Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 109

Количество 326 109

github логотип

GHSA-xpff-gfqx-47wg

почти 4 года назад

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xpff-c35g-j3cr

почти 2 года назад

silverstripe/framework Privilege Escalation Risk in Member Edit form

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpfc-p72p-hwch

почти 4 года назад

In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpfc-cjr2-3j39

3 месяца назад

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpfc-5pgf-2vp4

почти 4 года назад

PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute arbitrary code by uploading a crafted file, as demonstrated by a file named foo.php.php.

EPSS: Низкий
github логотип

GHSA-xpf8-484v-j9w6

8 месяцев назад

pyjwt v2.10.1 was discovered to contain weak encryption.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xpf7-vf54-5crr

почти 4 года назад

sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.

EPSS: Низкий
github логотип

GHSA-xpf6-m5rc-7966

около 3 лет назад

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpf5-rhc4-rvvh

больше 1 года назад

A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273648.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xpf3-7cmq-j53r

почти 4 года назад

An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. On the 'Air Print Setting' web page, if the data for 'Bonjour Service Location' at /PRESENTATION/BONJOUR is more than 251 bytes when sending data for Air Print Setting, then the device no longer functions until a reboot.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpf3-5x9r-5xfw

10 месяцев назад

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpf3-392m-9g4x

почти 4 года назад

Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via unknown vectors related to Deliverables.

EPSS: Низкий
github логотип

GHSA-xpf2-4v7h-fpcm

почти 3 года назад

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpf2-2px9-cj3p

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.

EPSS: Низкий
github логотип

GHSA-xpcx-xv4v-q822

почти 4 года назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PolyLine annotations. By manipulating a document's elements an attacker can cause a pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6265.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpcx-qq6q-cr7f

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Canalplan allows Reflected XSS. This issue affects Canalplan: from n/a through 5.31.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xpcw-jp98-6h3c

почти 4 года назад

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.

EPSS: Низкий
github логотип

GHSA-xpcw-5x35-jv4r

почти 4 года назад

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

EPSS: Низкий
github логотип

GHSA-xpcw-3w24-57xc

почти 4 года назад

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpcq-x3x2-r3vr

почти 4 года назад

A vulnerability in the local Certificate Authority (CA) feature of Cisco ASA Software before 9.6(1.5) could allow an unauthenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper handling of crafted packets during the enrollment operation. An attacker could exploit this vulnerability by sending a crafted enrollment request to the affected system. An exploit could allow the attacker to cause the reload of the affected system. Note: Only HTTPS packets directed to the Cisco ASA interface, where the local CA is allowing user enrollment, can be used to trigger this vulnerability. This vulnerability affects systems configured in routed firewall mode and in single or multiple context mode.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpff-gfqx-47wg

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

CVSS3: 9.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpff-c35g-j3cr

silverstripe/framework Privilege Escalation Risk in Member Edit form

CVSS3: 6.5
почти 2 года назад
github логотип
GHSA-xpfc-p72p-hwch

In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xpfc-cjr2-3j39

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xpfc-5pgf-2vp4

PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute arbitrary code by uploading a crafted file, as demonstrated by a file named foo.php.php.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xpf8-484v-j9w6

pyjwt v2.10.1 was discovered to contain weak encryption.

CVSS3: 7
0%
Низкий
8 месяцев назад
github логотип
GHSA-xpf7-vf54-5crr

sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xpf6-m5rc-7966

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xpf5-rhc4-rvvh

A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273648.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpf3-7cmq-j53r

An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. On the 'Air Print Setting' web page, if the data for 'Bonjour Service Location' at /PRESENTATION/BONJOUR is more than 251 bytes when sending data for Air Print Setting, then the device no longer functions until a reboot.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpf3-5x9r-5xfw

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xpf3-392m-9g4x

Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via unknown vectors related to Deliverables.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpf2-4v7h-fpcm

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xpf2-2px9-cj3p

Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xpcx-xv4v-q822

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PolyLine annotations. By manipulating a document's elements an attacker can cause a pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6265.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpcx-qq6q-cr7f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Canalplan allows Reflected XSS. This issue affects Canalplan: from n/a through 5.31.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xpcw-jp98-6h3c

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xpcw-5x35-jv4r

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpcw-3w24-57xc

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpcq-x3x2-r3vr

A vulnerability in the local Certificate Authority (CA) feature of Cisco ASA Software before 9.6(1.5) could allow an unauthenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper handling of crafted packets during the enrollment operation. An attacker could exploit this vulnerability by sending a crafted enrollment request to the affected system. An exploit could allow the attacker to cause the reload of the affected system. Note: Only HTTPS packets directed to the Cisco ASA interface, where the local CA is allowing user enrollment, can be used to trigger this vulnerability. This vulnerability affects systems configured in routed firewall mode and in single or multiple context mode.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу