Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2hw6-4rv9-82fp

больше 3 лет назад

Uvdesk remote code execution vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hw5-wx32-97v6

около 4 лет назад

Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.

EPSS: Низкий
github логотип

GHSA-2hw5-388c-g7xj

около 4 лет назад

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hw3-wmq2-hxf7

около 4 лет назад

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hw3-rfjc-q8m6

10 месяцев назад

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-2hw3-h8qx-hqqp

около 1 года назад

OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hw3-28v7-q78p

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."

EPSS: Средний
github логотип

GHSA-2hw2-hc6g-cv7v

9 месяцев назад

IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hw2-h3mf-c2j9

около 4 лет назад

Moodle open redirect vulnerability

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2hw2-7jq8-w9vp

больше 4 лет назад

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

EPSS: Низкий
github логотип

GHSA-2hw2-62cp-p9p7

около 7 лет назад

Access control bypass in Apache ZooKeeper

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2hw2-5mr3-w7wm

30 дней назад

A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2hvx-m86j-h9m3

около 4 лет назад

Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.

EPSS: Низкий
github логотип

GHSA-2hvx-9r8j-qvph

около 3 лет назад

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hvx-93c2-p928

почти 3 года назад

** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2hvw-r4rp-mjpp

почти 3 года назад

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2hvv-h4pw-wcm2

около 4 лет назад

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

EPSS: Низкий
github логотип

GHSA-2hvr-h6gw-qrxp

почти 4 года назад

Cargo extracting malicious crates can fill the file system

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-2hvr-43xf-39rx

больше 3 лет назад

Not used in 2022

EPSS: Низкий
github логотип

GHSA-2hvq-vmfm-c497

больше 3 лет назад

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hw6-4rv9-82fp

Uvdesk remote code execution vulnerability

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2hw5-wx32-97v6

Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2hw5-388c-g7xj

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hw3-wmq2-hxf7

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2hw3-rfjc-q8m6

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.

CVSS3: 9
1%
Низкий
10 месяцев назад
github логотип
GHSA-2hw3-h8qx-hqqp

OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2hw3-28v7-q78p

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."

17%
Средний
около 4 лет назад
github логотип
GHSA-2hw2-hc6g-cv7v

IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

CVSS3: 9.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-2hw2-h3mf-c2j9

Moodle open redirect vulnerability

CVSS3: 7.4
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hw2-7jq8-w9vp

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2hw2-62cp-p9p7

Access control bypass in Apache ZooKeeper

CVSS3: 5.9
10%
Низкий
около 7 лет назад
github логотип
GHSA-2hw2-5mr3-w7wm

A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

CVSS3: 6.2
0%
Низкий
30 дней назад
github логотип
GHSA-2hvx-m86j-h9m3

Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2hvx-9r8j-qvph

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms created with this plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2hvx-93c2-p928

** UNSUPPPORTED WHEN ASSIGNED ** Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.

CVSS3: 8.6
0%
Низкий
почти 3 года назад
github логотип
GHSA-2hvw-r4rp-mjpp

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVSS3: 5.9
1%
Низкий
почти 3 года назад
github логотип
GHSA-2hvv-h4pw-wcm2

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2hvr-h6gw-qrxp

Cargo extracting malicious crates can fill the file system

CVSS3: 4.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-2hvr-43xf-39rx

Not used in 2022

больше 3 лет назад
github логотип
GHSA-2hvq-vmfm-c497

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу