Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-386j-h4xj-j5ph

больше 4 лет назад

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points, aka 'Windows - User Profile Service Elevation of Privilege Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-386j-6m86-78f9

3 месяца назад

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-386j-5xxr-g7c7

19 дней назад

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-386j-565c-f86f

8 месяцев назад

A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-386h-wcf4-977x

больше 1 года назад

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-386g-rfxj-73f8

больше 4 лет назад

AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows computer where the AtlasVPN client is installed.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-386g-pgm8-cfcr

больше 4 лет назад

An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including incidents to which the user does not have access. This issue impacts: All versions of Cortex XSOAR 6.1; All versions of Cortex XSOAR 6.2; All versions of Cortex XSOAR 6.5; Cortex XSOAR 6.6 versions earlier than Cortex XSOAR 6.6.0 build 6.6.0.2585049.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-386g-g557-2gjj

около 4 лет назад

Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at WordPress.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-386g-6xm2-mvq6

больше 2 лет назад

Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-386g-5x7m-jch3

около 1 года назад

INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of INVT HMITool. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of VPM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25044.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-386f-6g8m-9292

больше 4 лет назад

Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3868-3wh9-6qr7

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TSO DMA API usage causing oops Commit 66600fac7a98 ("net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data") moved the assignment of tx_skbuff_dma[]'s members to be later in stmmac_tso_xmit(). The buf (dma cookie) and len stored in this structure are passed to dma_unmap_single() by stmmac_tx_clean(). The DMA API requires that the dma cookie passed to dma_unmap_single() is the same as the value returned from dma_map_single(). However, by moving the assignment later, this is not the case when priv->dma_cap.addr64 > 32 as "des" is offset by proto_hdr_len. This causes problems such as: dwc-eth-dwmac 2490000.ethernet eth0: Tx DMA map failed and with DMA_API_DEBUG enabled: DMA-API: dwc-eth-dwmac 2490000.ethernet: device driver tries to +free DMA memory it has not allocated [device address=0x000000ffffcf65c0] [size=66 bytes] Fix this by maintaining "des" as the original DMA cook...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3867-jc5c-66qf

больше 2 лет назад

Broken Access Control order API in Shopware

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3866-cc7f-3jx4

больше 4 лет назад

The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3866-98fq-wg7f

больше 4 лет назад

The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.

EPSS: Низкий
github логотип

GHSA-3866-72wv-xq49

7 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS).This issue affects Real Estate Script V5 (With Doping Module – Store Module – New Language System): through 17022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3866-5rgc-4rr9

больше 4 лет назад

Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.

EPSS: Низкий
github логотип

GHSA-3865-xcmr-qxp5

больше 3 лет назад

In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALPS07363599.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3864-rp2m-2qfj

почти 2 года назад

libre-chat Path Traversal vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3864-88qj-q5jc

больше 1 года назад

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

CVSS3: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-386j-h4xj-j5ph

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points, aka 'Windows - User Profile Service Elevation of Privilege Vulnerability'.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-386j-6m86-78f9

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

CVSS3: 7.5
3 месяца назад
github логотип
GHSA-386j-5xxr-g7c7

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

CVSS3: 7.5
0%
Низкий
19 дней назад
github логотип
GHSA-386j-565c-f86f

A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command.

CVSS3: 7.2
1%
Низкий
8 месяцев назад
github логотип
GHSA-386h-wcf4-977x

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

CVSS3: 5.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-386g-rfxj-73f8

AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows computer where the AtlasVPN client is installed.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-386g-pgm8-cfcr

An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including incidents to which the user does not have access. This issue impacts: All versions of Cortex XSOAR 6.1; All versions of Cortex XSOAR 6.2; All versions of Cortex XSOAR 6.5; Cortex XSOAR 6.6 versions earlier than Cortex XSOAR 6.6.0 build 6.6.0.2585049.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-386g-g557-2gjj

Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at WordPress.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-386g-6xm2-mvq6

Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.

CVSS3: 8.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-386g-5x7m-jch3

INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of INVT HMITool. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of VPM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25044.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-386f-6g8m-9292

Vulnerability in the Data Store component of Oracle Berkeley DB. The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

CVSS3: 7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3868-3wh9-6qr7

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TSO DMA API usage causing oops Commit 66600fac7a98 ("net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data") moved the assignment of tx_skbuff_dma[]'s members to be later in stmmac_tso_xmit(). The buf (dma cookie) and len stored in this structure are passed to dma_unmap_single() by stmmac_tx_clean(). The DMA API requires that the dma cookie passed to dma_unmap_single() is the same as the value returned from dma_map_single(). However, by moving the assignment later, this is not the case when priv->dma_cap.addr64 > 32 as "des" is offset by proto_hdr_len. This causes problems such as: dwc-eth-dwmac 2490000.ethernet eth0: Tx DMA map failed and with DMA_API_DEBUG enabled: DMA-API: dwc-eth-dwmac 2490000.ethernet: device driver tries to +free DMA memory it has not allocated [device address=0x000000ffffcf65c0] [size=66 bytes] Fix this by maintaining "des" as the original DMA cook...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3867-jc5c-66qf

Broken Access Control order API in Shopware

CVSS3: 4.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3866-cc7f-3jx4

The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3866-98fq-wg7f

The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3866-72wv-xq49

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS).This issue affects Real Estate Script V5 (With Doping Module – Store Module – New Language System): through 17022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-3866-5rgc-4rr9

Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3865-xcmr-qxp5

In display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07363599; Issue ID: ALPS07363599.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3864-rp2m-2qfj

libre-chat Path Traversal vulnerability

CVSS3: 9.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-3864-88qj-q5jc

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

CVSS3: 6.5
11%
Средний
больше 1 года назад

Уязвимостей на страницу