Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-2x53-x293-3jfh

около 4 лет назад

A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x53-jv7f-c2x5

около 2 лет назад

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2x53-82m9-jcgf

27 дней назад

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2x52-8f29-7cjr

больше 2 лет назад

Eclipse Dataspace Components vulnerable to OAuth2 client secret disclosure

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2x4x-xw83-gw6x

больше 1 года назад

Uncontrolled search path element in some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2x4x-fh63-4wpq

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2x4x-cc5g-qmmg

4 месяца назад

OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2x4x-73fj-7gr8

около 4 лет назад

NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of privileges. Android ID: A-62540032 Severity Rating: High Version: N/A.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2x4w-j73f-g9qq

почти 3 года назад

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/list_onlineuser.php. The manipulation of the argument SessionId leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243716. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2x4w-2j26-p5hx

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor lengths While the MIDI jacks are configured correctly, and the MIDIStreaming endpoint descriptors are filled with the correct information, bNumEmbMIDIJack and bLength are set incorrectly in these descriptors. This does not matter when the numbers of in and out ports are equal, but when they differ the host will receive broken descriptors with uninitialized stack memory leaking into the descriptor for whichever value is smaller. The precise meaning of "in" and "out" in the port counts is not clearly defined and can be confusing. But elsewhere the driver consistently uses this to match the USB meaning of IN and OUT viewed from the host, so that "in" ports send data to the host and "out" ports receive data from it.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2x4v-g8cx-jxrq

около 4 лет назад

Login timing attack in ibexa/core

EPSS: Низкий
github логотип

GHSA-2x4v-3mr5-58j8

почти 3 года назад

D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerability allows attackers to execute arbitrary commands via the update.device.packet-capture.tftp-file-name parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2x4r-f9mj-r6xq

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Pramschufer AppBanners allows Stored XSS. This issue affects AppBanners: from n/a through 1.5.14.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2x4q-vchp-x653

около 3 лет назад

Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2x4q-v57w-v4wv

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hafiz Uddin Ahmed Crazy Call To Action Box allows Stored XSS.This issue affects Crazy Call To Action Box: from n/a through 1.0.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x4q-h3hx-hhh6

около 1 года назад

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2x4q-6jfv-8h9h

около 8 лет назад

Path Traversal in glance

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x4p-3235-5xfj

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPCOM WPCOM Member allows Reflected XSS.This issue affects WPCOM Member: from n/a through 1.5.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2x4m-j49r-v72m

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject web script or HTML via the (1) name, (2) email, (3) add, and (4) wName parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2x4m-h7p8-49cx

11 месяцев назад

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2x53-x293-3jfh

A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

CVSS3: 6.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-2x53-jv7f-c2x5

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.

CVSS3: 7.6
2%
Низкий
около 2 лет назад
github логотип
GHSA-2x53-82m9-jcgf

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
27 дней назад
github логотип
GHSA-2x52-8f29-7cjr

Eclipse Dataspace Components vulnerable to OAuth2 client secret disclosure

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2x4x-xw83-gw6x

Uncontrolled search path element in some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-2x4x-fh63-4wpq

Cross-site scripting (XSS) vulnerability in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2x4x-cc5g-qmmg

OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2x4x-73fj-7gr8

NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of privileges. Android ID: A-62540032 Severity Rating: High Version: N/A.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2x4w-j73f-g9qq

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/list_onlineuser.php. The manipulation of the argument SessionId leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243716. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

CVSS3: 5.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-2x4w-2j26-p5hx

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor lengths While the MIDI jacks are configured correctly, and the MIDIStreaming endpoint descriptors are filled with the correct information, bNumEmbMIDIJack and bLength are set incorrectly in these descriptors. This does not matter when the numbers of in and out ports are equal, but when they differ the host will receive broken descriptors with uninitialized stack memory leaking into the descriptor for whichever value is smaller. The precise meaning of "in" and "out" in the port counts is not clearly defined and can be confusing. But elsewhere the driver consistently uses this to match the USB meaning of IN and OUT viewed from the host, so that "in" ports send data to the host and "out" ports receive data from it.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2x4v-g8cx-jxrq

Login timing attack in ibexa/core

около 4 лет назад
github логотип
GHSA-2x4v-3mr5-58j8

D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerability allows attackers to execute arbitrary commands via the update.device.packet-capture.tftp-file-name parameter.

CVSS3: 9.8
2%
Низкий
почти 3 года назад
github логотип
GHSA-2x4r-f9mj-r6xq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Pramschufer AppBanners allows Stored XSS. This issue affects AppBanners: from n/a through 1.5.14.

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-2x4q-vchp-x653

Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2x4q-v57w-v4wv

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hafiz Uddin Ahmed Crazy Call To Action Box allows Stored XSS.This issue affects Crazy Call To Action Box: from n/a through 1.0.5.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2x4q-h3hx-hhh6

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2x4q-6jfv-8h9h

Path Traversal in glance

CVSS3: 6.5
1%
Низкий
около 8 лет назад
github логотип
GHSA-2x4p-3235-5xfj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPCOM WPCOM Member allows Reflected XSS.This issue affects WPCOM Member: from n/a through 1.5.4.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2x4m-j49r-v72m

Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject web script or HTML via the (1) name, (2) email, (3) add, and (4) wName parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2x4m-h7p8-49cx

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

CVSS3: 8.8
0%
Низкий
11 месяцев назад

Уязвимостей на страницу