Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2jw2-8v9p-h7mp

около 4 лет назад

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.

EPSS: Высокий
github логотип

GHSA-2jw2-755p-5gqq

около 4 лет назад

Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jvx-x849-7gfm

около 1 года назад

A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteList. The manipulation of the argument addHostFilter leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jvx-f9f6-89cv

почти 3 года назад

Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jvx-947v-x43p

больше 4 лет назад

Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2jvx-42cx-5ggp

почти 3 года назад

Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jvx-3h5f-w2j7

больше 2 лет назад

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jvw-hf8m-phpv

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.

EPSS: Низкий
github логотип

GHSA-2jvw-9p97-g4qj

почти 2 года назад

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2jvv-ppmq-fvgf

около 4 лет назад

NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.

EPSS: Низкий
github логотип

GHSA-2jvr-rx29-36x8

11 дней назад

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2jvq-qwww-m6j5

около 4 лет назад

The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2jvq-3rhr-97x9

около 4 лет назад

Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38660.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jvp-r7m9-xhpr

больше 1 года назад

An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2jvp-h4w4-2vxh

4 месяца назад

Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large value that is passed to AEAD decryption routines, causing a large out-of-bounds read and crash. An unauthenticated attacker can trigger this remotely via malformed TLS Application Data records.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2jvm-wg52-7h4f

около 4 лет назад

ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2jvm-jgg9-h383

больше 1 года назад

Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

EPSS: Низкий
github логотип

GHSA-2jvm-ch9q-pwc4

больше 4 лет назад

Buffer overflow in JustSystems Hanako 2004 through 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, and Sanshiro 2005 allows remote attackers to execute arbitrary code via the (1) Keyword and (2) Title fields, related to string length fields.

EPSS: Низкий
github логотип

GHSA-2jvj-mhf2-g99w

около 4 лет назад

SilverStripe CSV Excel Macro Injection

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jvj-gqwv-f9w3

около 4 лет назад

Pandora FMS ? 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder with a "tricky" name in the filemanager. The exploit works when the php-fileinfo extension is disabled on the host system. The attacker must include shell metacharacters in the content type.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jw2-8v9p-h7mp

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.

75%
Высокий
около 4 лет назад
github логотип
GHSA-2jw2-755p-5gqq

Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2jvx-x849-7gfm

A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteList. The manipulation of the argument addHostFilter leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-2jvx-f9f6-89cv

Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2jvx-947v-x43p

Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2jvx-42cx-5ggp

Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-2jvx-3h5f-w2j7

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

CVSS3: 5.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2jvw-hf8m-phpv

In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.

0%
Низкий
7 месяцев назад
github логотип
GHSA-2jvw-9p97-g4qj

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-2jvv-ppmq-fvgf

NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2jvr-rx29-36x8

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
0%
Низкий
11 дней назад
github логотип
GHSA-2jvq-qwww-m6j5

The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.

CVSS3: 4.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-2jvq-3rhr-97x9

Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38660.

CVSS3: 7.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-2jvp-r7m9-xhpr

An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jvp-h4w4-2vxh

Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large value that is passed to AEAD decryption routines, causing a large out-of-bounds read and crash. An unauthenticated attacker can trigger this remotely via malformed TLS Application Data records.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2jvm-wg52-7h4f

ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2jvm-jgg9-h383

Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

0%
Низкий
больше 1 года назад
github логотип
GHSA-2jvm-ch9q-pwc4

Buffer overflow in JustSystems Hanako 2004 through 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, and Sanshiro 2005 allows remote attackers to execute arbitrary code via the (1) Keyword and (2) Title fields, related to string length fields.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2jvj-mhf2-g99w

SilverStripe CSV Excel Macro Injection

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jvj-gqwv-f9w3

Pandora FMS ? 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder with a "tricky" name in the filemanager. The exploit works when the php-fileinfo extension is disabled on the host system. The attacker must include shell metacharacters in the content type.

3%
Низкий
около 4 лет назад

Уязвимостей на страницу