Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35vm-xh8x-vfc2

больше 4 лет назад

Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.

EPSS: Средний
github логотип

GHSA-35vm-p7h9-q944

около 4 лет назад

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files via a direct request to a URL, aka Bug ID CSCum46495.

EPSS: Низкий
github логотип

GHSA-35vj-pjgj-gmmg

около 4 лет назад

Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.

EPSS: Низкий
github логотип

GHSA-35vj-j37m-2rfx

больше 1 года назад

Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-35vj-82w2-vv85

больше 4 лет назад

Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

EPSS: Низкий
github логотип

GHSA-35vj-78r5-pwj5

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-35vg-mphp-6q6c

больше 4 лет назад

Multiple buffer overflows in the web interface on the D-Link DI-524 router allow remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact via (1) a long username or (2) an HTTP header with a large name and an empty value.

EPSS: Низкий
github логотип

GHSA-35vf-vw9f-q3cr

3 месяца назад

Duplicate Advisory: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35vc-w93w-75c2

около 5 лет назад

JWT leak via Open Redirect in Programmatic access

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-35vc-3vm2-6c46

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35v9-p68v-wpm7

больше 4 лет назад

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35v9-p644-6gff

8 месяцев назад

Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.12.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35v9-jfrh-47jx

около 4 лет назад

Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-35v9-54h8-hx2c

больше 4 лет назад

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant from a more serious issue such as directory traversal.

EPSS: Низкий
github логотип

GHSA-35v9-42cw-vgg3

больше 4 лет назад

proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35v8-x66v-gw3q

около 4 лет назад

The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which allows remote attackers to modify internal read-only data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file, as demonstrated by modifying a C# struct.

EPSS: Низкий
github логотип

GHSA-35v8-f3m3-88h6

больше 4 лет назад

The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access can use this vulnerability to modify the file system as root.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35v7-q7c2-qg94

больше 1 года назад

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0 and 22.12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35v6-xwx8-cj7m

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: clk: thead: th1520-ap: set all AXI clocks to CLK_IS_CRITICAL The AXI crossbar of TH1520 has no proper timeout handling, which means gating AXI clocks can easily lead to bus timeout and thus system hang. Set all AXI clock gates to CLK_IS_CRITICAL. All these clock gates are ungated by default on system reset. In addition, convert all current CLK_IGNORE_UNUSED usage to CLK_IS_CRITICAL to prevent unwanted clock gating.

EPSS: Низкий
github логотип

GHSA-35v6-pv3q-68m3

почти 4 года назад

A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210840.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35vm-xh8x-vfc2

Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.

13%
Средний
больше 4 лет назад
github логотип
GHSA-35vm-p7h9-q944

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files via a direct request to a URL, aka Bug ID CSCum46495.

2%
Низкий
около 4 лет назад
github логотип
GHSA-35vj-pjgj-gmmg

Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.

0%
Низкий
около 4 лет назад
github логотип
GHSA-35vj-j37m-2rfx

Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.

CVSS3: 6.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-35vj-82w2-vv85

Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-35vj-78r5-pwj5

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
около 4 лет назад
github логотип
GHSA-35vg-mphp-6q6c

Multiple buffer overflows in the web interface on the D-Link DI-524 router allow remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact via (1) a long username or (2) an HTTP header with a large name and an empty value.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35vf-vw9f-q3cr

Duplicate Advisory: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens

CVSS3: 7.8
3 месяца назад
github логотип
GHSA-35vc-w93w-75c2

JWT leak via Open Redirect in Programmatic access

CVSS3: 6.3
1%
Низкий
около 5 лет назад
github логотип
GHSA-35vc-3vm2-6c46

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-35v9-p68v-wpm7

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35v9-p644-6gff

Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.12.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-35v9-jfrh-47jx

Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

4%
Низкий
около 4 лет назад
github логотип
GHSA-35v9-54h8-hx2c

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant from a more serious issue such as directory traversal.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35v9-42cw-vgg3

proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35v8-x66v-gw3q

The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properly restrict data types, which allows remote attackers to modify internal read-only data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file, as demonstrated by modifying a C# struct.

3%
Низкий
около 4 лет назад
github логотип
GHSA-35v8-f3m3-88h6

The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access can use this vulnerability to modify the file system as root.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35v7-q7c2-qg94

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0 and 22.12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and ...

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-35v6-xwx8-cj7m

In the Linux kernel, the following vulnerability has been resolved: clk: thead: th1520-ap: set all AXI clocks to CLK_IS_CRITICAL The AXI crossbar of TH1520 has no proper timeout handling, which means gating AXI clocks can easily lead to bus timeout and thus system hang. Set all AXI clock gates to CLK_IS_CRITICAL. All these clock gates are ungated by default on system reset. In addition, convert all current CLK_IGNORE_UNUSED usage to CLK_IS_CRITICAL to prevent unwanted clock gating.

0%
Низкий
8 месяцев назад
github логотип
GHSA-35v6-pv3q-68m3

A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210840.

CVSS3: 5.4
0%
Низкий
почти 4 года назад

Уязвимостей на страницу