jf92

If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.

CVSS3: 6.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-36fr-xc4j-fmhw

Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.

0%
Низкий
около 4 лет назад
github логотип
GHSA-36fr-w5h7-5f28

Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-36fr-3wg8-q5v8

Concrete CMS Cross-site Scripting vulnerability

CVSS3: 3.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-36fr-2gcj-778v

A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_parser::Elf_parser::get_segments of the file elf_parser.cpp. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-222222 is the identifier assigned to this vulnerability.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36fq-jgmw-4r9c

Keras is vulnerable to Deserialization of Untrusted Data

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-36fq-6c6v-89gr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36fq-3276-7898

A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-36fp-xj79-95mx

Links may not be rewritten according to policy in some specially formatted emails.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36fm-v9wv-56jf

Cross-site Scripting in OpenCart

CVSS3: 5.4
3%
Низкий
больше 5 лет назад
github логотип
GHSA-36fm-j33w-c25f

Privilege escalation (PR)/RCE from account through class sheet

CVSS3: 9.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-36fm-f9h6-j5xh

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-36fh-9j3c-fp3f

Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
0%
Низкий
17 дней назад
github логотип
GHSA-36fh-84j7-cv5h

JSZip contains Path Traversal via loadAsync

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-36fh-2j8m-mpcw

Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-36fg-whr2-g999

Jenkins NodeJS Plugin improper credential masking vulnerability

CVSS3: 4.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-36fg-v524-g4r4

A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-36fg-r84v-4px6

A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 8.8
1%
Низкий
12 месяцев назад

Уязвимостей на страницу