Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-2563-r73r-7cq9

больше 4 лет назад

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2563-fp9c-mgm8

больше 3 лет назад

Moodle Session Fixation vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2563-9f8c-7cw3

около 4 лет назад

PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

EPSS: Низкий
github логотип

GHSA-2563-83p7-f34p

почти 6 лет назад

Malicious Package in requestt

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-255x-mvhm-3947

около 4 лет назад

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-255w-8g7g-qmg6

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix race condition during IPSec ESN update In IPSec full offload mode, the device reports an ESN (Extended Sequence Number) wrap event to the driver. The driver validates this event by querying the IPSec ASO and checking that the esn_event_arm field is 0x0, which indicates an event has occurred. After handling the event, the driver must re-arm the context by setting esn_event_arm back to 0x1. A race condition exists in this handling path. After validating the event, the driver calls mlx5_accel_esp_modify_xfrm() to update the kernel's xfrm state. This function temporarily releases and re-acquires the xfrm state lock. So, need to acknowledge the event first by setting esn_event_arm to 0x1. This prevents the driver from reprocessing the same ESN update if the hardware sends events for other reason. Since the next ESN update only occurs after nearly 2^31 packets are received, there's no risk of missing an...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-255w-87rh-rg44

почти 2 года назад

Cross-site Scripting via uploaded SVG

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-255w-3rfx-h4rv

3 месяца назад

Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-255v-qv84-29p5

11 месяцев назад

DragonFly's manager generates mTLS certificates for arbitrary IP addresses

EPSS: Низкий
github логотип

GHSA-255v-qpcm-wc95

около 4 лет назад

Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

EPSS: Низкий
github логотип

GHSA-255v-hc9m-54wv

8 месяцев назад

Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-255v-grg6-24pg

почти 3 года назад

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-255v-ffqg-5w87

больше 3 лет назад

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-255r-pghp-r5wh

почти 6 лет назад

Malicious Package in hdeky

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-255r-f4p7-p9r5

около 4 лет назад

Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

EPSS: Низкий
github логотип

GHSA-255r-96jc-w7r6

30 дней назад

DVP80ES300T with Improper Validation of Array Index Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-255r-3prx-mf99

больше 3 лет назад

`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8

EPSS: Низкий
github логотип

GHSA-255q-f9p7-jxj6

почти 3 года назад

Microsoft SharePoint Server Spoofing Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-255p-hfwr-9qm4

почти 4 года назад

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-255p-hfc6-whjx

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2563-r73r-7cq9

Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2563-fp9c-mgm8

Moodle Session Fixation vulnerability

CVSS3: 9.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-2563-9f8c-7cw3

PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2563-83p7-f34p

Malicious Package in requestt

CVSS3: 9.8
почти 6 лет назад
github логотип
GHSA-255x-mvhm-3947

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-255w-8g7g-qmg6

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix race condition during IPSec ESN update In IPSec full offload mode, the device reports an ESN (Extended Sequence Number) wrap event to the driver. The driver validates this event by querying the IPSec ASO and checking that the esn_event_arm field is 0x0, which indicates an event has occurred. After handling the event, the driver must re-arm the context by setting esn_event_arm back to 0x1. A race condition exists in this handling path. After validating the event, the driver calls mlx5_accel_esp_modify_xfrm() to update the kernel's xfrm state. This function temporarily releases and re-acquires the xfrm state lock. So, need to acknowledge the event first by setting esn_event_arm to 0x1. This prevents the driver from reprocessing the same ESN update if the hardware sends events for other reason. Since the next ESN update only occurs after nearly 2^31 packets are received, there's no risk of missing an...

CVSS3: 4.7
0%
Низкий
4 месяца назад
github логотип
GHSA-255w-87rh-rg44

Cross-site Scripting via uploaded SVG

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-255w-3rfx-h4rv

Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-255v-qv84-29p5

DragonFly's manager generates mTLS certificates for arbitrary IP addresses

0%
Низкий
11 месяцев назад
github логотип
GHSA-255v-qpcm-wc95

Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.

1%
Низкий
около 4 лет назад
github логотип
GHSA-255v-hc9m-54wv

Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-255v-grg6-24pg

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.

CVSS3: 9.8
29%
Средний
почти 3 года назад
github логотип
GHSA-255v-ffqg-5w87

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-255r-pghp-r5wh

Malicious Package in hdeky

CVSS3: 9.1
почти 6 лет назад
github логотип
GHSA-255r-f4p7-p9r5

Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

2%
Низкий
около 4 лет назад
github логотип
GHSA-255r-96jc-w7r6

DVP80ES300T with Improper Validation of Array Index Vulnerability

CVSS3: 7.5
0%
Низкий
30 дней назад
github логотип
GHSA-255r-3prx-mf99

`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8

больше 3 лет назад
github логотип
GHSA-255q-f9p7-jxj6

Microsoft SharePoint Server Spoofing Vulnerability

CVSS3: 8
2%
Низкий
почти 3 года назад
github логотип
GHSA-255p-hfwr-9qm4

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.

CVSS3: 4.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-255p-hfc6-whjx

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021.

4%
Низкий
около 4 лет назад

Уязвимостей на страницу