Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-26r4-c2j9-3fcx

около 4 лет назад

SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.

EPSS: Низкий
github логотип

GHSA-26r4-3m3w-c772

больше 4 лет назад

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

EPSS: Низкий
github логотип

GHSA-26r3-pw5g-9v53

около 4 лет назад

The mintToken function of a smart contract implementation for Trabet_Coin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26r2-pm58-r4jr

почти 2 года назад

Windows MSHTML Platform Spoofing Vulnerability

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-26r2-c5w2-92vj

около 4 лет назад

The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, which might allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26r2-6q54-995j

больше 4 лет назад

Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26qx-fmxx-pg6h

около 4 лет назад

Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-26qx-4m49-6cfr

больше 2 лет назад

wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26qw-9rj6-9q7x

около 2 месяцев назад

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26qv-p8cr-jxp5

около 1 года назад

External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-26qv-fwp4-4p47

около 1 месяца назад

The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying update_failed_payment_status() function performs no capability check, no nonce verification, and no logged-in check before calling $this->db->updatePaymentByEventId() with attacker-controlled POST parameters. This makes it possible for unauthenticated attackers who can obtain a valid Stripe Payment Intent ID for the target site (Payment Intent IDs are exposed to the customer browser during normal Stripe.js checkout flows) to manipulate payment records in the site's database, marking previously successful payments as failed and overwriting failure codes and messages with attacker-supplied values.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26qv-cc62-952x

9 месяцев назад

Missing Authorization vulnerability in d3wp WP Snow Effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through 1.1.15.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26qv-3573-wxg2

около 2 лет назад

A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272617 was assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-26qr-qf74-v2w4

около 4 лет назад

Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory.

EPSS: Низкий
github логотип

GHSA-26qr-hrpr-gcj8

6 месяцев назад

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-26qr-5f59-55qh

около 4 лет назад

Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-26qr-26wf-xv6x

5 месяцев назад

A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.

EPSS: Низкий
github логотип

GHSA-26qq-h2w9-r3wv

около 4 лет назад

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-26qq-fq9w-jrj5

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix deadlock in remain-on-channel mt76_remain_on_channel() and mt76_roc_complete() call mt76_set_channel() while already holding dev->mutex. Since mt76_set_channel() also acquires dev->mutex, this results in a deadlock. Use __mt76_set_channel() instead of mt76_set_channel(). Add cancel_delayed_work_sync() for mac_work before acquiring the mutex in mt76_remain_on_channel() to prevent a secondary deadlock with the mac_work workqueue.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26qq-9jw6-r5h4

около 4 лет назад

Intesync Solismed 3.3sp has Incorrect Access Control.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26r4-c2j9-3fcx

SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.

1%
Низкий
около 4 лет назад
github логотип
GHSA-26r4-3m3w-c772

Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-26r3-pw5g-9v53

The mintToken function of a smart contract implementation for Trabet_Coin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-26r2-pm58-r4jr

Windows MSHTML Platform Spoofing Vulnerability

CVSS3: 6.5
44%
Средний
почти 2 года назад
github логотип
GHSA-26r2-c5w2-92vj

The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, which might allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-26r2-6q54-995j

Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this incomplete validation logic to download and execute arbitrary malicious file.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-26qx-fmxx-pg6h

Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-26qx-4m49-6cfr

wildfly-core Exposure of Sensitive Information to an Unauthorized Actor vulnerability

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-26qw-9rj6-9q7x

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-26qv-p8cr-jxp5

External control of file name or path in WebDAV allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
81%
Высокий
около 1 года назад
github логотип
GHSA-26qv-fwp4-4p47

The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying update_failed_payment_status() function performs no capability check, no nonce verification, and no logged-in check before calling $this->db->updatePaymentByEventId() with attacker-controlled POST parameters. This makes it possible for unauthenticated attackers who can obtain a valid Stripe Payment Intent ID for the target site (Payment Intent IDs are exposed to the customer browser during normal Stripe.js checkout flows) to manipulate payment records in the site's database, marking previously successful payments as failed and overwriting failure codes and messages with attacker-supplied values.

CVSS3: 5.3
1%
Низкий
около 1 месяца назад
github логотип
GHSA-26qv-cc62-952x

Missing Authorization vulnerability in d3wp WP Snow Effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through 1.1.15.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-26qv-3573-wxg2

A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272617 was assigned to this vulnerability.

CVSS3: 7.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-26qr-qf74-v2w4

Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working directory.

1%
Низкий
около 4 лет назад
github логотип
GHSA-26qr-hrpr-gcj8

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

CVSS3: 6.3
3%
Низкий
6 месяцев назад
github логотип
GHSA-26qr-5f59-55qh

Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-26qr-26wf-xv6x

A vulnerability found in Dahua NVR/XVR device. A third-party malicious attacker with physical access to the device may gain access to a restricted shell via the serial port, and bypasses the shell's authentication mechanism to escalate privileges.

0%
Низкий
5 месяцев назад
github логотип
GHSA-26qq-h2w9-r3wv

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.

CVSS3: 7
1%
Низкий
около 4 лет назад
github логотип
GHSA-26qq-fq9w-jrj5

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix deadlock in remain-on-channel mt76_remain_on_channel() and mt76_roc_complete() call mt76_set_channel() while already holding dev->mutex. Since mt76_set_channel() also acquires dev->mutex, this results in a deadlock. Use __mt76_set_channel() instead of mt76_set_channel(). Add cancel_delayed_work_sync() for mac_work before acquiring the mutex in mt76_remain_on_channel() to prevent a secondary deadlock with the mac_work workqueue.

CVSS3: 5.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-26qq-9jw6-r5h4

Intesync Solismed 3.3sp has Incorrect Access Control.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу