Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2hv5-x9f5-6mfx

около 4 лет назад

A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.

EPSS: Низкий
github логотип

GHSA-2hv5-x25m-j674

около 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2hv5-gqgx-ppf5

около 4 лет назад

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.

EPSS: Низкий
github логотип

GHSA-2hv5-4h3g-4hjv

3 месяца назад

Duplicate Advisory: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2hv5-3qjg-gjqr

3 дня назад

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap underlying that operation is tied into the binding of the VIRQ_DOM_EXC virtual IRQ. Unfortunately an error path there would tear down the bitmap even in cases when it wasn't set up. Unprivileged domains can trigger that error path.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hv4-j2px-29fc

около 4 лет назад

Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hv4-gfjm-57v5

около 4 лет назад

Zorum 3.5 allows remote attackers to obtain the full installation path via direct requests to (1) gorum/notification.php, (2) user.php, (3) attach.php, (4) blacklist.php, (5) zorum/forum.php, (6) globalstat.php, (7) gorum/trace.php, (8) gorum/badwords.php, or (9) gorum/flood.php.

EPSS: Низкий
github логотип

GHSA-2hv4-552m-4mw7

около 4 лет назад

A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hv2-87wf-9q3h

около 4 лет назад

Unspecified vulnerability in the FTP server for HP-UX B.11.11, B.11.23, and B.11.31 allows remote authenticated users to cause a denial of service (FTP server outage) via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-2hv2-4qf7-p9g4

больше 2 лет назад

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 3 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-2hrx-xx6v-c3v2

почти 2 года назад

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-2hrx-xwqf-pfcv

около 4 лет назад

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.

EPSS: Низкий
github логотип

GHSA-2hrw-hx67-34x6

больше 3 лет назад

Resource exhaustion in Django

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2hrv-x2vv-hm7r

около 4 лет назад

SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2hrr-r3hg-fjc2

около 4 лет назад

A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hrr-6728-qg8v

больше 4 лет назад

netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.

EPSS: Низкий
github логотип

GHSA-2hrr-4p8h-j38c

больше 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hrr-32vx-4wx9

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Matias s Shockingly Simple Favicon plugin <= 1.8.2 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hrq-f7cq-4p3c

около 4 лет назад

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hrp-x9mq-5qp2

больше 1 года назад

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hv5-x9f5-6mfx

A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2hv5-x25m-j674

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 9.8
100%
Критический
около 4 лет назад
github логотип
GHSA-2hv5-gqgx-ppf5

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a local user to obtain sensitive information from SessionManagement cookies. IBM X-Force ID: 162259.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2hv5-4h3g-4hjv

Duplicate Advisory: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification

CVSS3: 5.3
3 месяца назад
github логотип
GHSA-2hv5-3qjg-gjqr

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was introduced. The management of the bitmap underlying that operation is tied into the binding of the VIRQ_DOM_EXC virtual IRQ. Unfortunately an error path there would tear down the bitmap even in cases when it wasn't set up. Unprivileged domains can trigger that error path.

CVSS3: 7.5
0%
Низкий
3 дня назад
github логотип
GHSA-2hv4-j2px-29fc

Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2hv4-gfjm-57v5

Zorum 3.5 allows remote attackers to obtain the full installation path via direct requests to (1) gorum/notification.php, (2) user.php, (3) attach.php, (4) blacklist.php, (5) zorum/forum.php, (6) globalstat.php, (7) gorum/trace.php, (8) gorum/badwords.php, or (9) gorum/flood.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2hv4-552m-4mw7

A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hv2-87wf-9q3h

Unspecified vulnerability in the FTP server for HP-UX B.11.11, B.11.23, and B.11.31 allows remote authenticated users to cause a denial of service (FTP server outage) via unknown attack vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2hv2-4qf7-p9g4

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 3 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform stored XSS attacks on the targeted system.

CVSS3: 6.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2hrx-xx6v-c3v2

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.

CVSS3: 4.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-2hrx-xwqf-pfcv

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2hrw-hx67-34x6

Resource exhaustion in Django

CVSS3: 7.5
63%
Средний
больше 3 лет назад
github логотип
GHSA-2hrv-x2vv-hm7r

SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2hrr-r3hg-fjc2

A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hrr-6728-qg8v

netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2hrr-4p8h-j38c

Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hrr-32vx-4wx9

Cross-Site Request Forgery (CSRF) vulnerability in Matias s Shockingly Simple Favicon plugin <= 1.8.2 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-2hrq-f7cq-4p3c

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hrp-x9mq-5qp2

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
больше 1 года назад

Уязвимостей на страницу