Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-2x38-7mv7-h86v

около 4 лет назад

A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2x38-48vp-w23x

7 месяцев назад

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2x37-xp38-hq9m

около 4 лет назад

A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp, MobileQIS_Login.asp, QIS_wizard.htma, YandexDNS.asp, ajax_status.xml, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.asp.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2x37-ffq7-5322

больше 3 лет назад

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2x36-vr7v-9hpm

почти 3 года назад

Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2x36-qhx3-7m5f

около 2 лет назад

ZendFramework1 Potential SQL injection in the ORDER implementation of Zend_Db_Select

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2x36-7xfm-pgm7

больше 4 лет назад

Moodle default permissions too permissive

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2x35-j3p2-5qfh

около 4 лет назад

A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. Known Affected Releases: 2.2(1).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x35-3fw4-9jr4

19 дней назад

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

EPSS: Низкий
github логотип

GHSA-2x35-3575-64cp

около 3 лет назад

Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2x34-p5xr-4cq8

8 месяцев назад

User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2x34-7fj8-wmcv

около 4 лет назад

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2x34-356c-v9qp

около 4 лет назад

TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2x33-pfvq-675c

больше 2 лет назад

The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2x32-mwgm-xpr7

около 4 лет назад

Directory Traversal in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2x32-jv72-rchp

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation allows Stored XSS. This issue affects Graceful Email Obfuscation: from n/a through 0.2.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2x32-jm95-2cpx

больше 4 лет назад

Authentication Bypass in dex

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2x32-fffh-53mr

около 4 лет назад

KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host OS privileges or cause a denial of service (out-of-bounds array access and host OS crash) via a crafted interrupt request, related to arch/x86/kvm/ioapic.c and arch/x86/kvm/ioapic.h.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2x32-727m-44f2

больше 4 лет назад

Denial of service in Linux 2.2.0 running the ldd command on a core file.

EPSS: Низкий
github логотип

GHSA-2x32-6qfg-28pg

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the removeField property of a app object. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6849.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2x38-7mv7-h86v

A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2x38-48vp-w23x

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

CVSS3: 9.8
86%
Высокий
7 месяцев назад
github логотип
GHSA-2x37-xp38-hq9m

A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp, MobileQIS_Login.asp, QIS_wizard.htma, YandexDNS.asp, ajax_status.xml, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.asp.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2x37-ffq7-5322

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2x36-vr7v-9hpm

Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-2x36-qhx3-7m5f

ZendFramework1 Potential SQL injection in the ORDER implementation of Zend_Db_Select

CVSS3: 9.8
около 2 лет назад
github логотип
GHSA-2x36-7xfm-pgm7

Moodle default permissions too permissive

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2x35-j3p2-5qfh

A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. Known Affected Releases: 2.2(1).

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2x35-3fw4-9jr4

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

19 дней назад
github логотип
GHSA-2x35-3575-64cp

Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2x34-p5xr-4cq8

User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2x34-7fj8-wmcv

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072.

CVSS3: 8.8
22%
Средний
около 4 лет назад
github логотип
GHSA-2x34-356c-v9qp

TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2x33-pfvq-675c

The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2x32-mwgm-xpr7

Directory Traversal in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.

CVSS3: 7.5
20%
Средний
около 4 лет назад
github логотип
GHSA-2x32-jv72-rchp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation allows Stored XSS. This issue affects Graceful Email Obfuscation: from n/a through 0.2.2.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2x32-jm95-2cpx

Authentication Bypass in dex

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2x32-fffh-53mr

KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host OS privileges or cause a denial of service (out-of-bounds array access and host OS crash) via a crafted interrupt request, related to arch/x86/kvm/ioapic.c and arch/x86/kvm/ioapic.h.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2x32-727m-44f2

Denial of service in Linux 2.2.0 running the ldd command on a core file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2x32-6qfg-28pg

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the removeField property of a app object. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6849.

CVSS3: 8.8
3%
Низкий
около 4 лет назад

Уязвимостей на страницу