Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-38x9-25wx-7fg2

3 месяца назад

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

EPSS: Низкий
github логотип

GHSA-38x8-p6w4-7fjx

больше 4 лет назад

SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The ln parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38x8-c7cg-pg87

больше 4 лет назад

fwd_check.sh in libncbi6 6.1.20080302 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file.

EPSS: Низкий
github логотип

GHSA-38x8-c543-7468

больше 4 лет назад

SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.

EPSS: Низкий
github логотип

GHSA-38x8-4ffv-qww9

больше 4 лет назад

Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure via the FT Command Centre Service and FT Controller Service services.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38x7-v6rw-7386

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

EPSS: Средний
github логотип

GHSA-38x7-m6wx-74pr

больше 4 лет назад

The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38x7-cc6w-j27q

больше 1 года назад

TYPO3 Information Disclosure via Exception Handling/Logger

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-38x6-g4vx-6g7w

около 3 лет назад

Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38x6-39xc-4cpv

больше 4 лет назад

In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-187702830

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38x5-vg2x-7hw6

больше 4 лет назад

There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38x5-rcv4-xf7x

3 месяца назад

symfony/ux-live-component: XSS via attacker-controlled child component tag

EPSS: Низкий
github логотип

GHSA-38x5-mx6x-v39w

почти 2 года назад

Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verification is disabled everywhere. Therefore, remote unauthenticated users  suitably positioned on the network between an EV charger controller and eCharge infrastructure can execute arbitrary commands with elevated privileges on affected devices. This issue affects cph2_echarge_firmware: through 2.0.4.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-38x5-gc75-363x

больше 4 лет назад

Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability whereby the secondary layer of password protection could by bypassed for individuals with local administrator rights.

EPSS: Низкий
github логотип

GHSA-38x5-6rjp-vc28

больше 4 лет назад

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-38x4-r8qv-j5v2

5 месяцев назад

A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file sql.jsp of the component Interface. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-38x3-v328-497c

около 4 лет назад

Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For header can be manipulated by a client to store an arbitrary value that is used to replace the clientIp variable (without sanitization). A client can thus inject multiple arguments into the session startup. Systems that do not use the clientIP variable in the configuration are not vulnerable. The vulnerability is fixed in these versions: 20.1.16, 20.2.19, 21.1.8, 21.2.12, and 22.1.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38x2-fp9m-87mx

больше 4 лет назад

Improper Input Validation in Apache CXF

EPSS: Низкий
github логотип

GHSA-38wx-782h-g32v

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Compiling). Supported versions that are affected are 5.7.28 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-38ww-hmpv-8hc6

больше 4 лет назад

A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38x9-25wx-7fg2

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

3 месяца назад
github логотип
GHSA-38x8-p6w4-7fjx

SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The ln parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38x8-c7cg-pg87

fwd_check.sh in libncbi6 6.1.20080302 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-38x8-c543-7468

SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-38x8-4ffv-qww9

Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure via the FT Command Centre Service and FT Controller Service services.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38x7-v6rw-7386

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

41%
Средний
больше 4 лет назад
github логотип
GHSA-38x7-m6wx-74pr

The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38x7-cc6w-j27q

TYPO3 Information Disclosure via Exception Handling/Logger

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-38x6-g4vx-6g7w

Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-38x6-39xc-4cpv

In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-187702830

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-38x5-vg2x-7hw6

There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38x5-rcv4-xf7x

symfony/ux-live-component: XSS via attacker-controlled child component tag

0%
Низкий
3 месяца назад
github логотип
GHSA-38x5-mx6x-v39w

Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verification is disabled everywhere. Therefore, remote unauthenticated users  suitably positioned on the network between an EV charger controller and eCharge infrastructure can execute arbitrary commands with elevated privileges on affected devices. This issue affects cph2_echarge_firmware: through 2.0.4.

CVSS3: 9
0%
Низкий
почти 2 года назад
github логотип
GHSA-38x5-gc75-363x

Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability whereby the secondary layer of password protection could by bypassed for individuals with local administrator rights.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-38x5-6rjp-vc28

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38x4-r8qv-j5v2

A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file sql.jsp of the component Interface. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-38x3-v328-497c

Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For header can be manipulated by a client to store an arbitrary value that is used to replace the clientIp variable (without sanitization). A client can thus inject multiple arguments into the session startup. Systems that do not use the clientIP variable in the configuration are not vulnerable. The vulnerability is fixed in these versions: 20.1.16, 20.2.19, 21.1.8, 21.2.12, and 22.1.3.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-38x2-fp9m-87mx

Improper Input Validation in Apache CXF

7%
Низкий
больше 4 лет назад
github логотип
GHSA-38wx-782h-g32v

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Compiling). Supported versions that are affected are 5.7.28 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-38ww-hmpv-8hc6

A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу