Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-3rv9-f576-m286

больше 3 лет назад

Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Virames Vira-Investing allows Account Footprinting.This issue affects Vira-Investing: before 1.0.84.86.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3rv9-35j4-r85x

около 1 месяца назад

A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rv8-h7c2-7535

5 дней назад

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rv7-vfgw-fvwj

больше 4 лет назад

Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Высокий
github логотип

GHSA-3rv7-4xwm-v96j

4 месяца назад

Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3rv7-4fgp-6q58

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3rv5-pgj2-5frg

больше 2 лет назад

A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3rv5-ggwr-m2p2

больше 4 лет назад

AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 allows OS Command Injection because of missing input validation on one of the parameters of an HTTP request.

EPSS: Низкий
github логотип

GHSA-3rv5-c9qq-6335

около 1 года назад

An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public components.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rv4-77xr-w6jx

почти 3 года назад

A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rv3-jp5p-3jhw

больше 4 лет назад

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rv3-73vp-853w

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3rv2-7gw6-fqvv

4 дня назад

A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rrx-r28h-qh3c

около 4 лет назад

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34700.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rrx-pxh6-vf6v

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

EPSS: Низкий
github логотип

GHSA-3rrx-59q7-9g4m

19 дней назад

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is exploitable without authentication when a form is configured with public visibility (who_can_see='all'), as the required nonce is publicly obtainable from the rendered form.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rrx-364r-6wf6

почти 4 года назад

Cross-site Scripting in Jenkins Spring Config Plugin

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3rrw-pv9w-qgch

больше 4 лет назад

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rrw-2rpr-xr39

больше 4 лет назад

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, may arbitrarily change coming soon page layout.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rrv-jp9h-4vrq

больше 4 лет назад

A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-31244612. References: NVIDIA N-CVE-2016-6747.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rv9-f576-m286

Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Virames Vira-Investing allows Account Footprinting.This issue affects Vira-Investing: before 1.0.84.86.

CVSS3: 5.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rv9-35j4-r85x

A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3rv8-h7c2-7535

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.8
0%
Низкий
5 дней назад
github логотип
GHSA-3rv7-vfgw-fvwj

Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

81%
Высокий
больше 4 лет назад
github логотип
GHSA-3rv7-4xwm-v96j

Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.6
0%
Низкий
4 месяца назад
github логотип
GHSA-3rv7-4fgp-6q58

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-3rv5-pgj2-5frg

A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM.

CVSS3: 10
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3rv5-ggwr-m2p2

AIMANAGER before B115 on MONITORAPP Application Insight Web Application Firewall (AIWAF) devices with Manager 2.1.0 allows OS Command Injection because of missing input validation on one of the parameters of an HTTP request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rv5-c9qq-6335

An intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access non-public components.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3rv4-77xr-w6jx

A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3rv3-jp5p-3jhw

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rv3-73vp-853w

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rv2-7gw6-fqvv

A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.

CVSS3: 6.5
1%
Низкий
4 дня назад
github логотип
GHSA-3rrx-r28h-qh3c

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34700.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-3rrx-pxh6-vf6v

Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrx-59q7-9g4m

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). This is exploitable without authentication when a form is configured with public visibility (who_can_see='all'), as the required nonce is publicly obtainable from the rendered form.

CVSS3: 7.5
1%
Низкий
19 дней назад
github логотип
GHSA-3rrx-364r-6wf6

Cross-site Scripting in Jenkins Spring Config Plugin

CVSS3: 8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3rrw-pv9w-qgch

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.

CVSS3: 6.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrw-2rpr-xr39

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, may arbitrarily change coming soon page layout.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rrv-jp9h-4vrq

A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-31244612. References: NVIDIA N-CVE-2016-6747.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу