Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 352 321

Количество 352 321

github логотип

GHSA-2662-x873-f333

около 4 лет назад

A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-265x-jgfx-f3g8

около 4 лет назад

A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download and execute an arbitrary file via httpDownload function. A successful exploit could allow the attacker to hijack vulnerable system.

EPSS: Низкий
github логотип

GHSA-265x-fx7c-234x

около 4 лет назад

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-265x-5fh2-vqf4

около 4 лет назад

In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x002220e0.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-265x-54h3-3643

около 4 лет назад

Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.

EPSS: Низкий
github логотип

GHSA-265x-3mxm-gj2j

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ehues Gboy Custom Google Map allows Blind SQL Injection.This issue affects Gboy Custom Google Map: from n/a through 1.2.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-265w-rf2w-cjh4

4 месяца назад

Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-265v-54qj-mvh8

около 3 лет назад

The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-265r-pp83-gww7

около 4 лет назад

Cross-site Scripting in Apache Struts

EPSS: Низкий
github логотип

GHSA-265r-hfxg-fhmg

больше 1 года назад

containerd has an integer overflow in User ID handling

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-265q-28rp-chq5

больше 6 лет назад

Insecure Entropy Source - Math.random() in node-uuid

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-265q-222x-52m6

около 2 лет назад

silverstripe/framework has potential SQL Injection vulnerability in PostgreSQL database connector

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-265p-mprc-6xmw

около 4 лет назад

Windows Print Spooler Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26878.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-265p-gc7h-x375

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921e: fix rmmod crash in driver reload test In insmod/rmmod stress test, the following crash dump shows up immediately. The problem is caused by missing mt76_dev in mt7921_pci_remove(). We should make sure the drvdata is ready before probe() finished. [168.862789] ================================================================== [168.862797] BUG: KASAN: user-memory-access in try_to_grab_pending+0x59/0x480 [168.862805] Write of size 8 at addr 0000000000006df0 by task rmmod/5361 [168.862812] CPU: 7 PID: 5361 Comm: rmmod Tainted: G OE 5.19.0-rc6 #1 [168.862816] Hardware name: Intel(R) Client Systems NUC8i7BEH/NUC8BEB, 05/04/2020 [168.862820] Call Trace: [168.862822] <TASK> [168.862825] dump_stack_lvl+0x49/0x63 [168.862832] print_report.cold+0x493/0x6b7 [168.862845] kasan_report+0xa7/0x120 [168.862857] kasan_check_range+0x163/0x200 [168.862861] __kasan_check_write+0x14/0x20 [168.86...

EPSS: Низкий
github логотип

GHSA-265m-mr24-fcwv

около 4 лет назад

The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-265j-p2gg-g729

больше 4 лет назад

Zorbat Zorbstats PHP script before 0.9 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

EPSS: Низкий
github логотип

GHSA-265j-44f5-74rh

больше 4 лет назад

The web configuration server for NTMail V5 and V6 allows remote attackers to cause a denial of service via a series of partial HTTP requests.

EPSS: Низкий
github логотип

GHSA-265h-j3mg-7rf9

около 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.

EPSS: Низкий
github логотип

GHSA-265h-3m42-6x85

около 1 года назад

A vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file invoices.php. The manipulation of the argument del leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-265g-226q-c27c

около 4 лет назад

Unspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun VirtualBox 3.0.x before 3.0.8 on Solaris x86, Linux, and Mac OS X allows local users to gain privileges via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2662-x873-f333

A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-265x-jgfx-f3g8

A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download and execute an arbitrary file via httpDownload function. A successful exploit could allow the attacker to hijack vulnerable system.

1%
Низкий
около 4 лет назад
github логотип
GHSA-265x-fx7c-234x

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

CVSS3: 7.8
8%
Низкий
около 4 лет назад
github логотип
GHSA-265x-5fh2-vqf4

In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x002220e0.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-265x-54h3-3643

Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.

5%
Низкий
около 4 лет назад
github логотип
GHSA-265x-3mxm-gj2j

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ehues Gboy Custom Google Map allows Blind SQL Injection.This issue affects Gboy Custom Google Map: from n/a through 1.2.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-265w-rf2w-cjh4

Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution

CVSS3: 8.8
1%
Низкий
4 месяца назад
github логотип
GHSA-265v-54qj-mvh8

The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-265r-pp83-gww7

Cross-site Scripting in Apache Struts

6%
Низкий
около 4 лет назад
github логотип
GHSA-265r-hfxg-fhmg

containerd has an integer overflow in User ID handling

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-265q-28rp-chq5

Insecure Entropy Source - Math.random() in node-uuid

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
github логотип
GHSA-265q-222x-52m6

silverstripe/framework has potential SQL Injection vulnerability in PostgreSQL database connector

CVSS3: 8.8
около 2 лет назад
github логотип
GHSA-265p-mprc-6xmw

Windows Print Spooler Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26878.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-265p-gc7h-x375

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921e: fix rmmod crash in driver reload test In insmod/rmmod stress test, the following crash dump shows up immediately. The problem is caused by missing mt76_dev in mt7921_pci_remove(). We should make sure the drvdata is ready before probe() finished. [168.862789] ================================================================== [168.862797] BUG: KASAN: user-memory-access in try_to_grab_pending+0x59/0x480 [168.862805] Write of size 8 at addr 0000000000006df0 by task rmmod/5361 [168.862812] CPU: 7 PID: 5361 Comm: rmmod Tainted: G OE 5.19.0-rc6 #1 [168.862816] Hardware name: Intel(R) Client Systems NUC8i7BEH/NUC8BEB, 05/04/2020 [168.862820] Call Trace: [168.862822] <TASK> [168.862825] dump_stack_lvl+0x49/0x63 [168.862832] print_report.cold+0x493/0x6b7 [168.862845] kasan_report+0xa7/0x120 [168.862857] kasan_check_range+0x163/0x200 [168.862861] __kasan_check_write+0x14/0x20 [168.86...

0%
Низкий
7 месяцев назад
github логотип
GHSA-265m-mr24-fcwv

The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-265j-p2gg-g729

Zorbat Zorbstats PHP script before 0.9 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-265j-44f5-74rh

The web configuration server for NTMail V5 and V6 allows remote attackers to cause a denial of service via a series of partial HTTP requests.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-265h-j3mg-7rf9

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.

3%
Низкий
около 4 лет назад
github логотип
GHSA-265h-3m42-6x85

A vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file invoices.php. The manipulation of the argument del leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-265g-226q-c27c

Unspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun VirtualBox 3.0.x before 3.0.8 on Solaris x86, Linux, and Mac OS X allows local users to gain privileges via unknown vectors.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу