Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-254f-c2wq-r664

больше 4 лет назад

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

EPSS: Низкий
github логотип

GHSA-254c-893v-cfqr

около 1 года назад

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-254c-3p3v-hv7x

13 дней назад

A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file app/Http/Controllers/Admin/SiteThemeEditorController.php of the component Superadmin Theme Editor. This manipulation of the argument blade causes code injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 2.1.1 is capable of addressing this issue. Patch name: 67abfd864a15d169a78429f3290c91cb3b93e849. Upgrading the affected component is advised.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-254c-2j77-4hhm

около 4 лет назад

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2549-xh72-qrpm

больше 1 года назад

Mattermost Improper Validation of Specified Type of Input vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2549-r7rv-9g8p

почти 3 года назад

Information disclosure

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2549-f94w-jg6h

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2548-xwx6-3r34

больше 2 лет назад

A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2548-q746-x5x6

больше 5 лет назад

Code injection in port-killer

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2548-2rfq-335j

больше 4 лет назад

An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

EPSS: Низкий
github логотип

GHSA-2547-59jc-hhfr

больше 1 года назад

Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2546-h2cp-j8x8

больше 4 лет назад

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175767. References: M-ALPS02696445.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2546-c9vw-hgfw

около 4 лет назад

A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2546-8f75-8pq5

больше 4 лет назад

An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2546-6vr9-845q

больше 4 лет назад

PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter.

EPSS: Низкий
github логотип

GHSA-2546-6m8x-7vmx

больше 3 лет назад

In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2546-5j9r-qggh

больше 4 лет назад

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2546-2pf8-h3fr

больше 4 лет назад

Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker get access to files that are stored outside the web root folder via the items[] parameter in a move operation.

EPSS: Низкий
github логотип

GHSA-2544-hpcq-6g27

больше 1 года назад

Mezzanine CMS Cross-Site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2544-g9mc-6gfc

больше 1 года назад

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-254f-c2wq-r664

IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-254c-893v-cfqr

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-254c-3p3v-hv7x

A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file app/Http/Controllers/Admin/SiteThemeEditorController.php of the component Superadmin Theme Editor. This manipulation of the argument blade causes code injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 2.1.1 is capable of addressing this issue. Patch name: 67abfd864a15d169a78429f3290c91cb3b93e849. Upgrading the affected component is advised.

CVSS3: 4.7
0%
Низкий
13 дней назад
github логотип
GHSA-254c-2j77-4hhm

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-2549-xh72-qrpm

Mattermost Improper Validation of Specified Type of Input vulnerability

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2549-r7rv-9g8p

Information disclosure

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2549-f94w-jg6h

Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.

CVSS3: 6.1
10%
Низкий
больше 4 лет назад
github логотип
GHSA-2548-xwx6-3r34

A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2548-q746-x5x6

Code injection in port-killer

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
github логотип
GHSA-2548-2rfq-335j

An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2547-59jc-hhfr

Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2546-h2cp-j8x8

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175767. References: M-ALPS02696445.

CVSS3: 7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2546-c9vw-hgfw

A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2546-8f75-8pq5

An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2546-6vr9-845q

PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2546-6m8x-7vmx

In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2546-5j9r-qggh

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

CVSS3: 9.8
9%
Низкий
больше 4 лет назад
github логотип
GHSA-2546-2pf8-h3fr

Directory traversal in the Media File Organizer (aka media-file-organizer) plugin 1.0.1 for WordPress lets an attacker get access to files that are stored outside the web root folder via the items[] parameter in a move operation.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2544-hpcq-6g27

Mezzanine CMS Cross-Site Scripting (XSS) vulnerability

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2544-g9mc-6gfc

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу