Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-38gv-cwr5-whgg

больше 4 лет назад

An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38gr-cjjp-3f5w

больше 2 лет назад

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38gq-f4qx-7pmw

больше 4 лет назад

Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38gq-23v5-5q4r

6 месяцев назад

Missing Authorization vulnerability in CKThemes Flipmart flipmart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flipmart: from n/a through <= 2.8.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-38gp-wr3c-cqw7

больше 4 лет назад

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-38gp-wf27-935r

около 4 лет назад

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gp-jhv5-4hgh

больше 4 лет назад

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38gp-chjq-42jw

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38gp-2mrc-f9cj

почти 4 года назад

Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38gp-237c-7q54

больше 4 лет назад

Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

EPSS: Низкий
github логотип

GHSA-38gm-wvj3-rc26

почти 4 года назад

A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214625 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gm-m6ww-x846

больше 2 лет назад

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker sends high rate of specific ICMP traffic to a device with VXLAN configured, this causes a deadlock of the PFE and results in the device becoming unresponsive. A manual restart will be required to recover the device. This issue only affects EX4100, EX4400, EX4600, QFX5000 Series devices. This issue affects: Juniper Networks Junos OS * 21.4R3 versions earlier than 21.4R3-S4; * 22.1R3 versions earlier than 22.1R3-S3; * 22.2R2 versions earlier than 22.2R3-S1; * 22.3 versions earlier than 22.3R2-S2, 22.3R3; * 22.4 versions earlier than 22.4R2; * 23.1 versions earlier than 23.1R2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38gj-h5v9-v9pm

больше 1 года назад

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38gh-v47f-3r7c

больше 4 лет назад

Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-38gh-hfgh-77mp

3 месяца назад

A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38gh-44mj-6cx9

больше 2 лет назад

Missing Authorization vulnerability in AutoWriter AI Post Generator | AutoWriter.This issue affects AI Post Generator | AutoWriter: from n/a through 3.3.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38gf-rh2w-gmj7

больше 2 лет назад

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-38gf-q933-q62g

почти 2 года назад

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing XML input. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system or conduct an SSRF attack through the affected device.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38gc-w4h9-7pmf

больше 4 лет назад

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

EPSS: Низкий
github логотип

GHSA-38g9-r8v2-99xr

почти 2 года назад

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38gv-cwr5-whgg

An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-38gr-cjjp-3f5w

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-38gq-f4qx-7pmw

Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38gq-23v5-5q4r

Missing Authorization vulnerability in CKThemes Flipmart flipmart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flipmart: from n/a through <= 2.8.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-38gp-wr3c-cqw7

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-38gp-wf27-935r

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-38gp-jhv5-4hgh

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

CVSS3: 6.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38gp-chjq-42jw

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38gp-2mrc-f9cj

Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-38gp-237c-7q54

Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-38gm-wvj3-rc26

A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214625 was assigned to this vulnerability.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-38gm-m6ww-x846

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker sends high rate of specific ICMP traffic to a device with VXLAN configured, this causes a deadlock of the PFE and results in the device becoming unresponsive. A manual restart will be required to recover the device. This issue only affects EX4100, EX4400, EX4600, QFX5000 Series devices. This issue affects: Juniper Networks Junos OS * 21.4R3 versions earlier than 21.4R3-S4; * 22.1R3 versions earlier than 22.1R3-S3; * 22.2R2 versions earlier than 22.2R3-S1; * 22.3 versions earlier than 22.3R2-S2, 22.3R3; * 22.4 versions earlier than 22.4R2; * 23.1 versions earlier than 23.1R2.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-38gj-h5v9-v9pm

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-38gh-v47f-3r7c

Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-38gh-hfgh-77mp

A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-38gh-44mj-6cx9

Missing Authorization vulnerability in AutoWriter AI Post Generator | AutoWriter.This issue affects AI Post Generator | AutoWriter: from n/a through 3.3.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38gf-rh2w-gmj7

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-38gf-q933-q62g

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing XML input. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system or conduct an SSRF attack through the affected device.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-38gc-w4h9-7pmf

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-38g9-r8v2-99xr

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

CVSS3: 9.8
1%
Низкий
почти 2 года назад

Уязвимостей на страницу