Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-36hr-2pgw-4595

больше 4 лет назад

Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the application database.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36hq-xx3q-26mm

около 3 лет назад

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to a buffer overflow. An attacker can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_dmvpn function with the gre_ip and the gre_mask variables.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-36hq-v2fc-rpqp

около 3 лет назад

Jenkins Folders Plugin information disclosure vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-36hq-fr9w-frm9

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter).

EPSS: Низкий
github логотип

GHSA-36hp-jr8h-556f

больше 5 лет назад

Authentication Bypass

EPSS: Высокий
github логотип

GHSA-36hp-4x3g-phrg

больше 4 лет назад

Apache Tomcat's CookieExample Vulnerable to XSS

EPSS: Низкий
github логотип

GHSA-36hp-4q45-jxjc

около 1 месяца назад

Subscriber Path Traversal in Do Lasso <= 358 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36hm-qxxp-pg3m

9 месяцев назад

Preact has JSON VNode Injection issue

EPSS: Низкий
github логотип

GHSA-36hm-mqp3-4q69

больше 3 лет назад

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20300)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36hm-h89f-cr4p

10 месяцев назад

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36hm-c9f8-f8xc

4 месяца назад

Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36hm-c3f9-q57c

около 3 лет назад

SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-36hm-353j-v57w

больше 4 лет назад

Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36hj-r7fq-q38m

2 дня назад

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36hj-m3c2-4ggw

больше 4 лет назад

Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.

EPSS: Низкий
github логотип

GHSA-36hj-g8jh-r4rq

почти 3 года назад

A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-36hj-f8vr-vxrj

больше 4 лет назад

Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36hh-x5p5-jgc8

4 месяца назад

@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters

EPSS: Низкий
github логотип

GHSA-36hh-vpg6-r82h

больше 4 лет назад

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.

EPSS: Низкий
github логотип

GHSA-36hh-v57m-3mm5

больше 4 лет назад

NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36hr-2pgw-4595

Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the application database.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-36hq-xx3q-26mm

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to a buffer overflow. An attacker can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_dmvpn function with the gre_ip and the gre_mask variables.

CVSS3: 7.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-36hq-v2fc-rpqp

Jenkins Folders Plugin information disclosure vulnerability

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-36hq-fr9w-frm9

Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36hp-jr8h-556f

Authentication Bypass

88%
Высокий
больше 5 лет назад
github логотип
GHSA-36hp-4x3g-phrg

Apache Tomcat's CookieExample Vulnerable to XSS

3%
Низкий
больше 4 лет назад
github логотип
GHSA-36hp-4q45-jxjc

Subscriber Path Traversal in Do Lasso <= 358 versions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-36hm-qxxp-pg3m

Preact has JSON VNode Injection issue

0%
Низкий
9 месяцев назад
github логотип
GHSA-36hm-mqp3-4q69

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20300)

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36hm-h89f-cr4p

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-36hm-c9f8-f8xc

Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-36hm-c3f9-q57c

SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.

CVSS3: 7.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-36hm-353j-v57w

Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-36hj-r7fq-q38m

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.

CVSS3: 9.8
0%
Низкий
2 дня назад
github логотип
GHSA-36hj-m3c2-4ggw

Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36hj-g8jh-r4rq

A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-36hj-f8vr-vxrj

Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36hh-x5p5-jgc8

@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters

0%
Низкий
4 месяца назад
github логотип
GHSA-36hh-vpg6-r82h

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-36hh-v57m-3mm5

NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу