Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 419

Количество 288 419

github логотип

GHSA-xxc2-vvph-qprf

около 3 лет назад

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'get <node_name attr>' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxc2-j7jj-6g5m

около 3 лет назад

Raneto Denial of Service via crafted payload injected into `Search` parameter

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxc2-9vrh-pfjm

10 месяцев назад

A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by accessing a tech support file that is generated from an affected system. A successful exploit could allow the attacker to view remote controller admin credentials in clear text. Note: Best practice is to store debug logs and tech support files safely and to share them only with trusted parties because they may contain sensitive information.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxc2-5537-pj53

10 месяцев назад

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xx9x-q3jj-grrj

8 месяцев назад

The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njtele_button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xx9w-q44v-r2wh

около 3 лет назад

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7701.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx9w-p5jh-77v7

почти 2 года назад

Protection Mechanism Failure in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.13.5 allows local attacker to execute arbitrary code.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx9w-464f-7h6f

почти 3 года назад

Harbor fails to validate the user permissions when updating a robot account

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xx9r-h2q8-q5m3

почти 3 года назад

A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling of an IPv6 packet that is forwarded from an MPLS and ZBFW-enabled interface in a 6VPE deployment. An attacker could exploit this vulnerability by sending a crafted IPv6 packet sourced from a device on the IPv6-enabled virtual routing and forwarding (VRF) interface through the affected device. A successful exploit could allow the attacker to reload the device, resulting in a DoS condition.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xx9r-4wqj-799q

8 месяцев назад

SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xx9q-x7hp-rwhj

больше 2 лет назад

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-xx9q-52r9-4c2h

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the alert parameter.

EPSS: Низкий
github логотип

GHSA-xx9p-xxvh-7g8j

больше 1 года назад

Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-xx9p-x7xg-8hpx

около 3 лет назад

A elevation of privilege vulnerability in the MediaTek networking driver. Product: Android. Versions: Android kernel. Android ID: A-36099953. References: M-ALPS03206781.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx9p-q38p-3673

около 3 лет назад

An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31747590. References: MT-ALPS02968983.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xx9p-cfph-9mff

около 3 лет назад

Untrusted search path vulnerability in the installer of MARKET SPEED Ver.16.4 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx9p-c4jq-4cff

больше 1 года назад

An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx9m-mmw4-chgv

больше 3 лет назад

Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.

EPSS: Низкий
github логотип

GHSA-xx9m-jmj4-pwph

около 3 лет назад

Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to FTS.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx9m-2fc7-mhx8

7 месяцев назад

A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxc2-vvph-qprf

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'get <node_name attr>' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xxc2-j7jj-6g5m

Raneto Denial of Service via crafted payload injected into `Search` parameter

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxc2-9vrh-pfjm

A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by accessing a tech support file that is generated from an affected system. A successful exploit could allow the attacker to view remote controller admin credentials in clear text. Note: Best practice is to store debug logs and tech support files safely and to share them only with trusted parties because they may contain sensitive information.

CVSS3: 6.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xxc2-5537-pj53

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory.

CVSS3: 7.2
1%
Низкий
10 месяцев назад
github логотип
GHSA-xx9x-q3jj-grrj

The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njtele_button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xx9w-q44v-r2wh

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within ConvertToPDF_x86.dll. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7701.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xx9w-p5jh-77v7

Protection Mechanism Failure in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.13.5 allows local attacker to execute arbitrary code.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xx9w-464f-7h6f

Harbor fails to validate the user permissions when updating a robot account

CVSS3: 6.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-xx9r-h2q8-q5m3

A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling of an IPv6 packet that is forwarded from an MPLS and ZBFW-enabled interface in a 6VPE deployment. An attacker could exploit this vulnerability by sending a crafted IPv6 packet sourced from a device on the IPv6-enabled virtual routing and forwarding (VRF) interface through the affected device. A successful exploit could allow the attacker to reload the device, resulting in a DoS condition.

CVSS3: 7.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-xx9r-4wqj-799q

SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVSS3: 9.1
1%
Низкий
8 месяцев назад
github логотип
GHSA-xx9q-x7hp-rwhj

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

CVSS3: 7.5
87%
Высокий
больше 2 лет назад
github логотип
GHSA-xx9q-52r9-4c2h

Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the alert parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx9p-xxvh-7g8j

Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks

CVSS3: 3.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx9p-x7xg-8hpx

A elevation of privilege vulnerability in the MediaTek networking driver. Product: Android. Versions: Android kernel. Android ID: A-36099953. References: M-ALPS03206781.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx9p-q38p-3673

An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31747590. References: MT-ALPS02968983.

CVSS3: 7
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx9p-cfph-9mff

Untrusted search path vulnerability in the installer of MARKET SPEED Ver.16.4 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx9p-c4jq-4cff

An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx9m-mmw4-chgv

Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-xx9m-jmj4-pwph

Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to FTS.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx9m-2fc7-mhx8

A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.

CVSS3: 5.5
0%
Низкий
7 месяцев назад

Уязвимостей на страницу