Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-3mmc-w8vq-jvw8

больше 4 лет назад

EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).

EPSS: Низкий
github логотип

GHSA-3mm9-64xc-vf47

7 месяцев назад

A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /jeecg-boot/sys/api/getDictItems. Such manipulation leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3mm9-2p44-rw39

больше 2 лет назад

Silverstripe SiteTree Creation Permission Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mm6-vwmh-qm9c

больше 4 лет назад

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3mm6-mv5c-6hfv

больше 4 лет назад

LastPass prior to 2.5.1 has an insecure PIN implementation.

EPSS: Низкий
github логотип

GHSA-3mm6-hc5r-p5rx

больше 4 лет назад

Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mm6-4hpm-pgrc

больше 4 лет назад

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mm5-rh7g-ph5j

больше 4 лет назад

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mm5-fxrj-9334

больше 4 лет назад

SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.

EPSS: Низкий
github логотип

GHSA-3mm4-w7v6-4rhv

больше 4 лет назад

android-gif-drawable vulerable to denial of service due to unrestricted comment length

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mm4-v52x-x9rw

больше 4 лет назад

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

EPSS: Низкий
github логотип

GHSA-3mm4-jwgr-q6c5

больше 4 лет назад

Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

EPSS: Низкий
github логотип

GHSA-3mm3-wfpv-q85g

10 месяцев назад

Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mm3-f2hp-jpcj

около 2 месяцев назад

Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3mm3-c684-p47h

больше 4 лет назад

The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3mm2-hvqw-hxq3

около 4 лет назад

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3mjx-h33f-j53j

больше 1 года назад

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3mjx-fvq9-8vm2

больше 4 лет назад

BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3mjw-wv6f-4q2v

больше 4 лет назад

Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160.

EPSS: Низкий
github логотип

GHSA-3mjw-95xr-9726

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() On all modern platforms Qualcomm CCI controller provides two I2C masters, and on particular boards only one I2C master may be initialized, and in such cases the device unbinding or driver removal causes a NULL pointer dereference, because cci_halt() is called for all two I2C masters, but a completion is initialized only for the single enabled master: % rmmod i2c-qcom-cci Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 <snip> Call trace: __wait_for_common+0x194/0x1a8 (P) wait_for_completion_timeout+0x20/0x2c cci_remove+0xc4/0x138 [i2c_qcom_cci] platform_remove+0x20/0x30 device_remove+0x4c/0x80 device_release_driver_internal+0x1c8/0x224 driver_detach+0x50/0x98 bus_remove_driver+0x6c/0xbc driver_unregister+0x30/0x60 platform_driver_unregister+0x14/0x20 qcom_cci_...

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mmc-w8vq-jvw8

EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm9-64xc-vf47

A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /jeecg-boot/sys/api/getDictItems. Such manipulation leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3mm9-2p44-rw39

Silverstripe SiteTree Creation Permission Vulnerability

CVSS3: 7.5
больше 2 лет назад
github логотип
GHSA-3mm6-vwmh-qm9c

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm6-mv5c-6hfv

LastPass prior to 2.5.1 has an insecure PIN implementation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm6-hc5r-p5rx

Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm6-4hpm-pgrc

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm5-rh7g-ph5j

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm5-fxrj-9334

SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm4-w7v6-4rhv

android-gif-drawable vulerable to denial of service due to unrestricted comment length

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm4-v52x-x9rw

WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm4-jwgr-q6c5

Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm3-wfpv-q85g

Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage

CVSS3: 7.5
10 месяцев назад
github логотип
GHSA-3mm3-f2hp-jpcj

Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3mm3-c684-p47h

The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mm2-hvqw-hxq3

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335.

CVSS3: 7.2
3%
Низкий
около 4 лет назад
github логотип
GHSA-3mjx-h33f-j53j

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3mjx-fvq9-8vm2

BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjw-wv6f-4q2v

Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjw-95xr-9726

In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() On all modern platforms Qualcomm CCI controller provides two I2C masters, and on particular boards only one I2C master may be initialized, and in such cases the device unbinding or driver removal causes a NULL pointer dereference, because cci_halt() is called for all two I2C masters, but a completion is initialized only for the single enabled master: % rmmod i2c-qcom-cci Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 <snip> Call trace: __wait_for_common+0x194/0x1a8 (P) wait_for_completion_timeout+0x20/0x2c cci_remove+0xc4/0x138 [i2c_qcom_cci] platform_remove+0x20/0x30 device_remove+0x4c/0x80 device_release_driver_internal+0x1c8/0x224 driver_detach+0x50/0x98 bus_remove_driver+0x6c/0xbc driver_unregister+0x30/0x60 platform_driver_unregister+0x14/0x20 qcom_cci_...

CVSS3: 5.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу