Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-26gh-p63x-8w5r

около 4 лет назад

An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and the "Content-Type: image/gif" header.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26gh-f8r9-c8p5

около 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-26gh-5qf3-p3q4

около 2 лет назад

Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the testing or production server.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26gg-j5m5-45c6

около 4 лет назад

Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java Advanced Management Console. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java Advanced Management Console. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26gg-j549-wrrg

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: drm/msm/hdmi: fix memory corruption with too many bridges Add the missing sanity check on the bridge counter to avoid corrupting data beyond the fixed-sized bridge array in case there are ever more than eight bridges. Patchwork: https://patchwork.freedesktop.org/patch/502670/

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26gg-9gv2-v27j

3 месяца назад

Spring AI Vulnerable to OOM by attacker-controlled PDF

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26gg-89xw-hgwx

9 месяцев назад

Memory corruption while performing encryption and decryption commands.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26gg-4hm3-4xgm

около 4 лет назад

Unspecified vulnerability in the IPv6 networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_122, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames. NOTE: this issue exists because of an incomplete fix for CVE-2009-2136.

EPSS: Низкий
github логотип

GHSA-26gf-p7cp-hc45

больше 3 лет назад

A vulnerability has been found in falling-fruit and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 15adb8e1ea1f1c3e3d152fc266071f621ef0c621. It is recommended to apply a patch to fix this issue. VDB-215446 is the identifier assigned to this vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-26gf-57vw-hc28

почти 4 года назад

Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26gc-pp26-pw6q

больше 4 лет назад

Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.

EPSS: Низкий
github логотип

GHSA-26g9-w943-5ghm

около 4 лет назад

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.

EPSS: Низкий
github логотип

GHSA-26g9-qm28-697j

больше 4 лет назад

There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash.

EPSS: Низкий
github логотип

GHSA-26g9-q99r-c973

около 4 лет назад

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-26g9-59f6-jrc2

около 4 лет назад

SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-26g9-27vm-x3q8

3 месяца назад

Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-26g8-xr7h-wxh3

больше 4 лет назад

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26g8-pm8g-xfh3

5 месяцев назад

A security flaw has been discovered in D-Link DIR-619L 2.06B01. The affected element is the function formSchedule of the file /goform/formSchedule of the component boa. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26g8-gmr4-3jjh

около 4 лет назад

IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26g6-gmvf-m8xm

около 4 лет назад

In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/input/ff-memless.c driver, aka CID-fa3a5a1880c9.

CVSS3: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26gh-p63x-8w5r

An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and the "Content-Type: image/gif" header.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-26gh-f8r9-c8p5

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-26gh-5qf3-p3q4

Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the testing or production server.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-26gg-j5m5-45c6

Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java Advanced Management Console. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java Advanced Management Console. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 5.3
3%
Низкий
около 4 лет назад
github логотип
GHSA-26gg-j549-wrrg

In the Linux kernel, the following vulnerability has been resolved: drm/msm/hdmi: fix memory corruption with too many bridges Add the missing sanity check on the bridge counter to avoid corrupting data beyond the fixed-sized bridge array in case there are ever more than eight bridges. Patchwork: https://patchwork.freedesktop.org/patch/502670/

CVSS3: 7.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-26gg-9gv2-v27j

Spring AI Vulnerable to OOM by attacker-controlled PDF

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-26gg-89xw-hgwx

Memory corruption while performing encryption and decryption commands.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-26gg-4hm3-4xgm

Unspecified vulnerability in the IPv6 networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_122, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames. NOTE: this issue exists because of an incomplete fix for CVE-2009-2136.

2%
Низкий
около 4 лет назад
github логотип
GHSA-26gf-p7cp-hc45

A vulnerability has been found in falling-fruit and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 15adb8e1ea1f1c3e3d152fc266071f621ef0c621. It is recommended to apply a patch to fix this issue. VDB-215446 is the identifier assigned to this vulnerability.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26gf-57vw-hc28

Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-26gc-pp26-pw6q

Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-26g9-w943-5ghm

An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.

1%
Низкий
около 4 лет назад
github логотип
GHSA-26g9-qm28-697j

There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-26g9-q99r-c973

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.

CVSS3: 8.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-26g9-59f6-jrc2

SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-26g9-27vm-x3q8

Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion

CVSS3: 8
0%
Низкий
3 месяца назад
github логотип
GHSA-26g8-xr7h-wxh3

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-26g8-pm8g-xfh3

A security flaw has been discovered in D-Link DIR-619L 2.06B01. The affected element is the function formSchedule of the file /goform/formSchedule of the component boa. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-26g8-gmr4-3jjh

IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-26g6-gmvf-m8xm

In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/input/ff-memless.c driver, aka CID-fa3a5a1880c9.

CVSS3: 4.6
1%
Низкий
около 4 лет назад

Уязвимостей на страницу