Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-xpj8-p66v-3v8x

около 4 лет назад

plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpj8-hw7p-pxp2

больше 4 лет назад

The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xpj8-f336-6vmf

около 4 лет назад

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation occurs in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to handling of bitmap rectangles. A successful attack can lead to sensitive data exposure.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-xpj8-3q42-mc9j

почти 3 года назад

A vulnerability was found in Tongda OA 2017. It has been rated as critical. Affected by this issue is some unknown functionality of the file general/hr/recruit/requirements/delete.php. The manipulation of the argument REQUIREMENTS_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240938 is the identifier assigned to this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpj7-w3p4-qj6q

4 месяца назад

Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpj7-v9x5-6gh9

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Vadym K. Extra User Details allows Stored XSS.This issue affects Extra User Details: from n/a through 0.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xpj7-qrq5-7w9m

больше 4 лет назад

GE Healthcare Infinia II has a default password of (1) infinia for the infinia user, (2) #bigguy1 for the acqservice user, (3) dont4get2 for the Administrator user, (4) #bigguy1 for the emergency user, and (5) 2Bfamous for the InfiniaAdmin user, which has unspecified impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-xpj6-mr3p-wcrr

больше 4 лет назад

archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xpj6-jg5q-m9x4

больше 2 лет назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xpj6-7692-h85x

около 4 лет назад

An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpj5-4mpq-74xf

больше 4 лет назад

The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before version 5.7.3, and Windows before version 5.6.3. This could lead to availability issues on the client host by exhausting system resources.

EPSS: Низкий
github логотип

GHSA-xpj4-jm23-59w7

около 2 лет назад

A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policy

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xpj4-6w39-7c42

около 4 лет назад

An issue was discovered in Asuswrt-Merlin 384.6. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a long string over UDP, which may lead to an information leak.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpj4-4xhh-w7g3

около 4 лет назад

The OpenManage web application 2.5 build 1.19 on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote authenticated users to cause a denial of service (device reset) via a direct request to an unspecified OSPF URL.

EPSS: Низкий
github логотип

GHSA-xpj3-gvqv-w3mp

больше 1 года назад

A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected by this issue is some unknown functionality of the file /update_pd_process.php. The manipulation of the argument profile leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xphx-pcmh-58pq

около 4 лет назад

LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xphx-jp87-55x8

около 4 лет назад

A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not properly sanitized for certain commands at the CLI. An attacker could exploit this vulnerability by sending crafted commands to the CLI of an affected device. A successful exploit could allow the attacker to establish an interactive session with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xphx-6fx2-92w6

8 месяцев назад

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xphw-cqx3-667j

4 месяца назад

thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xphw-85x2-h482

около 4 лет назад

An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpj8-p66v-3v8x

plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xpj8-hw7p-pxp2

The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpj8-f336-6vmf

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation occurs in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to handling of bitmap rectangles. A successful attack can lead to sensitive data exposure.

CVSS3: 6.5
11%
Средний
около 4 лет назад
github логотип
GHSA-xpj8-3q42-mc9j

A vulnerability was found in Tongda OA 2017. It has been rated as critical. Affected by this issue is some unknown functionality of the file general/hr/recruit/requirements/delete.php. The manipulation of the argument REQUIREMENTS_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240938 is the identifier assigned to this vulnerability.

CVSS3: 5.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xpj7-w3p4-qj6q

Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xpj7-v9x5-6gh9

Cross-Site Request Forgery (CSRF) vulnerability in Vadym K. Extra User Details allows Stored XSS.This issue affects Extra User Details: from n/a through 0.5.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpj7-qrq5-7w9m

GE Healthcare Infinia II has a default password of (1) infinia for the infinia user, (2) #bigguy1 for the acqservice user, (3) dont4get2 for the Administrator user, (4) #bigguy1 for the emergency user, and (5) 2Bfamous for the InfiniaAdmin user, which has unspecified impact and attack vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xpj6-mr3p-wcrr

archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpj6-jg5q-m9x4

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpj6-7692-h85x

An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.

CVSS3: 7.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-xpj5-4mpq-74xf

The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before version 5.7.3, and Windows before version 5.6.3. This could lead to availability issues on the client host by exhausting system resources.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xpj4-jm23-59w7

A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policy

CVSS3: 8.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-xpj4-6w39-7c42

An issue was discovered in Asuswrt-Merlin 384.6. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a long string over UDP, which may lead to an information leak.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xpj4-4xhh-w7g3

The OpenManage web application 2.5 build 1.19 on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote authenticated users to cause a denial of service (device reset) via a direct request to an unspecified OSPF URL.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xpj3-gvqv-w3mp

A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected by this issue is some unknown functionality of the file /update_pd_process.php. The manipulation of the argument profile leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xphx-pcmh-58pq

LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.

CVSS3: 6.5
7%
Низкий
около 4 лет назад
github логотип
GHSA-xphx-jp87-55x8

A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not properly sanitized for certain commands at the CLI. An attacker could exploit this vulnerability by sending crafted commands to the CLI of an affected device. A successful exploit could allow the attacker to establish an interactive session with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xphx-6fx2-92w6

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xphw-cqx3-667j

thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xphw-85x2-h482

An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-message channel creation) via the Message slash command.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу