Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2fx6-r6qx-3c7h

около 4 лет назад

Path Traversal in Apache Oozie

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fx6-86r8-c487

около 4 лет назад

Prima Systems FlexAir devices have Hard-coded Credentials.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fx6-2pm7-cwvm

больше 2 лет назад

Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2fx5-pggv-6jjr

больше 1 года назад

TYPO3 Potential Open Redirect via Parsing Differences

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2fx5-835p-hm49

около 1 месяца назад

A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fx4-vwf2-pw99

5 месяцев назад

A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2fx4-qxwh-34x6

около 4 лет назад

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2fx4-8cc3-3383

почти 4 года назад

In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fx4-27pj-8f74

около 4 лет назад

ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.

EPSS: Средний
github логотип

GHSA-2fx2-v8hh-86v7

около 4 лет назад

Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.

EPSS: Низкий
github логотип

GHSA-2fx2-jv5q-q4m6

около 4 лет назад

Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fwx-xc3r-67p8

около 4 лет назад

Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresses via a packet with a small TTL, which triggers an ICMP_TIMXCEED_INTRANS (aka ICMP time exceeded in-transit) response containing an encapsulated IP packet with an intranet address, as demonstrated by a TCP packet to the firewall management server on port 18264.

EPSS: Низкий
github логотип

GHSA-2fwx-cj48-8qqf

больше 3 лет назад

An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fww-xpgm-c42v

около 4 лет назад

HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22018, CVE-2022-29111, CVE-2022-29119.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fww-mhh6-5mxr

около 4 лет назад

Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.

EPSS: Низкий
github логотип

GHSA-2fww-fj3r-9677

почти 2 года назад

The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for unauthenticated attackers to gain unauthorized access to the site.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2fww-cx7f-4r69

около 4 лет назад

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to AD Utilities.

EPSS: Низкий
github логотип

GHSA-2fwv-796r-67vv

больше 4 лет назад

Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigations. Additionally, pages that do make use of CSRF tokens are trivially bypassable as the server does not appear to validate them properly (i.e. re-using an old token or finding the token thru some other method is possible).

EPSS: Низкий
github логотип

GHSA-2fwv-2r36-xvh5

около 1 года назад

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. The manipulation of the argument productId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2fwq-wx47-hm6x

почти 6 лет назад

Malicious Package in bcion

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fx6-r6qx-3c7h

Path Traversal in Apache Oozie

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2fx6-86r8-c487

Prima Systems FlexAir devices have Hard-coded Credentials.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2fx6-2pm7-cwvm

Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fx5-pggv-6jjr

TYPO3 Potential Open Redirect via Parsing Differences

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fx5-835p-hm49

A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2fx4-vwf2-pw99

A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.

CVSS3: 6.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-2fx4-qxwh-34x6

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2fx4-8cc3-3383

In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fx4-27pj-8f74

ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.

13%
Средний
около 4 лет назад
github логотип
GHSA-2fx2-v8hh-86v7

Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2fx2-jv5q-q4m6

Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2fwx-xc3r-67p8

Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresses via a packet with a small TTL, which triggers an ICMP_TIMXCEED_INTRANS (aka ICMP time exceeded in-transit) response containing an encapsulated IP packet with an intranet address, as demonstrated by a TCP packet to the firewall management server on port 18264.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2fwx-cj48-8qqf

An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fww-xpgm-c42v

HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22018, CVE-2022-29111, CVE-2022-29119.

CVSS3: 7.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2fww-mhh6-5mxr

Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2fww-fj3r-9677

The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for unauthenticated attackers to gain unauthorized access to the site.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2fww-cx7f-4r69

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to AD Utilities.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2fwv-796r-67vv

Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigations. Additionally, pages that do make use of CSRF tokens are trivially bypassable as the server does not appear to validate them properly (i.e. re-using an old token or finding the token thru some other method is possible).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2fwv-2r36-xvh5

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. The manipulation of the argument productId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2fwq-wx47-hm6x

Malicious Package in bcion

CVSS3: 9.1
почти 6 лет назад

Уязвимостей на страницу