Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-33ff-q632-5gfm

больше 4 лет назад

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

EPSS: Средний
github логотип

GHSA-33ff-c2wp-wfmh

больше 3 лет назад

Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33f9-j839-rf8h

около 5 лет назад

Prototype Pollution in immer

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33f9-8mmr-x938

больше 4 лет назад

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33f9-622r-p353

больше 4 лет назад

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-33f9-4h6q-m86q

около 4 лет назад

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-33f8-vpx6-6229

больше 4 лет назад

Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128.

EPSS: Низкий
github логотип

GHSA-33f8-qg6q-959p

больше 4 лет назад

SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.

EPSS: Низкий
github логотип

GHSA-33f7-6fm9-7m6p

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode Stop adjusting the horizontal timing values based on the compression ratio in command mode. Bspec seems to be telling us to do this only in video mode, and this is also how the Windows driver does things. This should also fix a div-by-zero on some machines because the adjusted htotal ends up being so small that we end up with line_time_us==0 when trying to determine the vtotal value in command mode. Note that this doesn't actually make the display on the Huawei Matebook E work, but at least the kernel no longer explodes when the driver loads. (cherry picked from commit 0b475e91ecc2313207196c6d7fd5c53e1a878525)

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33f7-633w-3fph

около 1 года назад

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-33f5-5f45-vcqg

больше 4 лет назад

Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-33f5-2c5q-wgwj

1 день назад

RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-33f4-xj2w-x86q

больше 1 года назад

A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper authorization. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-33f4-mjch-7fpr

11 месяцев назад

Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

EPSS: Низкий
github логотип

GHSA-33f4-9prw-vfp6

около 4 лет назад

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33f4-9hr4-253g

больше 4 лет назад

A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An attacker could exploit this vulnerability by sending properly formatted data values to the statistics collection service of an affected device. A successful exploit could allow the attacker to cause the web interface statistics view to present invalid data to users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33f3-88p6-j3f9

больше 2 лет назад

TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33f2-v5w3-mmvw

больше 1 года назад

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-33f2-r445-jvq6

больше 4 лет назад

Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file following after call_mmap() returns an error. However, the aufs patchs change mmap_region() to replace the fput() using a local variable with vma_fput(), which will fput() vm_file, leading to a refcount underflow.

EPSS: Низкий
github логотип

GHSA-33f2-chfr-x425

больше 4 лет назад

Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33ff-q632-5gfm

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

69%
Средний
больше 4 лет назад
github логотип
GHSA-33ff-c2wp-wfmh

Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33f9-j839-rf8h

Prototype Pollution in immer

CVSS3: 9.8
2%
Низкий
около 5 лет назад
github логотип
GHSA-33f9-8mmr-x938

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

CVSS3: 6.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-33f9-622r-p353

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.

CVSS3: 6.2
0%
Низкий
больше 4 лет назад
github логотип
GHSA-33f9-4h6q-m86q

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.

CVSS3: 7.2
2%
Низкий
около 4 лет назад
github логотип
GHSA-33f8-vpx6-6229

Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-33f8-qg6q-959p

SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-33f7-6fm9-7m6p

In the Linux kernel, the following vulnerability has been resolved: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode Stop adjusting the horizontal timing values based on the compression ratio in command mode. Bspec seems to be telling us to do this only in video mode, and this is also how the Windows driver does things. This should also fix a div-by-zero on some machines because the adjusted htotal ends up being so small that we end up with line_time_us==0 when trying to determine the vtotal value in command mode. Note that this doesn't actually make the display on the Huawei Matebook E work, but at least the kernel no longer explodes when the driver loads. (cherry picked from commit 0b475e91ecc2313207196c6d7fd5c53e1a878525)

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-33f7-633w-3fph

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-33f5-5f45-vcqg

Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.

CVSS3: 7.5
10%
Средний
больше 4 лет назад
github логотип
GHSA-33f5-2c5q-wgwj

RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery

CVSS3: 8.2
1 день назад
github логотип
GHSA-33f4-xj2w-x86q

A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper authorization. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-33f4-mjch-7fpr

Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

0%
Низкий
11 месяцев назад
github логотип
GHSA-33f4-9prw-vfp6

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-33f4-9hr4-253g

A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An attacker could exploit this vulnerability by sending properly formatted data values to the statistics collection service of an affected device. A successful exploit could allow the attacker to cause the web interface statistics view to present invalid data to users.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-33f3-88p6-j3f9

TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-33f2-v5w3-mmvw

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-33f2-r445-jvq6

Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file following after call_mmap() returns an error. However, the aufs patchs change mmap_region() to replace the fput() using a local variable with vma_fput(), which will fput() vm_file, leading to a refcount underflow.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-33f2-chfr-x425

Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу