Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-26g6-6369-5jmc

больше 1 года назад

This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for the initiation, modification, or cancellation operations. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body to gain unauthorized access to other user accounts. Successful exploitation of this vulnerability could allow remote attacker to perform authorized manipulation of data associated with other user accounts.

EPSS: Низкий
github логотип

GHSA-26g5-xm46-wmp6

около 4 лет назад

Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execute commands via a message without a signature.

EPSS: Низкий
github логотип

GHSA-26g5-rwh8-qcmq

11 месяцев назад

Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing.This issue affects LimonDesk: from s1.02.14 before v1.02.17.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-26g5-jjxh-94pm

около 2 лет назад

Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26g5-98pg-gvr8

больше 4 лет назад

Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.

EPSS: Низкий
github логотип

GHSA-26g4-r5qf-54qp

около 4 лет назад

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-26g4-3p64-cvvp

около 4 лет назад

Use-after-free vulnerability in the DNS server in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Use After Free Vulnerability."

EPSS: Средний
github логотип

GHSA-26g3-v5f7-pgv9

около 4 лет назад

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

EPSS: Низкий
github логотип

GHSA-26g3-97cv-p9w8

около 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in ZPanel 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the body parameter to templates/ZPanelV2/template.php or (2) the page parameter to zpanel.php. NOTE: the zpanel.php vector may overlap CVE-2005-0793.2. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-26g3-897h-f2rc

больше 1 года назад

Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-26g2-rp9v-hfr4

около 4 лет назад

Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26g2-mv7p-7j93

больше 4 лет назад

Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.

EPSS: Низкий
github логотип

GHSA-26g2-gh8x-5xrm

больше 4 лет назад

Eltima USB Network Gate is affected by Integer Overflow. IOCTL Handler 0x22001B in the USB Network Gate above 7.0.1370 below 9.2.2420 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

EPSS: Низкий
github логотип

GHSA-26fx-wg27-mhq9

больше 3 лет назад

To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

EPSS: Низкий
github логотип

GHSA-26fx-c7cw-5jh4

около 3 лет назад

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26fv-px38-wm73

больше 1 года назад

The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-26fv-2h8q-2655

около 4 лет назад

The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows remote attackers to cause a denial of service (memory allocation failure in the AcquireMagickMemory function in MagickCore/memory.c).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26fr-w2qr-43r5

больше 1 года назад

The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-26fr-9hjv-9fj7

около 4 лет назад

Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.

EPSS: Низкий
github логотип

GHSA-26fr-8fj2-mr2r

почти 4 года назад

OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could disclose sensitive information including kernel pointer, which could be used in further attacks. The processes with system user UID run on the device would be able to mmap memory pools used by kernel and override them which could be used to gain kernel code execution on the device, gain root privileges, or cause device reboot.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26g6-6369-5jmc

This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for the initiation, modification, or cancellation operations. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body to gain unauthorized access to other user accounts. Successful exploitation of this vulnerability could allow remote attacker to perform authorized manipulation of data associated with other user accounts.

0%
Низкий
больше 1 года назад
github логотип
GHSA-26g5-xm46-wmp6

Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execute commands via a message without a signature.

7%
Низкий
около 4 лет назад
github логотип
GHSA-26g5-rwh8-qcmq

Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing.This issue affects LimonDesk: from s1.02.14 before v1.02.17.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-26g5-jjxh-94pm

Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-26g5-98pg-gvr8

Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-26g4-r5qf-54qp

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

7%
Низкий
около 4 лет назад
github логотип
GHSA-26g4-3p64-cvvp

Use-after-free vulnerability in the DNS server in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Use After Free Vulnerability."

30%
Средний
около 4 лет назад
github логотип
GHSA-26g3-v5f7-pgv9

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

0%
Низкий
около 4 лет назад
github логотип
GHSA-26g3-97cv-p9w8

Multiple PHP remote file inclusion vulnerabilities in ZPanel 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the body parameter to templates/ZPanelV2/template.php or (2) the page parameter to zpanel.php. NOTE: the zpanel.php vector may overlap CVE-2005-0793.2. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
около 4 лет назад
github логотип
GHSA-26g3-897h-f2rc

Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.

CVSS3: 6
0%
Низкий
больше 1 года назад
github логотип
GHSA-26g2-rp9v-hfr4

Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-26g2-mv7p-7j93

Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-26g2-gh8x-5xrm

Eltima USB Network Gate is affected by Integer Overflow. IOCTL Handler 0x22001B in the USB Network Gate above 7.0.1370 below 9.2.2420 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-26fx-wg27-mhq9

To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

больше 3 лет назад
github логотип
GHSA-26fx-c7cw-5jh4

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

CVSS3: 7.5
2%
Низкий
около 3 лет назад
github логотип
GHSA-26fv-px38-wm73

The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-26fv-2h8q-2655

The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows remote attackers to cause a denial of service (memory allocation failure in the AcquireMagickMemory function in MagickCore/memory.c).

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-26fr-w2qr-43r5

The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-26fr-9hjv-9fj7

Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.

0%
Низкий
около 4 лет назад
github логотип
GHSA-26fr-8fj2-mr2r

OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could disclose sensitive information including kernel pointer, which could be used in further attacks. The processes with system user UID run on the device would be able to mmap memory pools used by kernel and override them which could be used to gain kernel code execution on the device, gain root privileges, or cause device reboot.

CVSS3: 7.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу