Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-227x-w5qv-2294

больше 4 лет назад

admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

EPSS: Низкий
github логотип

GHSA-227x-7mh8-3cf6

11 месяцев назад

Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-227x-6m74-5g32

больше 3 лет назад

Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-227x-48c5-2jpf

около 4 лет назад

HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.

EPSS: Низкий
github логотип

GHSA-227w-xh58-rx2j

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.

EPSS: Низкий
github логотип

GHSA-227w-wv4j-67h4

больше 4 лет назад

Class Loading Vulnerability in Artemis

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-227w-82c7-87qx

около 4 лет назад

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS: Низкий
github логотип

GHSA-227v-w3r6-6vc4

около 4 лет назад

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-227v-m6p6-j6gx

почти 3 года назад

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-227r-w5j2-6243

больше 1 года назад

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-227r-vmhh-jq3x

8 месяцев назад

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.

EPSS: Низкий
github логотип

GHSA-227r-jm2g-7cp4

около 1 месяца назад

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-227r-cc3q-mh85

около 4 лет назад

Windows GDI+ Information Disclosure Vulnerability

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-227p-wwrh-m869

5 месяцев назад

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-227p-7qgj-96v9

около 2 лет назад

Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-227m-878m-h3qm

около 2 лет назад

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-227j-xj2v-7f5v

около 4 лет назад

The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

EPSS: Низкий
github логотип

GHSA-227h-wvc4-w9jx

около 4 лет назад

In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-227h-6jwp-327q

больше 2 лет назад

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-227g-p58c-6fwx

больше 1 года назад

Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-227x-w5qv-2294

admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-227x-7mh8-3cf6

Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning

CVSS3: 9.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-227x-6m74-5g32

Cross Site Scripting vulnerability found in Exelysis Unified Communication Solutions (EUCS) v.1.0 allows a remote attacker to execute arbitrary code via the Username parameter of the eucsAdmin login form.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-227x-48c5-2jpf

HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-227w-xh58-rx2j

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to hijack the authentication of arbitrary users for requests that send course messages.

1%
Низкий
около 4 лет назад
github логотип
GHSA-227w-wv4j-67h4

Class Loading Vulnerability in Artemis

CVSS3: 8.2
0%
Низкий
больше 4 лет назад
github логотип
GHSA-227w-82c7-87qx

The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

2%
Низкий
около 4 лет назад
github логотип
GHSA-227v-w3r6-6vc4

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-227v-m6p6-j6gx

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-227r-w5j2-6243

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-227r-vmhh-jq3x

The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.

0%
Низкий
8 месяцев назад
github логотип
GHSA-227r-jm2g-7cp4

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-227r-cc3q-mh85

Windows GDI+ Information Disclosure Vulnerability

CVSS3: 5.7
3%
Низкий
около 4 лет назад
github логотип
GHSA-227p-wwrh-m869

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

CVSS3: 9.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-227p-7qgj-96v9

Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-227m-878m-h3qm

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-227j-xj2v-7f5v

The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-227h-wvc4-w9jx

In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-227h-6jwp-327q

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation of the argument useremail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-227g-p58c-6fwx

Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2.

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу