Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-xr7p-j896-c2qj

больше 4 лет назад

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr7p-hqq6-j962

почти 4 года назад

The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr7p-8q82-878q

почти 4 года назад

teler dashboard vulnerable to DOM-based cross-site scripting (XSS)

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xr7m-jcj6-p39r

больше 4 лет назад

Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.

EPSS: Средний
github логотип

GHSA-xr7m-7c2m-9x23

27 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-xr7h-qxr4-vfvf

почти 2 года назад

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEntryptPolicySort of the file /com/esafenet/servlet/system/EncryptPolicyTypeService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xr7h-q8xq-c8ww

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter.

EPSS: Низкий
github логотип

GHSA-xr7h-9g48-33qf

почти 2 года назад

A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper access control validation via PHP Info Page. This issue can lead to data leaks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr7h-8r7p-xpv9

почти 2 года назад

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xr7g-r5xg-pq95

около 3 лет назад

Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-xr7f-vc2p-mhqr

около 1 месяца назад

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr7f-qpj4-xp37

17 дней назад

A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xr7f-qhp5-ffxc

больше 4 лет назад

The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.

EPSS: Низкий
github логотип

GHSA-xr7f-6r6v-cqmm

6 месяцев назад

Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xr7f-4hm8-fh72

больше 4 лет назад

SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-xr7f-3c69-r77f

больше 4 лет назад

DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xr7f-32j7-5fh9

почти 2 года назад

This issue was addressed with improved redaction of sensitive information. This issue is fixed in visionOS 2.1. A user may be able to view sensitive user information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr7c-w8xq-cg55

больше 4 лет назад

bitcoind and Bitcoin-Qt before 0.4.9rc2, 0.5.x before 0.5.8rc2, 0.6.x before 0.6.5rc2, and 0.7.x before 0.7.3rc2, and wxBitcoin, do not properly consider whether a block's size could require an excessive number of database locks, which allows remote attackers to cause a denial of service (split) and enable certain double-spending capabilities via a large block that triggers incorrect Berkeley DB locking.

EPSS: Низкий
github логотип

GHSA-xr7c-jqqr-89vm

больше 4 лет назад

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.

EPSS: Низкий
github логотип

GHSA-xr79-9mqh-j474

больше 4 лет назад

Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr7p-j896-c2qj

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr7p-hqq6-j962

The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xr7p-8q82-878q

teler dashboard vulnerable to DOM-based cross-site scripting (XSS)

CVSS3: 3.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr7m-jcj6-p39r

Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.

11%
Средний
больше 4 лет назад
github логотип
GHSA-xr7m-7c2m-9x23

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

27 дней назад
github логотип
GHSA-xr7h-qxr4-vfvf

A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEntryptPolicySort of the file /com/esafenet/servlet/system/EncryptPolicyTypeService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-xr7h-q8xq-c8ww

Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr7h-9g48-33qf

A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper access control validation via PHP Info Page. This issue can lead to data leaks.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr7h-8r7p-xpv9

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.

CVSS3: 6.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr7g-r5xg-pq95

Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure.

CVSS3: 9
1%
Низкий
около 3 лет назад
github логотип
GHSA-xr7f-vc2p-mhqr

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xr7f-qpj4-xp37

A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 3.5
0%
Низкий
17 дней назад
github логотип
GHSA-xr7f-qhp5-ffxc

The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xr7f-6r6v-cqmm

Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xr7f-4hm8-fh72

SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr7f-3c69-r77f

DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr7f-32j7-5fh9

This issue was addressed with improved redaction of sensitive information. This issue is fixed in visionOS 2.1. A user may be able to view sensitive user information.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr7c-w8xq-cg55

bitcoind and Bitcoin-Qt before 0.4.9rc2, 0.5.x before 0.5.8rc2, 0.6.x before 0.6.5rc2, and 0.7.x before 0.7.3rc2, and wxBitcoin, do not properly consider whether a block's size could require an excessive number of database locks, which allows remote attackers to cause a denial of service (split) and enable certain double-spending capabilities via a large block that triggers incorrect Berkeley DB locking.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr7c-jqqr-89vm

An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr79-9mqh-j474

Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.

56%
Средний
больше 4 лет назад

Уязвимостей на страницу