Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-27wr-2vmx-7hq4

около 1 года назад

A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the component File Upload. The manipulation of the argument image leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.2.8 is able to address this issue. The name of the patch is e23559b98c8ea2957f09978c29f4e512ba789eb6. It is recommended to upgrade the affected component.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-27wq-qx3q-fxm9

почти 5 лет назад

Improper Handling of Unexpected Data Type in ced

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27wq-9xfm-724g

больше 1 года назад

An issue in the sqlexp component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27wq-44rw-m6wh

больше 4 лет назад

Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.

EPSS: Низкий
github логотип

GHSA-27wp-xpgf-2rjq

около 4 лет назад

A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system. A successful exploit would consist of an attacker persuading an authorized user to follow a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user.

EPSS: Низкий
github логотип

GHSA-27wp-x9q2-grf8

около 4 лет назад

SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-27wp-jvhw-v4xp

почти 2 года назад

Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-27wp-chg4-ffw3

больше 1 года назад

An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-27wp-7452-56g5

6 месяцев назад

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.7.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-27wm-p6hh-jm27

больше 3 лет назад

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27wj-qvh3-g73h

8 месяцев назад

Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27wj-6vjv-96mm

около 4 лет назад

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27wh-h3mm-7hf3

больше 4 лет назад

FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.

EPSS: Низкий
github логотип

GHSA-27wh-38h4-pr2j

около 1 месяца назад

A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27wg-r456-jc87

больше 2 лет назад

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-27wg-m2hx-ww9m

около 4 лет назад

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27wg-jv26-vh4g

около 4 лет назад

login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.

EPSS: Низкий
github логотип

GHSA-27wg-99g8-2v4v

больше 2 лет назад

Rust EVM erroneousle handles `record_external_operation` error return

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-27wg-3m5v-r5fh

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27wf-jhgm-qm73

больше 1 года назад

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27wr-2vmx-7hq4

A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the component File Upload. The manipulation of the argument image leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.2.8 is able to address this issue. The name of the patch is e23559b98c8ea2957f09978c29f4e512ba789eb6. It is recommended to upgrade the affected component.

CVSS3: 7.3
1%
Низкий
около 1 года назад
github логотип
GHSA-27wq-qx3q-fxm9

Improper Handling of Unexpected Data Type in ced

CVSS3: 7.5
2%
Низкий
почти 5 лет назад
github логотип
GHSA-27wq-9xfm-724g

An issue in the sqlexp component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-27wq-44rw-m6wh

Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-27wp-xpgf-2rjq

A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system. A successful exploit would consist of an attacker persuading an authorized user to follow a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user.

1%
Низкий
около 4 лет назад
github логотип
GHSA-27wp-x9q2-grf8

SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-27wp-jvhw-v4xp

Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

CVSS3: 8.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-27wp-chg4-ffw3

An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.

CVSS3: 8.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-27wp-7452-56g5

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.7.3.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-27wm-p6hh-jm27

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27wj-qvh3-g73h

Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-27wj-6vjv-96mm

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-27wh-h3mm-7hf3

FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-27wh-38h4-pr2j

A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-27wg-r456-jc87

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability.

CVSS3: 5.3
18%
Средний
больше 2 лет назад
github логотип
GHSA-27wg-m2hx-ww9m

Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-27wg-jv26-vh4g

login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-27wg-99g8-2v4v

Rust EVM erroneousle handles `record_external_operation` error return

CVSS3: 5.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-27wg-3m5v-r5fh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-27wf-jhgm-qm73

The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions up to, and including, 2.1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
0%
Низкий
больше 1 года назад

Уязвимостей на страницу