Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2hc6-pjqv-vf75

около 4 лет назад

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of user-supplied input to the web UI. An attacker could exploit this vulnerability by submitting crafted input to the web UI. A successful exploit could allow an attacker to execute arbitrary commands with administrative privileges on an affected device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hc5-mf64-rr7f

почти 2 года назад

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2hc4-qjj9-7p6r

около 4 лет назад

CODESYS Gateway 3 before 3.5.17.0 has a NULL pointer dereference that may result in a denial of service (DoS).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hc3-647x-j4pq

около 4 лет назад

Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.

EPSS: Низкий
github логотип

GHSA-2hc3-38qf-h9pv

около 4 лет назад

Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.3 and 12.1.0.4 allows remote attackers to affect confidentiality via unknown vectors related to UI Framework.

EPSS: Низкий
github логотип

GHSA-2hc2-j336-j495

около 4 лет назад

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly have other unspecified impact as demonstrated by uploading a file with an .html extension, then accessing it via the elFinder functionality.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2h9x-xhwj-wr94

около 1 года назад

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2h9x-x82w-69cq

больше 4 лет назад

Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other users, e.g. by deleting clients via dltclnt.php, possibly in a SQL injection attack.

EPSS: Низкий
github логотип

GHSA-2h9x-7qvf-96j8

больше 2 лет назад

Memory Corruption in Audio while invoking IOCTLs calls from the user-space.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2h9w-xq69-f5qj

около 4 лет назад

There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2h9w-x423-49m5

больше 1 года назад

Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2h9v-wp82-7j69

4 дня назад

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2h9v-34wh-2q7g

около 4 лет назад

Buffer Overflow vulnerability in function activate in libavfilter/af_afade.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

EPSS: Низкий
github логотип

GHSA-2h9r-gmgg-grw7

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.8.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2h9r-5xf2-97qv

около 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme BodyCenter - Gym, Fitness WooCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects BodyCenter - Gym, Fitness WooCommerce WordPress Theme: from n/a through 2.4.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2h9q-f394-cmcx

около 4 лет назад

Windows WLAN AutoConfig Service Information Disclosure Vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h9q-c8x4-7278

почти 2 года назад

Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2h9q-63fq-25hj

больше 4 лет назад

IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header.

EPSS: Низкий
github логотип

GHSA-2h9q-5qx9-w5fm

около 2 лет назад

Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2h9p-q5rr-fvrp

10 месяцев назад

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server. Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hc6-pjqv-vf75

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of user-supplied input to the web UI. An attacker could exploit this vulnerability by submitting crafted input to the web UI. A successful exploit could allow an attacker to execute arbitrary commands with administrative privileges on an affected device.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2hc5-mf64-rr7f

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.

CVSS3: 9.9
1%
Низкий
почти 2 года назад
github логотип
GHSA-2hc4-qjj9-7p6r

CODESYS Gateway 3 before 3.5.17.0 has a NULL pointer dereference that may result in a denial of service (DoS).

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2hc3-647x-j4pq

Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2hc3-38qf-h9pv

Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.3 and 12.1.0.4 allows remote attackers to affect confidentiality via unknown vectors related to UI Framework.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2hc2-j336-j495

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly have other unspecified impact as demonstrated by uploading a file with an .html extension, then accessing it via the elFinder functionality.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h9x-xhwj-wr94

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2h9x-x82w-69cq

Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other users, e.g. by deleting clients via dltclnt.php, possibly in a SQL injection attack.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2h9x-7qvf-96j8

Memory Corruption in Audio while invoking IOCTLs calls from the user-space.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2h9w-xq69-f5qj

There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2h9w-x423-49m5

Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h9v-wp82-7j69

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

CVSS3: 9.1
1%
Низкий
4 дня назад
github логотип
GHSA-2h9v-34wh-2q7g

Buffer Overflow vulnerability in function activate in libavfilter/af_afade.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

около 4 лет назад
github логотип
GHSA-2h9r-gmgg-grw7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.8.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-2h9r-5xf2-97qv

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme BodyCenter - Gym, Fitness WooCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects BodyCenter - Gym, Fitness WooCommerce WordPress Theme: from n/a through 2.4.

CVSS3: 8.1
1%
Низкий
около 1 года назад
github логотип
GHSA-2h9q-f394-cmcx

Windows WLAN AutoConfig Service Information Disclosure Vulnerability.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h9q-c8x4-7278

Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-2h9q-63fq-25hj

IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2h9q-5qx9-w5fm

Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2h9p-q5rr-fvrp

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server. Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.

CVSS3: 6.7
1%
Низкий
10 месяцев назад

Уязвимостей на страницу