Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-3rjq-9j9w-pxr3

больше 4 лет назад

OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site.

EPSS: Низкий
github логотип

GHSA-3rjq-96vg-4j89

5 месяцев назад

Missing Authorization vulnerability in G5Theme G5Plus April g5plus-april allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects G5Plus April: from n/a through <= 6.8.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rjp-hfjx-9689

больше 4 лет назад

In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rjp-6929-2mrw

больше 4 лет назад

HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames and directory paths via a direct URL request.

EPSS: Низкий
github логотип

GHSA-3rjm-xww9-gmm6

больше 4 лет назад

Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rjm-q6hg-6jw8

больше 4 лет назад

RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3rjm-jwr3-fh58

больше 4 лет назад

Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.

EPSS: Низкий
github логотип

GHSA-3rjj-rpg2-4f2q

больше 4 лет назад

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607.

EPSS: Средний
github логотип

GHSA-3rjh-r4h7-c3mq

около 1 месяца назад

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rjh-fcp5-cg7v

больше 4 лет назад

In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.

EPSS: Низкий
github логотип

GHSA-3rjh-cgv2-5vr4

больше 4 лет назад

Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.

EPSS: Низкий
github логотип

GHSA-3rjg-j65w-6v3j

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3rjg-j575-7f6p

больше 4 лет назад

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3rjg-j22m-wrv3

больше 4 лет назад

A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

EPSS: Низкий
github логотип

GHSA-3rjg-g3j8-q837

больше 4 лет назад

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rjg-ff6r-x2c7

больше 2 лет назад

A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3rjg-586v-gcmf

больше 4 лет назад

Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rjf-4xj2-6g8f

больше 4 лет назад

** DISPUTED ** Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.

EPSS: Низкий
github логотип

GHSA-3rjc-xpqg-5mh4

больше 3 лет назад

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rjc-6hx2-f4rh

почти 2 года назад

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rjq-9j9w-pxr3

OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjq-96vg-4j89

Missing Authorization vulnerability in G5Theme G5Plus April g5plus-april allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects G5Plus April: from n/a through <= 6.8.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3rjp-hfjx-9689

In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjp-6929-2mrw

HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames and directory paths via a direct URL request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjm-xww9-gmm6

Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjm-q6hg-6jw8

RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjm-jwr3-fh58

Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjj-rpg2-4f2q

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607.

38%
Средний
больше 4 лет назад
github логотип
GHSA-3rjh-r4h7-c3mq

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3rjh-fcp5-cg7v

In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjh-cgv2-5vr4

Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjg-j65w-6v3j

Rejected reason: Not used

8 месяцев назад
github логотип
GHSA-3rjg-j575-7f6p

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

CVSS3: 4.7
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjg-j22m-wrv3

A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjg-g3j8-q837

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjg-ff6r-x2c7

A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456.

CVSS3: 3.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3rjg-586v-gcmf

Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjf-4xj2-6g8f

** DISPUTED ** Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjc-xpqg-5mh4

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rjc-6hx2-f4rh

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.

CVSS3: 7.2
1%
Низкий
почти 2 года назад

Уязвимостей на страницу