Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-2vw7-9m84-rphf

больше 4 лет назад

Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL.

EPSS: Низкий
github логотип

GHSA-2vw7-5jhc-pc89

больше 4 лет назад

Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vw6-vp5j-cgp9

больше 4 лет назад

finger .@host on some systems may print information on some user accounts.

EPSS: Низкий
github логотип

GHSA-2vw6-5f85-h22m

больше 1 года назад

Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.

EPSS: Низкий
github логотип

GHSA-2vw5-mf9h-8p68

4 месяца назад

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2vw5-8fhm-cvqc

больше 4 лет назад

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vw5-8crq-9vmf

больше 4 лет назад

The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of service (CPU consumption and error-message flood) by attempting to mount a crafted ext4 filesystem.

EPSS: Низкий
github логотип

GHSA-2vw4-j4g8-m4r4

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index.php in NC LinkList 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) view parameters.

EPSS: Низкий
github логотип

GHSA-2vw3-r555-jwcc

больше 3 лет назад

Unauthenticated denial of service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vw3-5xf5-vwq6

2 дня назад

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2vw3-5r88-9c5p

3 месяца назад

A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly creating a race condition potentially leading to a loss of integrity.

EPSS: Низкий
github логотип

GHSA-2vw2-h5mp-gfhw

больше 4 лет назад

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vw2-587w-g9v6

больше 4 лет назад

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vvx-6336-xm8p

10 месяцев назад

A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing manipulation of the argument ename can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2vvx-5g27-9gvj

почти 3 года назад

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2vvw-3422-x4g5

больше 4 лет назад

Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first argument to the Archive method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2vvv-3xfp-234v

7 месяцев назад

Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vvr-5757-qp87

около 4 лет назад

Open redirect vulnerability in Jenkins CAS Plugin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2vvq-r7r7-rh56

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, or the (2) search parameter or (3) theme cookie to (b) recherche.php.

EPSS: Низкий
github логотип

GHSA-2vvq-mgpq-88xw

около 2 лет назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vw7-9m84-rphf

Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2vw7-5jhc-pc89

Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2vw6-vp5j-cgp9

finger .@host on some systems may print information on some user accounts.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2vw6-5f85-h22m

Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.

0%
Низкий
больше 1 года назад
github логотип
GHSA-2vw5-mf9h-8p68

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 9.8
16%
Средний
4 месяца назад
github логотип
GHSA-2vw5-8fhm-cvqc

TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2vw5-8crq-9vmf

The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of service (CPU consumption and error-message flood) by attempting to mount a crafted ext4 filesystem.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2vw4-j4g8-m4r4

Multiple cross-site scripting (XSS) vulnerabilities in index.php in NC LinkList 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) view parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2vw3-r555-jwcc

Unauthenticated denial of service

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vw3-5xf5-vwq6

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
0%
Низкий
2 дня назад
github логотип
GHSA-2vw3-5r88-9c5p

A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly creating a race condition potentially leading to a loss of integrity.

0%
Низкий
3 месяца назад
github логотип
GHSA-2vw2-h5mp-gfhw

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2vw2-587w-g9v6

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-2vvx-6336-xm8p

A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing manipulation of the argument ename can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2vvx-5g27-9gvj

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.

CVSS3: 7.5
26%
Средний
почти 3 года назад
github логотип
GHSA-2vvw-3422-x4g5

Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first argument to the Archive method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2vvv-3xfp-234v

Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-2vvr-5757-qp87

Open redirect vulnerability in Jenkins CAS Plugin

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2vvq-r7r7-rh56

Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, or the (2) search parameter or (3) theme cookie to (b) recherche.php.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2vvq-mgpq-88xw

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 2 лет назад

Уязвимостей на страницу