Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-33c6-85j7-6xcp

больше 4 лет назад

SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33c5-xpjg-3vv5

больше 4 лет назад

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

EPSS: Низкий
github логотип

GHSA-33c5-j9v5-cwqf

больше 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33c5-fq57-8p37

больше 4 лет назад

An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33c5-cxgm-mjpc

больше 4 лет назад

A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-33c5-chm5-2ggp

3 дня назад

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender. The manipulation of the argument push_info.url leads to server-side request forgery. Remote exploitation of the attack is possible. Upgrading to version 1.1.4 is able to mitigate this issue. It is suggested to upgrade the affected component.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-33c5-9fx5-fvjm

больше 2 лет назад

Privilege Escalation in Kubernetes

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-33c4-r3r9-gr9g

больше 4 лет назад

Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc79922.

EPSS: Низкий
github логотип

GHSA-33c4-f7cm-95m7

около 3 лет назад

Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33c4-c7ch-qm8j

больше 1 года назад

Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33c4-33mw-wm8j

больше 4 лет назад

HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-33775, CVE-2021-33776, CVE-2021-33777, CVE-2021-33778.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33c3-x8f5-62m8

больше 4 лет назад

bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter.

EPSS: Низкий
github логотип

GHSA-33c3-8653-qmxw

больше 4 лет назад

Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-33c2-g8hf-fxjf

16 дней назад

A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33c2-986r-8vm4

больше 4 лет назад

A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user. If the user has administrative privileges, the attacker could alter the configuration, execute commands, or cause a denial of service (DoS) condition on an affected device.

EPSS: Низкий
github логотип

GHSA-33c2-32m9-q3cg

почти 4 года назад

An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the pbx_exchange process.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-339x-wfph-g72p

больше 4 лет назад

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 159129.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-339x-r4hv-hwwx

6 дней назад

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative interface, which manages the credential store used to gate every other service in the deployment, is delegated entirely to that third-party interface's own login mechanism. Any authentication weakness in that bundled interface would compromise the credential store protecting the rest of the deployment.

EPSS: Низкий
github логотип

GHSA-339x-6c8m-xvxc

2 месяца назад

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-339w-gwg3-jg86

около 4 лет назад

Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33c6-85j7-6xcp

SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-33c5-xpjg-3vv5

Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-33c5-j9v5-cwqf

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-33c5-fq57-8p37

An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-33c5-cxgm-mjpc

A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.

CVSS3: 8.8
23%
Средний
больше 4 лет назад
github логотип
GHSA-33c5-chm5-2ggp

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender. The manipulation of the argument push_info.url leads to server-side request forgery. Remote exploitation of the attack is possible. Upgrading to version 1.1.4 is able to mitigate this issue. It is suggested to upgrade the affected component.

CVSS3: 6.3
0%
Низкий
3 дня назад
github логотип
GHSA-33c5-9fx5-fvjm

Privilege Escalation in Kubernetes

CVSS3: 6.8
6%
Низкий
больше 2 лет назад
github логотип
GHSA-33c4-r3r9-gr9g

Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc79922.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-33c4-f7cm-95m7

Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-33c4-c7ch-qm8j

Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-33c4-33mw-wm8j

HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-33775, CVE-2021-33776, CVE-2021-33777, CVE-2021-33778.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-33c3-x8f5-62m8

bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-33c3-8653-qmxw

Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.

CVSS3: 4.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-33c2-g8hf-fxjf

A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
16 дней назад
github логотип
GHSA-33c2-986r-8vm4

A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user. If the user has administrative privileges, the attacker could alter the configuration, execute commands, or cause a denial of service (DoS) condition on an affected device.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-33c2-32m9-q3cg

An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the pbx_exchange process.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-339x-wfph-g72p

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 159129.

CVSS3: 7.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-339x-r4hv-hwwx

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative interface, which manages the credential store used to gate every other service in the deployment, is delegated entirely to that third-party interface's own login mechanism. Any authentication weakness in that bundled interface would compromise the credential store protecting the rest of the deployment.

0%
Низкий
6 дней назад
github логотип
GHSA-339x-6c8m-xvxc

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
2 месяца назад
github логотип
GHSA-339w-gwg3-jg86

Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability.

CVSS3: 5.3
3%
Низкий
около 4 лет назад

Уязвимостей на страницу