Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-27q2-f57c-rgmr

около 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

EPSS: Низкий
github логотип

GHSA-27q2-f36g-hmv6

больше 3 лет назад

Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27px-qpmj-qg38

около 4 лет назад

Paste Script has improper group memberships permissions

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27px-4rjc-4chg

больше 4 лет назад

The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27pw-mrx7-45mq

4 месяца назад

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27pw-7wxg-pvx9

больше 2 лет назад

Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27pw-27h4-97mx

около 4 лет назад

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.

EPSS: Низкий
github логотип

GHSA-27pv-w59x-hr4j

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger Currently the runtime.oss.trigger field may be accessed concurrently without protection, which may lead to the data race. And, in this case, it may lead to more severe problem because it's a bit field; as writing the data, it may overwrite other bit fields as well, which confuses the operation completely, as spotted by fuzzing. Fix it by covering runtime.oss.trigger bit fled also with the existing params_lock mutex in both snd_pcm_oss_get_trigger() and snd_pcm_oss_poll().

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27pv-q55r-222g

около 5 лет назад

Path traversal in github.com/ipfs/go-ipfs

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-27pv-p83w-4xp4

около 4 лет назад

Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.

EPSS: Низкий
github логотип

GHSA-27pv-9qxj-gfj6

около 4 лет назад

In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123700383

EPSS: Низкий
github логотип

GHSA-27pv-53mj-ff4j

около 4 лет назад

PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.

EPSS: Низкий
github логотип

GHSA-27pr-r7hm-c2rc

около 3 лет назад

Missing permission check in Jenkins Dimensions Plugin allows enumerating credentials IDs

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-27pr-43qm-8hmf

больше 4 лет назад

The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.

EPSS: Средний
github логотип

GHSA-27pq-p52w-4h65

почти 4 года назад

Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-27pq-h4wp-4qvp

4 дня назад

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27pq-ccjc-wxmc

около 3 лет назад

Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27pq-2ph8-8x25

около 1 месяца назад

Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-27pp-94gr-r5v9

около 4 лет назад

Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-27pm-56m3-q426

больше 2 лет назад

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27q2-f57c-rgmr

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

2%
Низкий
около 4 лет назад
github логотип
GHSA-27q2-f36g-hmv6

Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27px-qpmj-qg38

Paste Script has improper group memberships permissions

CVSS3: 6.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-27px-4rjc-4chg

The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-27pw-mrx7-45mq

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-27pw-7wxg-pvx9

Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27pw-27h4-97mx

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.

5%
Низкий
около 4 лет назад
github логотип
GHSA-27pv-w59x-hr4j

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger Currently the runtime.oss.trigger field may be accessed concurrently without protection, which may lead to the data race. And, in this case, it may lead to more severe problem because it's a bit field; as writing the data, it may overwrite other bit fields as well, which confuses the operation completely, as spotted by fuzzing. Fix it by covering runtime.oss.trigger bit fled also with the existing params_lock mutex in both snd_pcm_oss_get_trigger() and snd_pcm_oss_poll().

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-27pv-q55r-222g

Path traversal in github.com/ipfs/go-ipfs

CVSS3: 7.7
2%
Низкий
около 5 лет назад
github логотип
GHSA-27pv-p83w-4xp4

Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.

4%
Низкий
около 4 лет назад
github логотип
GHSA-27pv-9qxj-gfj6

In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123700383

1%
Низкий
около 4 лет назад
github логотип
GHSA-27pv-53mj-ff4j

PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.

3%
Низкий
около 4 лет назад
github логотип
GHSA-27pr-r7hm-c2rc

Missing permission check in Jenkins Dimensions Plugin allows enumerating credentials IDs

CVSS3: 4.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-27pr-43qm-8hmf

The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.

19%
Средний
больше 4 лет назад
github логотип
GHSA-27pq-p52w-4h65

Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-27pq-h4wp-4qvp

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
4 дня назад
github логотип
GHSA-27pq-ccjc-wxmc

Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-27pq-2ph8-8x25

Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks

CVSS3: 8.1
около 1 месяца назад
github логотип
GHSA-27pp-94gr-r5v9

Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.

CVSS3: 6.1
4%
Низкий
около 4 лет назад
github логотип
GHSA-27pm-56m3-q426

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу