Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-33f5-5f45-vcqg

около 4 лет назад

Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-33f4-xj2w-x86q

больше 1 года назад

A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper authorization. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-33f4-mjch-7fpr

10 месяцев назад

Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

EPSS: Низкий
github логотип

GHSA-33f4-9prw-vfp6

почти 4 года назад

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33f4-9hr4-253g

около 4 лет назад

A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An attacker could exploit this vulnerability by sending properly formatted data values to the statistics collection service of an affected device. A successful exploit could allow the attacker to cause the web interface statistics view to present invalid data to users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33f3-88p6-j3f9

больше 2 лет назад

TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33f2-v5w3-mmvw

около 1 года назад

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-33f2-r445-jvq6

около 4 лет назад

Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file following after call_mmap() returns an error. However, the aufs patchs change mmap_region() to replace the fput() using a local variable with vma_fput(), which will fput() vm_file, leading to a refcount underflow.

EPSS: Низкий
github логотип

GHSA-33f2-chfr-x425

около 4 лет назад

Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.

EPSS: Низкий
github логотип

GHSA-33f2-544v-wh7x

больше 4 лет назад

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33cx-2vvq-mf52

больше 1 года назад

Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.

EPSS: Низкий
github логотип

GHSA-33cw-rfhq-85q4

больше 3 лет назад

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33cw-f6c5-2rv7

больше 1 года назад

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-33cw-2rgg-pqmh

больше 4 лет назад

SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.

EPSS: Низкий
github логотип

GHSA-33cv-rf7v-r5m4

около 4 лет назад

The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6; Skype for Business 2016; Lync 2010; Lync 2013 SP1; Live Meeting 2007 Console; and Silverlight 5 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-33cv-ffrg-w682

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-33cr-xf9m-fqqr

почти 4 года назад

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33cr-m232-xqch

больше 1 года назад

cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement

EPSS: Низкий
github логотип

GHSA-33cr-5mgj-3gg9

около 4 лет назад

An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) Physical-to-Machine (P2M) errors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33cr-4mvf-fj5r

около 4 лет назад

IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 128689.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33f5-5f45-vcqg

Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.

CVSS3: 7.5
10%
Средний
около 4 лет назад
github логотип
GHSA-33f4-xj2w-x86q

A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper authorization. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-33f4-mjch-7fpr

Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

0%
Низкий
10 месяцев назад
github логотип
GHSA-33f4-9prw-vfp6

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-33f4-9hr4-253g

A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An attacker could exploit this vulnerability by sending properly formatted data values to the statistics collection service of an affected device. A successful exploit could allow the attacker to cause the web interface statistics view to present invalid data to users.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-33f3-88p6-j3f9

TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-33f2-v5w3-mmvw

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-33f2-r445-jvq6

Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file following after call_mmap() returns an error. However, the aufs patchs change mmap_region() to replace the fput() using a local variable with vma_fput(), which will fput() vm_file, leading to a refcount underflow.

1%
Низкий
около 4 лет назад
github логотип
GHSA-33f2-chfr-x425

Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.

1%
Низкий
около 4 лет назад
github логотип
GHSA-33f2-544v-wh7x

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-33cx-2vvq-mf52

Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.

0%
Низкий
больше 1 года назад
github логотип
GHSA-33cw-rfhq-85q4

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33cw-f6c5-2rv7

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-33cw-2rgg-pqmh

SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-33cv-rf7v-r5m4

The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6; Skype for Business 2016; Lync 2010; Lync 2013 SP1; Live Meeting 2007 Console; and Silverlight 5 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."

26%
Средний
около 4 лет назад
github логотип
GHSA-33cv-ffrg-w682

Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-33cr-xf9m-fqqr

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-33cr-m232-xqch

cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement

больше 1 года назад
github логотип
GHSA-33cr-5mgj-3gg9

An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) Physical-to-Machine (P2M) errors.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-33cr-4mvf-fj5r

IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 128689.

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу