Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35p4-9mmc-6xh6

больше 4 лет назад

SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-35p4-8325-mm2c

больше 2 лет назад

Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layouts for Elementor: from n/a before 1.8.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35p3-6j45-prwm

больше 1 года назад

Aim Uncontrolled Resource Consumption vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35p2-v8mc-67vh

больше 1 года назад

Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-35p2-9fg3-f2p2

около 3 лет назад

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35p2-8gmg-pp6j

больше 2 лет назад

Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command with the root privilege via the internet.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35p2-5vrh-m3p6

больше 1 года назад

DevDojo Voyager Arbitrary File Write

CVSS3: 4.3
EPSS: Средний
github логотип

GHSA-35mx-p6x7-pwmc

больше 4 лет назад

An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35mw-5vvr-vrxc

3 месяца назад

OpenClaw contains a symlink traversal vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35mv-vrc8-4x74

больше 4 лет назад

The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35mv-px68-wh6h

больше 4 лет назад

SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c allows remote attackers to execute arbitrary SQL commands via the entryid parameter in a comment_add action.

EPSS: Низкий
github логотип

GHSA-35mv-96c3-9q8w

около 4 лет назад

Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35mv-64rp-pmf8

больше 4 лет назад

Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-35mr-9r8x-gpfr

больше 4 лет назад

The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.

EPSS: Низкий
github логотип

GHSA-35mr-3g6g-qqwc

около 4 лет назад

courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.

EPSS: Низкий
github логотип

GHSA-35mq-8mc3-vcm8

больше 4 лет назад

OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.

EPSS: Низкий
github логотип

GHSA-35mm-cc6r-8fjp

больше 5 лет назад

Cross-site scripting in actionpack

CVSS3: 6.1
EPSS: Высокий
github логотип

GHSA-35mm-49c2-78fg

больше 4 лет назад

The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).

EPSS: Низкий
github логотип

GHSA-35mj-pjqh-8j57

около 4 лет назад

The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allows remote attackers to execute operating-system commands via vectors involving a session on TCP port 7870, aka Bug ID CSCtz67038.

EPSS: Низкий
github логотип

GHSA-35mj-p5wm-c7vw

около 4 лет назад

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Memory corruption vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35p4-9mmc-6xh6

SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35p4-8325-mm2c

Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layouts for Elementor: from n/a before 1.8.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35p3-6j45-prwm

Aim Uncontrolled Resource Consumption vulnerability

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-35p2-v8mc-67vh

Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-35p2-9fg3-f2p2

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-35p2-8gmg-pp6j

Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command with the root privilege via the internet.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35p2-5vrh-m3p6

DevDojo Voyager Arbitrary File Write

CVSS3: 4.3
13%
Средний
больше 1 года назад
github логотип
GHSA-35mx-p6x7-pwmc

An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-35mw-5vvr-vrxc

OpenClaw contains a symlink traversal vulnerability

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-35mv-vrc8-4x74

The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mv-px68-wh6h

SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c allows remote attackers to execute arbitrary SQL commands via the entryid parameter in a comment_add action.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-35mv-96c3-9q8w

Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-35mv-64rp-pmf8

Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-35mr-9r8x-gpfr

The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mr-3g6g-qqwc

courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.

7%
Низкий
около 4 лет назад
github логотип
GHSA-35mq-8mc3-vcm8

OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-35mm-cc6r-8fjp

Cross-site scripting in actionpack

CVSS3: 6.1
71%
Высокий
больше 5 лет назад
github логотип
GHSA-35mm-49c2-78fg

The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35mj-pjqh-8j57

The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allows remote attackers to execute operating-system commands via vectors involving a session on TCP port 7870, aka Bug ID CSCtz67038.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35mj-p5wm-c7vw

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Memory corruption vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
3%
Низкий
около 4 лет назад

Уязвимостей на страницу