Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3p3h-7wpm-9j2r

около 4 лет назад

Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p3h-5g54-qmc8

почти 2 года назад

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p3g-vpw6-4w66

больше 5 лет назад

Authentication Bypass in hydra

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3p3g-v9c5-jwvw

больше 3 лет назад

An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS/FortiProxy device and remote servers hosting threat feeds (when the latter are configured as Fabric connectors in FortiOS/FortiProxy)

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3p3f-hgmm-72qv

больше 4 лет назад

Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3p3f-h63v-47c5

больше 4 лет назад

A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p3f-cf7r-qqhf

больше 4 лет назад

FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain privileges.

EPSS: Низкий
github логотип

GHSA-3p3f-2jrx-f966

почти 3 года назад

Adobe Dimension versions 3.4.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p3c-qfrw-wp9f

11 месяцев назад

The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the admin_process_widget_page_change function. This makes it possible for unauthenticated attackers to modify widget page block configurations via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p3c-hpcw-jjrv

больше 4 лет назад

In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing locks.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p3c-fq8f-wj3w

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in gallery.php in Captivate 1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter, which is reflected in an error message.

EPSS: Низкий
github логотип

GHSA-3p3c-7gwc-rw29

почти 2 года назад

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p39-7f4w-92pm

больше 4 лет назад

In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code execution via a crafted HTML page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p39-2wh4-rwfp

больше 4 лет назад

A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a flaw in the logic that governs directory permissions. An attacker could exploit this vulnerability by using capabilities that are not controlled by the role-based access control (RBAC) mechanisms of the software. A successful exploit could allow the attacker to overwrite files on an affected device.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p38-7q3j-hw9h

около 2 месяцев назад

Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p37-hv77-x3rp

больше 4 лет назад

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-3p37-f5jm-24mc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the imagedir parameter. NOTE: this issue might be resultant from directory traversal.

EPSS: Низкий
github логотип

GHSA-3p37-3636-q8wv

больше 3 лет назад

Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p36-h8wm-47v4

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Calculate events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6353.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p36-28gq-hv7j

около 3 лет назад

In inviteInternal of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-274443441

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p3h-7wpm-9j2r

Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3p3h-5g54-qmc8

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3p3g-vpw6-4w66

Authentication Bypass in hydra

CVSS3: 5.8
1%
Низкий
больше 5 лет назад
github логотип
GHSA-3p3g-v9c5-jwvw

An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS/FortiProxy device and remote servers hosting threat feeds (when the latter are configured as Fabric connectors in FortiOS/FortiProxy)

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p3f-hgmm-72qv

Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3f-h63v-47c5

A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3f-cf7r-qqhf

FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3f-2jrx-f966

Adobe Dimension versions 3.4.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3p3c-qfrw-wp9f

The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the admin_process_widget_page_change function. This makes it possible for unauthenticated attackers to modify widget page block configurations via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3p3c-hpcw-jjrv

In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing locks.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3c-fq8f-wj3w

Cross-site scripting (XSS) vulnerability in gallery.php in Captivate 1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter, which is reflected in an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3c-7gwc-rw29

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3p39-7f4w-92pm

In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code execution via a crafted HTML page.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p39-2wh4-rwfp

A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a flaw in the logic that governs directory permissions. An attacker could exploit this vulnerability by using capabilities that are not controlled by the role-based access control (RBAC) mechanisms of the software. A successful exploit could allow the attacker to overwrite files on an affected device.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p38-7q3j-hw9h

Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3p37-hv77-x3rp

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

CVSS3: 9.8
100%
Критический
больше 4 лет назад
github логотип
GHSA-3p37-f5jm-24mc

Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the imagedir parameter. NOTE: this issue might be resultant from directory traversal.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3p37-3636-q8wv

Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p36-h8wm-47v4

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Calculate events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6353.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3p36-28gq-hv7j

In inviteInternal of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-274443441

CVSS3: 4.4
0%
Низкий
около 3 лет назад

Уязвимостей на страницу