Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2c72-646m-c23c

около 2 лет назад

The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c72-5x23-mj4v

около 4 лет назад

Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including version 10.00.0164 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.

EPSS: Низкий
github логотип

GHSA-2c6x-m49v-xr55

больше 4 лет назад

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c6v-v6m8-9jvh

11 месяцев назад

A weakness has been identified in SpyShelter up to 15.4.0.1015. Affected is an unknown function in the library SpyShelter.sys of the component IOCTL Handler. This manipulation causes denial of service. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited. Upgrading to version 15.4.0.1028 is able to address this issue. It is advisable to upgrade the affected component.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2c6v-h7h5-hq25

7 месяцев назад

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c6v-8r3v-gh6p

5 месяцев назад

Gogs has a Protected Branch Deletion Bypass in Web Interface

EPSS: Низкий
github логотип

GHSA-2c6r-pj43-h4x3

больше 4 лет назад

The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with a different icon.

EPSS: Низкий
github логотип

GHSA-2c6r-gxwp-v69j

около 4 лет назад

Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-5689 and can be performed by a local user with administrative privileges.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2c6r-5j5c-mjw4

около 4 лет назад

Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0023.

EPSS: Средний
github логотип

GHSA-2c6q-rgvj-66rx

около 4 лет назад

Apache Tiles Vulnerable to XSS via EL Expression Injection

EPSS: Низкий
github логотип

GHSA-2c6q-77jp-q575

11 месяцев назад

A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the file /viewsubcategory.php. This manipulation of the argument t1 causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c6q-2f39-j65x

около 4 лет назад

OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c6p-4m26-3gwg

около 2 лет назад

Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21786.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c6p-33cp-55fm

около 4 лет назад

Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2c6m-rwqw-pc6r

около 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.

EPSS: Низкий
github логотип

GHSA-2c6m-mj9w-v79h

больше 4 лет назад

Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.

EPSS: Средний
github логотип

GHSA-2c6m-gpf4-cfgp

около 1 года назад

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c6m-6gqh-6qg3

почти 4 года назад

Docker Command Escaping in the GitHub Actions Runner

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c6m-54c4-x2fg

почти 2 года назад

An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2. It was possible for a guest to read the source code of a private project by using group templates.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c6j-vw6r-mfch

10 месяцев назад

Fiora chat group avatar is vulnerable to XSS via SVG files

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c72-646m-c23c

The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-2c72-5x23-mj4v

Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including version 10.00.0164 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2c6x-m49v-xr55

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2c6v-v6m8-9jvh

A weakness has been identified in SpyShelter up to 15.4.0.1015. Affected is an unknown function in the library SpyShelter.sys of the component IOCTL Handler. This manipulation causes denial of service. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited. Upgrading to version 15.4.0.1028 is able to address this issue. It is advisable to upgrade the affected component.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2c6v-h7h5-hq25

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-2c6v-8r3v-gh6p

Gogs has a Protected Branch Deletion Bypass in Web Interface

0%
Низкий
5 месяцев назад
github логотип
GHSA-2c6r-pj43-h4x3

The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with a different icon.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2c6r-gxwp-v69j

Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-5689 and can be performed by a local user with administrative privileges.

CVSS3: 4.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-2c6r-5j5c-mjw4

Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0023.

16%
Средний
около 4 лет назад
github логотип
GHSA-2c6q-rgvj-66rx

Apache Tiles Vulnerable to XSS via EL Expression Injection

3%
Низкий
около 4 лет назад
github логотип
GHSA-2c6q-77jp-q575

A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the file /viewsubcategory.php. This manipulation of the argument t1 causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 9.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2c6q-2f39-j65x

OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2c6p-4m26-3gwg

Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21786.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2c6p-33cp-55fm

Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2c6m-rwqw-pc6r

Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2c6m-mj9w-v79h

Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.

11%
Средний
больше 4 лет назад
github логотип
GHSA-2c6m-gpf4-cfgp

LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.

CVSS3: 9.8
3%
Низкий
около 1 года назад
github логотип
GHSA-2c6m-6gqh-6qg3

Docker Command Escaping in the GitHub Actions Runner

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2c6m-54c4-x2fg

An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2. It was possible for a guest to read the source code of a private project by using group templates.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2c6j-vw6r-mfch

Fiora chat group avatar is vulnerable to XSS via SVG files

0%
Низкий
10 месяцев назад

Уязвимостей на страницу