Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-236c-vhj4-gfxg

больше 4 лет назад

Duplicate Advisory: Embedded malware in ua-parser-js

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-236c-rp7g-fqf2

больше 4 лет назад

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.

EPSS: Низкий
github логотип

GHSA-236c-jvm7-g9g6

больше 4 лет назад

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-236c-586c-7q48

около 1 года назад

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2369-w664-2vw7

больше 4 лет назад

Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2369-v4cc-9249

больше 4 лет назад

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run...

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2369-qr3g-mg2m

4 дня назад

Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2369-78ph-422f

3 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-2369-45jq-xgc9

6 месяцев назад

Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2368-j9pf-v6jc

больше 4 лет назад

Multiple unspecified vulnerabilities in Opera before 10.54 have unknown impact and attack vectors related to (1) "extremely severe," (2) "highly severe," (3) "moderately severe," and (4) "less severe" issues.

EPSS: Низкий
github логотип

GHSA-2367-xw5p-w8h5

3 месяца назад

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2367-v666-24m6

около 2 лет назад

A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. This vulnerability affects unknown code of the file /sscdms/classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-271450 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2367-c296-3mp2

около 5 лет назад

Arbitrary file overwrite in tar-rs

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2366-wj32-h6qc

больше 4 лет назад

Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.

EPSS: Низкий
github логотип

GHSA-2366-wcjw-43wx

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently.

EPSS: Низкий
github логотип

GHSA-2366-559p-m86q

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer The TPM SPI transfer mechanism uses MAX_SPI_FRAMESIZE for computing the maximum transfer length and the size of the transfer buffer. As such, it does not account for the 4 bytes of header that prepends the SPI data frame. This can result in out-of-bounds accesses and was confirmed with KASAN. Introduce SPI_HDRSIZE to account for the header and use to allocate the transfer buffer.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2365-p872-cmm2

больше 4 лет назад

ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2365-7mr9-wqp2

больше 1 года назад

A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown function of the file opencms-dev/src/main/webapp/view/admin/document/dataPage.jsp. The manipulation of the argument path leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2364-qg82-xg35

больше 4 лет назад

An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack (RHOSP) containers could send messages to the dbus. With access to the dbus, the attacker could start or stop services, possibly causing a denial of service. Versions before openstack-selinux 0.8.24 are affected.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2364-jh4q-m9vm

около 1 месяца назад

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-236c-vhj4-gfxg

Duplicate Advisory: Embedded malware in ua-parser-js

CVSS3: 8.8
больше 4 лет назад
github логотип
GHSA-236c-rp7g-fqf2

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-236c-jvm7-g9g6

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
github логотип
GHSA-236c-586c-7q48

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2369-w664-2vw7

Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2369-v4cc-9249

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run...

CVSS3: 9.6
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2369-qr3g-mg2m

Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16.

CVSS3: 7.5
0%
Низкий
4 дня назад
github логотип
GHSA-2369-78ph-422f

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

CVSS3: 9.3
1%
Низкий
3 месяца назад
github логотип
GHSA-2369-45jq-xgc9

Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges.

CVSS3: 7.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-2368-j9pf-v6jc

Multiple unspecified vulnerabilities in Opera before 10.54 have unknown impact and attack vectors related to (1) "extremely severe," (2) "highly severe," (3) "moderately severe," and (4) "less severe" issues.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2367-xw5p-w8h5

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2367-v666-24m6

A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. This vulnerability affects unknown code of the file /sscdms/classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-271450 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-2367-c296-3mp2

Arbitrary file overwrite in tar-rs

CVSS3: 7.5
2%
Низкий
около 5 лет назад
github логотип
GHSA-2366-wj32-h6qc

Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2366-wcjw-43wx

In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently.

больше 2 лет назад
github логотип
GHSA-2366-559p-m86q

In the Linux kernel, the following vulnerability has been resolved: tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer The TPM SPI transfer mechanism uses MAX_SPI_FRAMESIZE for computing the maximum transfer length and the size of the transfer buffer. As such, it does not account for the 4 bytes of header that prepends the SPI data frame. This can result in out-of-bounds accesses and was confirmed with KASAN. Introduce SPI_HDRSIZE to account for the header and use to allocate the transfer buffer.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2365-p872-cmm2

ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2365-7mr9-wqp2

A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown function of the file opencms-dev/src/main/webapp/view/admin/document/dataPage.jsp. The manipulation of the argument path leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2364-qg82-xg35

An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack (RHOSP) containers could send messages to the dbus. With access to the dbus, the attacker could start or stop services, possibly causing a denial of service. Versions before openstack-selinux 0.8.24 are affected.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2364-jh4q-m9vm

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

около 1 месяца назад

Уязвимостей на страницу