Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-3mw8-p9vq-vwxw

больше 4 лет назад

The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mw8-jr69-x96w

больше 3 лет назад

Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mw8-88mv-4wcm

больше 4 лет назад

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mw8-34v3-p9w6

около 1 месяца назад

OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OPJU files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-29331.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mw7-6cqh-vgc6

больше 4 лет назад

Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3mw7-4727-j55f

11 дней назад

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.

EPSS: Низкий
github логотип

GHSA-3mw6-rrq3-376v

7 дней назад

Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a user who was tricked into submitting a crafted POST request to the conversation view endpoint. Exploitation was aided by the absence of a CSRF token on the endpoint, which allowed the payload to be delivered through an auto-submitting cross-origin POST without authentication. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mw6-fgc8-7frc

почти 4 года назад

GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_sffield at /scene_manager/scene_dump.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mw6-835f-4vv4

больше 4 лет назад

Unspecified vulnerability in Octopussy before 0.9.5.8 has unknown impact and attack vectors related to a "major security" vulnerability.

EPSS: Низкий
github логотип

GHSA-3mw5-8fv4-p245

больше 4 лет назад

PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode field.

EPSS: Низкий
github логотип

GHSA-3mw5-7hq7-6p5w

больше 1 года назад

NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3mw5-466q-295q

6 месяцев назад

Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3mw4-pmpc-h76j

больше 4 лет назад

Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames.

EPSS: Низкий
github логотип

GHSA-3mw4-ccpc-mvj9

4 месяца назад

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scripting (XSS). This issue affects Colorbox Inline: from 0.0.0 before 2.1.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mw4-6rj6-74g5

больше 4 лет назад

Null pointer dereference in TensorFlow

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mw4-4mfr-235g

больше 4 лет назад

On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' driver, Virtual Edition instances hosted in Amazon Web Services (AWS) may experience a TMM restart.

EPSS: Низкий
github логотип

GHSA-3mw3-473f-ghgm

около 1 года назад

A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user interaction.

EPSS: Низкий
github логотип

GHSA-3mw3-2r27-jvqm

почти 3 года назад

An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mvx-8xgc-hh5r

больше 4 лет назад

Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are predictable. This would allow an attacker to learn the state of the system if they can observe the traffic. This would be possible even if the traffic were encrypted, e.g., using WPA2, as the packet sizes would remain observable. The communication encryption scheme is theoretically sound, but is not strong enough for the level of protection required.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mvv-q4g4-gx25

4 месяца назад

An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mw8-p9vq-vwxw

The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mw8-jr69-x96w

Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mw8-88mv-4wcm

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mw8-34v3-p9w6

OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OPJU files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-29331.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3mw7-6cqh-vgc6

Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename.

CVSS3: 9.6
5%
Низкий
больше 4 лет назад
github логотип
GHSA-3mw7-4727-j55f

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.

0%
Низкий
11 дней назад
github логотип
GHSA-3mw6-rrq3-376v

Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a user who was tricked into submitting a crafted POST request to the conversation view endpoint. Exploitation was aided by the absence of a CSRF token on the endpoint, which allowed the payload to be delivered through an auto-submitting cross-origin POST without authentication. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.

CVSS3: 6.1
0%
Низкий
7 дней назад
github логотип
GHSA-3mw6-fgc8-7frc

GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_sffield at /scene_manager/scene_dump.c.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3mw6-835f-4vv4

Unspecified vulnerability in Octopussy before 0.9.5.8 has unknown impact and attack vectors related to a "major security" vulnerability.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mw5-8fv4-p245

PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode field.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3mw5-7hq7-6p5w

NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering.

CVSS3: 7.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-3mw5-466q-295q

Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration

CVSS3: 6.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-3mw4-pmpc-h76j

Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mw4-ccpc-mvj9

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scripting (XSS). This issue affects Colorbox Inline: from 0.0.0 before 2.1.1.

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-3mw4-6rj6-74g5

Null pointer dereference in TensorFlow

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mw4-4mfr-235g

On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' driver, Virtual Edition instances hosted in Amazon Web Services (AWS) may experience a TMM restart.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mw3-473f-ghgm

A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user interaction.

0%
Низкий
около 1 года назад
github логотип
GHSA-3mw3-2r27-jvqm

An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

CVSS3: 9.8
2%
Низкий
почти 3 года назад
github логотип
GHSA-3mvx-8xgc-hh5r

Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are predictable. This would allow an attacker to learn the state of the system if they can observe the traffic. This would be possible even if the traffic were encrypted, e.g., using WPA2, as the packet sizes would remain observable. The communication encryption scheme is theoretically sound, but is not strong enough for the level of protection required.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mvv-q4g4-gx25

An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component

CVSS3: 8
0%
Низкий
4 месяца назад

Уязвимостей на страницу