Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2jqm-x3hr-jjmq

13 дней назад

SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS URL pointing to an allowlisted host that redirects to blocked internal addresses, bypassing network access controls.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-2jqj-xw9v-qv9j

около 4 лет назад

CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an attacker to directly connect to the kubernetes API server. Unauthenticated users are able to list all Namespaces through the Console, resulting in an information disclosure. Tectonic's exposure of an unauthenticated API endpoint containing information regarding the internal state of the cluster can provide an attacker with information that may assist in other attacks against the cluster. For example, an attacker may not have the permissions required to list all namespaces in the cluster but can instead leverage this vulnerability to enumerate the namespaces and then begin to check each namespace for weak authorization policies that may allow further escalation of privileges.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jqj-w7h9-j4g2

больше 2 лет назад

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jqj-5qv2-xvcg

больше 1 года назад

ezsystems/ezplatform-richtext allows access to external entities in XML

EPSS: Низкий
github логотип

GHSA-2jqh-5pvj-7mrg

около 4 лет назад

Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.

EPSS: Низкий
github логотип

GHSA-2jqf-xvwf-cwgj

около 4 лет назад

I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect.

EPSS: Низкий
github логотип

GHSA-2jqf-mvg9-fhf9

больше 4 лет назад

Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument string to the TraceTarget method. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Средний
github логотип

GHSA-2jqf-jwg5-2mm3

около 4 лет назад

Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-2jqf-9377-3hhp

больше 3 лет назад

Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jqc-m5c2-q976

около 4 лет назад

The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute-value pairs, aka Bug ID CSCux15521.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2jqc-4vc4-2j4m

больше 1 года назад

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2jq9-6xx7-3h29

почти 4 года назад

`temporary` makes use of uninitialized memory

EPSS: Низкий
github логотип

GHSA-2jq8-xw89-gcg8

около 4 лет назад

The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.

EPSS: Низкий
github логотип

GHSA-2jq7-x2v9-98wx

около 3 лет назад

ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2jq7-pgqq-gqqj

около 4 лет назад

TYPO3 powermail extension allows remote attackers to bypass CAPTCHA protection mechanism

EPSS: Низкий
github логотип

GHSA-2jq7-6vh9-gh84

8 месяцев назад

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2jq6-ffph-p4h8

около 4 лет назад

Kubernetes arbitrary file overwrite

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jq5-wq32-4rfq

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2jq4-q6vv-4cp3

около 1 месяца назад

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2jq4-cxqg-p845

больше 4 лет назад

The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to cause a denial of service (application crash) via a YES message without a newline character, which triggers a NULL dereference.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jqm-x3hr-jjmq

SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redirects without re-validating redirect targets against network capabilities. Attackers with Owner role can configure a JWKS URL pointing to an allowlisted host that redirects to blocked internal addresses, bypassing network access controls.

CVSS3: 4.1
0%
Низкий
13 дней назад
github логотип
GHSA-2jqj-xw9v-qv9j

CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an attacker to directly connect to the kubernetes API server. Unauthenticated users are able to list all Namespaces through the Console, resulting in an information disclosure. Tectonic's exposure of an unauthenticated API endpoint containing information regarding the internal state of the cluster can provide an attacker with information that may assist in other attacks against the cluster. For example, an attacker may not have the permissions required to list all namespaces in the cluster but can instead leverage this vulnerability to enumerate the namespaces and then begin to check each namespace for weak authorization policies that may allow further escalation of privileges.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2jqj-w7h9-j4g2

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2jqj-5qv2-xvcg

ezsystems/ezplatform-richtext allows access to external entities in XML

больше 1 года назад
github логотип
GHSA-2jqh-5pvj-7mrg

Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2jqf-xvwf-cwgj

I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2jqf-mvg9-fhf9

Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument string to the TraceTarget method. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

56%
Средний
больше 4 лет назад
github логотип
GHSA-2jqf-jwg5-2mm3

Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."

21%
Средний
около 4 лет назад
github логотип
GHSA-2jqf-9377-3hhp

Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2jqc-m5c2-q976

The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute-value pairs, aka Bug ID CSCux15521.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jqc-4vc4-2j4m

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2jq9-6xx7-3h29

`temporary` makes use of uninitialized memory

почти 4 года назад
github логотип
GHSA-2jq8-xw89-gcg8

The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.

5%
Низкий
около 4 лет назад
github логотип
GHSA-2jq7-x2v9-98wx

ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.

CVSS3: 4.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-2jq7-pgqq-gqqj

TYPO3 powermail extension allows remote attackers to bypass CAPTCHA protection mechanism

2%
Низкий
около 4 лет назад
github логотип
GHSA-2jq7-6vh9-gh84

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface.

CVSS3: 4.6
0%
Низкий
8 месяцев назад
github логотип
GHSA-2jq6-ffph-p4h8

Kubernetes arbitrary file overwrite

CVSS3: 5.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2jq5-wq32-4rfq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jq4-q6vv-4cp3

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

CVSS3: 9.6
около 1 месяца назад
github логотип
GHSA-2jq4-cxqg-p845

The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to cause a denial of service (application crash) via a YES message without a newline character, which triggers a NULL dereference.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу