Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-2vjc-5wcf-g24v

10 месяцев назад

Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution. This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vj9-cx9q-8m6r

около 4 лет назад

Stack-based buffer overflow in the RichFX component in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 allows remote attackers to have an unspecified impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2vj9-882j-v7fm

около 4 лет назад

Windows Cryptographic Primitives Library Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vj8-5447-hhff

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vj7-qv54-wqmr

около 4 лет назад

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.

EPSS: Низкий
github логотип

GHSA-2vj7-37qg-hm7q

больше 2 лет назад

The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vj6-wmm6-q722

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vj6-p9c5-8h3v

около 4 лет назад

main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2vj6-mvxm-4f5f

около 4 лет назад

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.

EPSS: Низкий
github логотип

GHSA-2vj5-r237-wrxw

больше 1 года назад

Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vj5-px25-gjrp

больше 4 лет назад

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vj5-ff34-px52

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2vj5-chrh-vh25

19 дней назад

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2vj4-mfcc-xffc

около 4 лет назад

MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.

EPSS: Низкий
github логотип

GHSA-2vj4-82m3-c6h5

больше 4 лет назад

Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument.

EPSS: Низкий
github логотип

GHSA-2vj3-wf4c-q7hg

около 4 лет назад

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vj3-75qw-x4pm

больше 4 лет назад

SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters.

EPSS: Низкий
github логотип

GHSA-2vhx-gg9g-r3h4

около 4 лет назад

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

EPSS: Низкий
github логотип

GHSA-2vhx-cw73-6rc9

около 4 лет назад

Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2vhw-q7vh-7xv2

4 месяца назад

openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vjc-5wcf-g24v

Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution. This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

CVSS3: 9.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-2vj9-cx9q-8m6r

Stack-based buffer overflow in the RichFX component in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 allows remote attackers to have an unspecified impact via unknown vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2vj9-882j-v7fm

Windows Cryptographic Primitives Library Information Disclosure Vulnerability

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vj8-5447-hhff

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.3.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2vj7-qv54-wqmr

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2vj7-37qg-hm7q

The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2vj6-wmm6-q722

In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2vj6-p9c5-8h3v

main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.

CVSS3: 7.5
22%
Средний
около 4 лет назад
github логотип
GHSA-2vj6-mvxm-4f5f

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2vj5-r237-wrxw

Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2vj5-px25-gjrp

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2vj5-ff34-px52

Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2vj5-chrh-vh25

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVSS3: 7.3
1%
Низкий
19 дней назад
github логотип
GHSA-2vj4-mfcc-xffc

MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vj4-82m3-c6h5

Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2vj3-wf4c-q7hg

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2vj3-75qw-x4pm

SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2vhx-gg9g-r3h4

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

5%
Низкий
около 4 лет назад
github логотип
GHSA-2vhx-cw73-6rc9

Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.

CVSS3: 7.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vhw-q7vh-7xv2

openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers

4 месяца назад

Уязвимостей на страницу