Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjhv-6v7m-9x77

около 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xjhr-j8qw-xvfw

больше 4 лет назад

PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter.

EPSS: Низкий
github логотип

GHSA-xjhr-fm27-4hmx

6 месяцев назад

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xjhq-mcqp-qfx3

около 4 лет назад

The affected insulin pump is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

EPSS: Низкий
github логотип

GHSA-xjhq-fvhg-j7h7

больше 2 лет назад

A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Project Name parameter /TaskManager/Projects.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjhq-7cq7-m2mj

около 4 лет назад

Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requesting a .aspx file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjhq-6wq5-hhvx

около 4 лет назад

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjhp-vgwg-948r

больше 2 лет назад

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-xjhp-c9jh-8mhv

около 4 лет назад

emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-xjhp-97gh-h5mv

около 4 лет назад

The ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memory, reading and writing to Model Specific Register (MSR) registers, and input from and output to I/O ports to local non-privileged users. This leads to privilege escalation to NT AUTHORITY\SYSTEM.

EPSS: Низкий
github логотип

GHSA-xjhm-gp88-8pfx

7 месяцев назад

Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xjhm-2p9h-g3h8

больше 4 лет назад

HashiCorp Terraform Enterprise before 202202-1 inserts Sensitive Information into a Log File.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjhj-9v89-v9m8

около 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xjhh-xcpq-fjx4

около 4 лет назад

IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users under specific conditions. IBM X-Fporce ID: 201780.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xjhh-w3rj-8mxm

около 4 лет назад

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-xjhh-pfph-2w9v

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Sutana WP App Bar wp-app-bar allows Reflected XSS.This issue affects WP App Bar: from n/a through <= 1.5.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjhg-wrcc-8945

10 месяцев назад

Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using insecure file/command handling and insufficient validation of attacker-controlled inputs, and in some deployments executed with elevated privileges. A local attacker with low-level access could exploit these weaknesses to cause the script to execute arbitrary commands or modify privileged files, resulting in privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjhg-m88j-hqrc

больше 1 года назад

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjhf-9qgj-jmmq

больше 4 лет назад

TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xjhf-7833-3pm5

12 месяцев назад

Volto affected by possible DoS by invoking specific URL by anonymous user

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjhv-6v7m-9x77

An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xjhr-j8qw-xvfw

PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xjhr-fm27-4hmx

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

CVSS3: 4.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xjhq-mcqp-qfx3

The affected insulin pump is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjhq-fvhg-j7h7

A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Project Name parameter /TaskManager/Projects.php.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xjhq-7cq7-m2mj

Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requesting a .aspx file.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xjhq-6wq5-hhvx

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjhp-vgwg-948r

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.

CVSS3: 4.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xjhp-c9jh-8mhv

emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.

CVSS3: 5.3
21%
Средний
около 4 лет назад
github логотип
GHSA-xjhp-97gh-h5mv

The ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memory, reading and writing to Model Specific Register (MSR) registers, and input from and output to I/O ports to local non-privileged users. This leads to privilege escalation to NT AUTHORITY\SYSTEM.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xjhm-gp88-8pfx

Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xjhm-2p9h-g3h8

HashiCorp Terraform Enterprise before 202202-1 inserts Sensitive Information into a Log File.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjhj-9v89-v9m8

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjhh-xcpq-fjx4

IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users under specific conditions. IBM X-Fporce ID: 201780.

CVSS3: 4.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjhh-w3rj-8mxm

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 4.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xjhh-pfph-2w9v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Sutana WP App Bar wp-app-bar allows Reflected XSS.This issue affects WP App Bar: from n/a through <= 1.5.

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-xjhg-wrcc-8945

Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using insecure file/command handling and insufficient validation of attacker-controlled inputs, and in some deployments executed with elevated privileges. A local attacker with low-level access could exploit these weaknesses to cause the script to execute arbitrary commands or modify privileged files, resulting in privilege escalation.

CVSS3: 7.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-xjhg-m88j-hqrc

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xjhf-9qgj-jmmq

TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjhf-7833-3pm5

Volto affected by possible DoS by invoking specific URL by anonymous user

CVSS3: 7.5
1%
Низкий
12 месяцев назад

Уязвимостей на страницу