Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 989

Количество 376 989

github логотип

GHSA-3p3w-8fvr-q4gw

больше 4 лет назад

Multiple unspecified vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

EPSS: Низкий
github логотип

GHSA-3p3v-qhpw-qrgr

5 месяцев назад

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-user parameter to /cgi-bin/cstecgi.cgi.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p3r-fjqw-f7g3

больше 4 лет назад

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.

EPSS: Низкий
github логотип

GHSA-3p3q-w36v-m4vj

больше 4 лет назад

Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a denial of service (crash) via a flood of "extraneous" messages, as demonstrated by the Nessus "Generic flood" denial of service plugin.

EPSS: Низкий
github логотип

GHSA-3p3q-5gjp-wvmc

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3p3p-qg5g-j2p5

больше 4 лет назад

SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.

EPSS: Низкий
github логотип

GHSA-3p3p-pvm7-cggr

больше 4 лет назад

Winston 1.5.4 devices are vulnerable to command injection via the API.

EPSS: Низкий
github логотип

GHSA-3p3p-cgj7-vgw3

больше 2 лет назад

RSSHub vulnerable to Server-Side Request Forgery

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p3m-mqcr-8mfw

около 3 лет назад

Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p3m-h26v-9r73

больше 4 лет назад

The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p3m-4x7c-p4pw

4 месяца назад

unsafe parameter handing in `wsrep_notify_cmd`

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3p3h-qghp-hvh2

больше 5 лет назад

Open Redirect in werkzeug

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p3h-j9q4-q239

почти 2 года назад

Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3p3h-7wpm-9j2r

около 4 лет назад

Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p3h-5g54-qmc8

почти 2 года назад

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p3g-vpw6-4w66

больше 5 лет назад

Authentication Bypass in hydra

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3p3g-v9c5-jwvw

больше 3 лет назад

An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS/FortiProxy device and remote servers hosting threat feeds (when the latter are configured as Fabric connectors in FortiOS/FortiProxy)

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3p3f-hgmm-72qv

больше 4 лет назад

Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3p3f-h63v-47c5

больше 4 лет назад

A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p3f-cf7r-qqhf

больше 4 лет назад

FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain privileges.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p3w-8fvr-q4gw

Multiple unspecified vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3v-qhpw-qrgr

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-user parameter to /cgi-bin/cstecgi.cgi.

CVSS3: 6.5
1%
Низкий
5 месяцев назад
github логотип
GHSA-3p3r-fjqw-f7g3

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3q-w36v-m4vj

Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a denial of service (crash) via a flood of "extraneous" messages, as demonstrated by the Nessus "Generic flood" denial of service plugin.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3q-5gjp-wvmc

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

больше 1 года назад
github логотип
GHSA-3p3p-qg5g-j2p5

SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3p-pvm7-cggr

Winston 1.5.4 devices are vulnerable to command injection via the API.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3p-cgj7-vgw3

RSSHub vulnerable to Server-Side Request Forgery

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p3m-mqcr-8mfw

Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p3m-h26v-9r73

The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3m-4x7c-p4pw

unsafe parameter handing in `wsrep_notify_cmd`

CVSS3: 10
2%
Низкий
4 месяца назад
github логотип
GHSA-3p3h-qghp-hvh2

Open Redirect in werkzeug

CVSS3: 6.1
2%
Низкий
больше 5 лет назад
github логотип
GHSA-3p3h-j9q4-q239

Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

CVSS3: 8.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3p3h-7wpm-9j2r

Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3p3h-5g54-qmc8

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3p3g-vpw6-4w66

Authentication Bypass in hydra

CVSS3: 5.8
1%
Низкий
больше 5 лет назад
github логотип
GHSA-3p3g-v9c5-jwvw

An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS/FortiProxy device and remote servers hosting threat feeds (when the latter are configured as Fabric connectors in FortiOS/FortiProxy)

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p3f-hgmm-72qv

Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3f-h63v-47c5

A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3f-cf7r-qqhf

FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain privileges.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу