Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-34p9-f4q3-c4r7

почти 5 лет назад

Improper Certificate Validation in openssl

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-34p9-8chp-pp4w

больше 4 лет назад

PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parameter.

EPSS: Низкий
github логотип

GHSA-34p8-x6j6-mmg5

около 4 лет назад

There is a buffer overflow vulnerability in Mate 30 10.1.0.126(C00E125R5P3). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause buffer overflow, compromising normal service.

EPSS: Низкий
github логотип

GHSA-34p8-gxhp-7h8f

9 месяцев назад

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34p8-5457-hfg2

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zzmaster WP AntiDDOS allows Reflected XSS. This issue affects WP AntiDDOS: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34p7-67p6-m2pf

почти 2 года назад

The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34p6-3rc2-gm7q

больше 4 лет назад

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-34p5-v4jr-qvw6

около 4 лет назад

Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or show_month parameter to (2) webapp/users/blhistory.jsp or (3) webapp/users/prhistory.jsp.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-34p5-jp77-fcrc

больше 3 лет назад

Command injection in Rancher Git package

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-34p4-vjw3-68hq

больше 2 лет назад

An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .evcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34p4-pf9q-p32p

около 4 лет назад

The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34p4-7w83-35g2

6 месяцев назад

Formwork Improperly Managed Privileges in User creation

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34p3-c86q-c8j4

около 4 лет назад

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_SCRIPT message.

EPSS: Средний
github логотип

GHSA-34p2-9566-jfhx

почти 4 года назад

The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-34mx-7qhf-2323

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: mt6359: Fix refcount leak bug In mt6359_parse_dt() and mt6359_accdet_parse_dt(), we should call of_node_put() for the reference returned by of_get_child_by_name() which has increased the refcount.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-34mx-45mg-p6wm

4 месяца назад

Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34mv-wr5q-834h

6 месяцев назад

A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-34mv-vh59-6543

23 дня назад

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34mv-cg5q-cf3q

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Jobs for WordPress allows Reflected XSS.This issue affects Jobs for WordPress: from n/a through 2.7.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34mr-cvr4-m435

больше 3 лет назад

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34p9-f4q3-c4r7

Improper Certificate Validation in openssl

CVSS3: 8.1
1%
Низкий
почти 5 лет назад
github логотип
GHSA-34p9-8chp-pp4w

PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-34p8-x6j6-mmg5

There is a buffer overflow vulnerability in Mate 30 10.1.0.126(C00E125R5P3). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause buffer overflow, compromising normal service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-34p8-gxhp-7h8f

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-34p8-5457-hfg2

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zzmaster WP AntiDDOS allows Reflected XSS. This issue affects WP AntiDDOS: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-34p7-67p6-m2pf

The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect to a host presenting a certificate included in the revocation file passed to the --crl option.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-34p6-3rc2-gm7q

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).

CVSS3: 8.2
0%
Низкий
больше 4 лет назад
github логотип
GHSA-34p5-v4jr-qvw6

Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or show_month parameter to (2) webapp/users/blhistory.jsp or (3) webapp/users/prhistory.jsp.

CVSS3: 9.8
19%
Средний
около 4 лет назад
github логотип
GHSA-34p5-jp77-fcrc

Command injection in Rancher Git package

CVSS3: 6.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-34p4-vjw3-68hq

An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .evcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34p4-pf9q-p32p

The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-34p4-7w83-35g2

Formwork Improperly Managed Privileges in User creation

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-34p3-c86q-c8j4

Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_SCRIPT message.

14%
Средний
около 4 лет назад
github логотип
GHSA-34p2-9566-jfhx

The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

CVSS3: 2.7
1%
Низкий
почти 4 года назад
github логотип
GHSA-34mx-7qhf-2323

In the Linux kernel, the following vulnerability has been resolved: ASoC: mt6359: Fix refcount leak bug In mt6359_parse_dt() and mt6359_accdet_parse_dt(), we should call of_node_put() for the reference returned by of_get_child_by_name() which has increased the refcount.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-34mx-45mg-p6wm

Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-34mv-wr5q-834h

A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-34mv-vh59-6543

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
0%
Низкий
23 дня назад
github логотип
GHSA-34mv-cg5q-cf3q

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Jobs for WordPress allows Reflected XSS.This issue affects Jobs for WordPress: from n/a through 2.7.5.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34mr-cvr4-m435

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу