Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-2v64-wgmh-whp9

больше 1 года назад

BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handling of SSL certificates validation.

CVSS3: 2.8
EPSS: Низкий
github логотип

GHSA-2v64-gq4j-wx65

около 4 лет назад

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image processing engine when processing JPEG 2000 (JP2) code stream data. Successful exploitation could lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2v63-g4wq-72pq

около 4 лет назад

Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.

EPSS: Средний
github логотип

GHSA-2v63-98q8-j2pr

около 4 лет назад

Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.

EPSS: Низкий
github логотип

GHSA-2v62-w6hr-9gww

больше 4 лет назад

SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) top_view.php.

EPSS: Низкий
github логотип

GHSA-2v62-qxwf-qh42

4 месяца назад

A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently dropped as duplicates. Only the first of such rules is actually loaded into pf. Ranges expressed using the address[/mask-bits] syntax were not affected. Some keywords representing actions taken on a packet-matching rule, such as 'log', 'return tll', or 'dnpipe', may suffer from the same issue. It is unlikely that users have such configurations, as these rules would always be redundant. Affected rules are silently ignored, which can lead to unexpected behaviour including over- and underblocking.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2v62-48mq-rgvp

около 4 лет назад

Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

EPSS: Низкий
github логотип

GHSA-2v62-25cm-4v7w

больше 3 лет назад

NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an attacker with user level privileges may cause the installer to load an arbitrary DLL when the installer is launched. A successful exploit of this vulnerability could lead to escalation of privileges and code execution.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2v5x-9xhg-52hm

около 4 лет назад

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2v5w-x4f3-xf47

около 4 лет назад

In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478078; Issue ID: ALPS06478078.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2v5w-v683-c839

больше 2 лет назад

Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2v5v-vwrw-9m56

больше 4 лет назад

Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-2v5r-gc72-7xcw

больше 4 лет назад

NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.

EPSS: Низкий
github логотип

GHSA-2v5q-fm75-vvjv

9 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2v5p-gw86-2385

около 4 лет назад

A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.2 and below may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.

EPSS: Низкий
github логотип

GHSA-2v5p-5pj6-h3hp

6 месяцев назад

Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.

EPSS: Низкий
github логотип

GHSA-2v5m-cq9w-fc33

10 месяцев назад

Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2v5m-7mpw-7w7j

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.31.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v5j-q74q-r53f

больше 4 лет назад

django-helpdesk is vulnerable to Cross-site Scripting

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2v5j-pf93-x5xr

больше 4 лет назад

webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2v64-wgmh-whp9

BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handling of SSL certificates validation.

CVSS3: 2.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v64-gq4j-wx65

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image processing engine when processing JPEG 2000 (JP2) code stream data. Successful exploitation could lead to arbitrary code execution.

CVSS3: 8.8
7%
Низкий
около 4 лет назад
github логотип
GHSA-2v63-g4wq-72pq

Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.

51%
Средний
около 4 лет назад
github логотип
GHSA-2v63-98q8-j2pr

Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v62-w6hr-9gww

SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) top_view.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v62-qxwf-qh42

A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently dropped as duplicates. Only the first of such rules is actually loaded into pf. Ranges expressed using the address[/mask-bits] syntax were not affected. Some keywords representing actions taken on a packet-matching rule, such as 'log', 'return tll', or 'dnpipe', may suffer from the same issue. It is unlikely that users have such configurations, as these rules would always be redundant. Affected rules are silently ignored, which can lead to unexpected behaviour including over- and underblocking.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2v62-48mq-rgvp

Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2v62-25cm-4v7w

NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an attacker with user level privileges may cause the installer to load an arbitrary DLL when the installer is launched. A successful exploit of this vulnerability could lead to escalation of privileges and code execution.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2v5x-9xhg-52hm

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-2v5w-x4f3-xf47

In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478078; Issue ID: ALPS06478078.

CVSS3: 4.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-2v5w-v683-c839

Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.

CVSS3: 8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2v5v-vwrw-9m56

Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2v5r-gc72-7xcw

NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2v5q-fm75-vvjv

Rejected reason: Not used

9 месяцев назад
github логотип
GHSA-2v5p-gw86-2385

A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.2 and below may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2v5p-5pj6-h3hp

Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.

0%
Низкий
6 месяцев назад
github логотип
GHSA-2v5m-cq9w-fc33

Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality

CVSS3: 7.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-2v5m-7mpw-7w7j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.31.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2v5j-q74q-r53f

django-helpdesk is vulnerable to Cross-site Scripting

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2v5j-pf93-x5xr

webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу