Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3pc4-pj89-2j67

больше 4 лет назад

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pc4-7j85-539h

больше 4 лет назад

The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.

EPSS: Низкий
github логотип

GHSA-3pc3-xxxx-7pfj

около 1 года назад

A security flaw has been discovered in Open5GS up to 2.7.5. The impacted element is the function gmm_state_exception of the file src/amf/gmm-sm.c. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited. The patch is identified as 8e5fed16114f2f5e40bee1b161914b592b2b7b8f. Applying a patch is advised to resolve this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3pc3-vcqg-prf6

около 2 лет назад

A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pc3-p9j7-xvq6

почти 2 года назад

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3pc3-3mfc-x5vj

больше 4 лет назад

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.

EPSS: Низкий
github логотип

GHSA-3pc2-v6g3-vwg9

3 месяца назад

Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3pc2-fm7p-q2vg

около 6 лет назад

Cross-site Scripting in October

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3pc2-c878-63rj

около 3 лет назад

A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3p9x-xxx6-2w4p

больше 3 лет назад

Broken Access Control in 3rd party TYPO3 extension "femanager"

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3p9x-xxjc-hw5p

больше 4 лет назад

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

EPSS: Низкий
github логотип

GHSA-3p9x-fj5f-w25c

больше 4 лет назад

A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3p9x-34w6-f58v

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p9w-wq67-w93f

больше 4 лет назад

libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.

EPSS: Низкий
github логотип

GHSA-3p9w-w3x4-vc62

больше 4 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p9w-w3g3-89rg

больше 4 лет назад

Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

EPSS: Низкий
github логотип

GHSA-3p9w-pv5h-crrp

почти 5 лет назад

The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p9w-cf27-62fv

около 3 лет назад

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p9w-7x8w-2m9v

больше 4 лет назад

PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.

EPSS: Низкий
github логотип

GHSA-3p9v-xp6w-wcmc

больше 4 лет назад

QuickAppsCMS Cross-Site Request Forgery (CSRF)

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pc4-pj89-2j67

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pc4-7j85-539h

The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3pc3-xxxx-7pfj

A security flaw has been discovered in Open5GS up to 2.7.5. The impacted element is the function gmm_state_exception of the file src/amf/gmm-sm.c. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited. The patch is identified as 8e5fed16114f2f5e40bee1b161914b592b2b7b8f. Applying a patch is advised to resolve this issue.

CVSS3: 5.3
1%
Низкий
около 1 года назад
github логотип
GHSA-3pc3-vcqg-prf6

A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-3pc3-p9j7-xvq6

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF).

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3pc3-3mfc-x5vj

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pc2-v6g3-vwg9

Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-3pc2-fm7p-q2vg

Cross-site Scripting in October

CVSS3: 3.7
1%
Низкий
около 6 лет назад
github логотип
GHSA-3pc2-c878-63rj

A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.

CVSS3: 7.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p9x-xxx6-2w4p

Broken Access Control in 3rd party TYPO3 extension "femanager"

CVSS3: 8.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p9x-xxjc-hw5p

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9x-fj5f-w25c

A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9x-34w6-f58v

Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9w-wq67-w93f

libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9w-w3x4-vc62

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9w-w3g3-89rg

Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9w-pv5h-crrp

The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-3p9w-cf27-62fv

Microsoft Message Queuing Remote Code Execution Vulnerability

CVSS3: 9.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-3p9w-7x8w-2m9v

PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3p9v-xp6w-wcmc

QuickAppsCMS Cross-Site Request Forgery (CSRF)

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу