Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-3pvj-gf5m-rhhf

больше 1 года назад

MapUrlToZone Security Feature Bypass Vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3pvh-h2xv-4jw7

больше 2 лет назад

PDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18663.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pvh-8v83-x7v2

больше 4 лет назад

Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pvh-63gf-j9mw

2 месяца назад

LangBot: Authenticated RCE Via MCP Configuration

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pvh-4h3w-f294

больше 4 лет назад

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pvh-38hr-8x7c

около 4 лет назад

The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. The affected components are characterized as: Inter-Controller (IC) protocol (57612/UDP). The potential impact is: Compromise of credentials. Several Trend Controls building automation controllers utilize the Inter-Controller (IC) protocol in for information exchange and automation purposes. This protocol offers authentication in the form of a 4-digit PIN in order to protect access to sensitive operations like strategy uploads and downloads as well as optional 0-30 character username and password protection for web page access protection. Both the PIN and usernames and passwords are transmitted in cleartext, allowing an attacker with passive interception capabilities to obtain these credentials. Credentials are transmitted in cleartext. An attacker w...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pvg-8h3w-fc9m

больше 4 лет назад

Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

EPSS: Низкий
github логотип

GHSA-3pvf-vxrv-hh9c

6 месяцев назад

Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)

EPSS: Низкий
github логотип

GHSA-3pvf-vxc3-wr36

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3pvf-9jm4-6vxf

почти 3 года назад

An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3pvf-92c7-q7p5

больше 2 лет назад

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3pvf-8762-r99w

больше 4 лет назад

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."

EPSS: Низкий
github логотип

GHSA-3pvc-h22x-rq5v

5 месяцев назад

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3pvc-g892-vvj8

больше 4 лет назад

SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).

EPSS: Низкий
github логотип

GHSA-3pv8-6f4r-ffg2

4 месяца назад

tar has a PAX header desynchronization issue

EPSS: Низкий
github логотип

GHSA-3pv7-h25w-9xp8

почти 4 года назад

The Uji Countdown WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3pv7-43jr-xjjj

больше 4 лет назад

Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

EPSS: Низкий
github логотип

GHSA-3pv6-grgx-9mv9

больше 4 лет назад

There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pv5-7qjw-87p6

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the dominio parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9732.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pv5-2f7m-jxm4

около 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pvj-gf5m-rhhf

MapUrlToZone Security Feature Bypass Vulnerability

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3pvh-h2xv-4jw7

PDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18663.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3pvh-8v83-x7v2

Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvh-63gf-j9mw

LangBot: Authenticated RCE Via MCP Configuration

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-3pvh-4h3w-f294

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvh-38hr-8x7c

The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. The affected components are characterized as: Inter-Controller (IC) protocol (57612/UDP). The potential impact is: Compromise of credentials. Several Trend Controls building automation controllers utilize the Inter-Controller (IC) protocol in for information exchange and automation purposes. This protocol offers authentication in the form of a 4-digit PIN in order to protect access to sensitive operations like strategy uploads and downloads as well as optional 0-30 character username and password protection for web page access protection. Both the PIN and usernames and passwords are transmitted in cleartext, allowing an attacker with passive interception capabilities to obtain these credentials. Credentials are transmitted in cleartext. An attacker w...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3pvg-8h3w-fc9m

Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvf-vxrv-hh9c

Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)

0%
Низкий
6 месяцев назад
github логотип
GHSA-3pvf-vxc3-wr36

Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvf-9jm4-6vxf

An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-3pvf-92c7-q7p5

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVSS3: 5.5
7%
Низкий
больше 2 лет назад
github логотип
GHSA-3pvf-8762-r99w

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvc-h22x-rq5v

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop.

CVSS3: 4.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-3pvc-g892-vvj8

SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pv8-6f4r-ffg2

tar has a PAX header desynchronization issue

4 месяца назад
github логотип
GHSA-3pv7-h25w-9xp8

The Uji Countdown WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3pv7-43jr-xjjj

Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pv6-grgx-9mv9

There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pv5-7qjw-87p6

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the dominio parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9732.

CVSS3: 9.8
8%
Низкий
больше 4 лет назад
github логотип
GHSA-3pv5-2f7m-jxm4

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.

CVSS3: 7.1
0%
Низкий
около 3 лет назад

Уязвимостей на страницу