Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2976-6mfc-xmp6

около 4 лет назад

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.

EPSS: Низкий
github логотип

GHSA-2975-qhjf-83mc

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 1.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2974-6593-2jqm

около 4 лет назад

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

EPSS: Низкий
github логотип

GHSA-2974-5gjv-486c

больше 2 лет назад

A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2973-q4qx-mjf5

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle errors from btrfs_dec_ref() properly In walk_up_proc() we BUG_ON(ret) from btrfs_dec_ref(). This is incorrect, we have proper error handling here, return the error.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2973-f65x-7j53

больше 2 лет назад

Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2972-gp35-c62r

около 1 года назад

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2972-cgfm-mxj8

2 месяца назад

A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2972-7g9m-9qv2

4 месяца назад

A security vulnerability has been detected in Tenda F451 1.0.0.7_cn_svn7958. Impacted is the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-296x-83m2-v73h

около 4 лет назад

vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.

EPSS: Низкий
github логотип

GHSA-296x-6w33-2mmq

около 4 лет назад

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0920, CVE-2019-1005, CVE-2019-1055, CVE-2019-1080.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-296w-6qhq-gf92

около 4 лет назад

Django denial of service via file upload naming

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-296w-48hc-3xvf

3 месяца назад

SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of the data

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-296v-w4c4-j24q

около 4 лет назад

The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-296v-w233-rg6j

около 3 лет назад

AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to the loss confidentiality, integrity, and authentication.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-296v-93wv-2fxf

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NanoSupport allows Reflected XSS. This issue affects NanoSupport: from n/a through 0.6.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-296q-wv58-25qg

около 4 лет назад

JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-296q-vjcw-5f97

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eDoc Intelligence LLC eDoc Easy Tables allows SQL Injection.This issue affects eDoc Easy Tables: from n/a through 1.29.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-296q-rj83-g9rq

около 2 лет назад

Reflected Cross Site-Scripting (XSS) in Oveleon Cookiebar

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-296q-fx3q-6h3p

почти 2 года назад

Windows Networking Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2976-6mfc-xmp6

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2975-qhjf-83mc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 1.0.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2974-6593-2jqm

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2974-5gjv-486c

A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2973-q4qx-mjf5

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle errors from btrfs_dec_ref() properly In walk_up_proc() we BUG_ON(ret) from btrfs_dec_ref(). This is incorrect, we have proper error handling here, return the error.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2973-f65x-7j53

Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2972-gp35-c62r

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2972-cgfm-mxj8

A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2972-7g9m-9qv2

A security vulnerability has been detected in Tenda F451 1.0.0.7_cn_svn7958. Impacted is the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
1%
Низкий
4 месяца назад
github логотип
GHSA-296x-83m2-v73h

vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.

3%
Низкий
около 4 лет назад
github логотип
GHSA-296x-6w33-2mmq

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0920, CVE-2019-1005, CVE-2019-1055, CVE-2019-1080.

CVSS3: 7.5
6%
Низкий
около 4 лет назад
github логотип
GHSA-296w-6qhq-gf92

Django denial of service via file upload naming

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-296w-48hc-3xvf

SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of the data

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-296v-w4c4-j24q

The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-296v-w233-rg6j

AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to the loss confidentiality, integrity, and authentication.

CVSS3: 6.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-296v-93wv-2fxf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NanoSupport allows Reflected XSS. This issue affects NanoSupport: from n/a through 0.6.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-296q-wv58-25qg

JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-296q-vjcw-5f97

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eDoc Intelligence LLC eDoc Easy Tables allows SQL Injection.This issue affects eDoc Easy Tables: from n/a through 1.29.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-296q-rj83-g9rq

Reflected Cross Site-Scripting (XSS) in Oveleon Cookiebar

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-296q-fx3q-6h3p

Windows Networking Denial of Service Vulnerability

CVSS3: 7.5
2%
Низкий
почти 2 года назад

Уязвимостей на страницу