Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-2h9q-63fq-25hj

больше 4 лет назад

IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header.

EPSS: Низкий
github логотип

GHSA-2h9q-5qx9-w5fm

около 2 лет назад

Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2h9p-q5rr-fvrp

10 месяцев назад

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server. Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2h9p-fvvm-92g9

около 4 лет назад

Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2h9m-7wj7-h654

больше 2 лет назад

IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h9j-hxw7-2jf3

17 дней назад

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2h9h-wfvh-5r96

около 4 лет назад

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h9h-pcw6-4f34

8 месяцев назад

A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h9h-4f6p-xvfc

около 4 лет назад

Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

EPSS: Низкий
github логотип

GHSA-2h9g-8p3q-w23q

около 2 месяцев назад

A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2h9f-xm25-q379

больше 1 года назад

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h9f-vrvc-wfwh

около 4 лет назад

An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system, a.k.a. "Windows Kernel Information Disclosure Vulnerability."

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h9f-vc99-85c4

больше 4 лет назад

A system-critical Windows NT registry key has inappropriate permissions.

EPSS: Низкий
github логотип

GHSA-2h9f-ppj9-gcvv

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h9f-48qh-w996

больше 2 лет назад

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h9c-p959-263w

17 дней назад

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2h9c-gjwm-vfqx

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Rara Business allows Cross Site Request Forgery.This issue affects Rara Business: from n/a through 1.2.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h9c-34v6-3qmr

около 4 лет назад

Kubernetes in OpenShift3 Access Control Misconfiguration

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2h98-r334-3wg6

около 4 лет назад

siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.

EPSS: Низкий
github логотип

GHSA-2h98-6q8m-mm63

около 4 лет назад

textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h9q-63fq-25hj

IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2h9q-5qx9-w5fm

Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2h9p-q5rr-fvrp

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server. Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.

CVSS3: 6.7
1%
Низкий
10 месяцев назад
github логотип
GHSA-2h9p-fvvm-92g9

Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability.

CVSS3: 7
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h9m-7wj7-h654

IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2h9j-hxw7-2jf3

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
17 дней назад
github логотип
GHSA-2h9h-wfvh-5r96

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2h9h-pcw6-4f34

A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2h9h-4f6p-xvfc

Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2h9g-8p3q-w23q

A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2h9f-xm25-q379

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h9f-vrvc-wfwh

An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system, a.k.a. "Windows Kernel Information Disclosure Vulnerability."

CVSS3: 5.5
6%
Низкий
около 4 лет назад
github логотип
GHSA-2h9f-vc99-85c4

A system-critical Windows NT registry key has inappropriate permissions.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2h9f-ppj9-gcvv

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2h9f-48qh-w996

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2h9c-p959-263w

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
17 дней назад
github логотип
GHSA-2h9c-gjwm-vfqx

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Rara Business allows Cross Site Request Forgery.This issue affects Rara Business: from n/a through 1.2.5.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h9c-34v6-3qmr

Kubernetes in OpenShift3 Access Control Misconfiguration

CVSS3: 3.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h98-r334-3wg6

siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2h98-6q8m-mm63

textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.

CVSS3: 7.8
2%
Низкий
около 4 лет назад

Уязвимостей на страницу