Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhp5-pvv6-r659

около 4 лет назад

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Средний
github логотип

GHSA-xhp4-6g9v-4xvj

около 1 года назад

setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xhp3-g75g-8f9j

около 3 лет назад

An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-xhp2-qq28-gm5m

больше 4 лет назад

In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhmx-mwfm-vrhx

около 4 лет назад

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.

EPSS: Низкий
github логотип

GHSA-xhmx-jv3j-5wf8

около 2 лет назад

Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhmx-j9vh-76xp

около 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49.31, 8.50.20, and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2011-2274.

EPSS: Низкий
github логотип

GHSA-xhmx-2vhp-f3pq

около 4 лет назад

In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216825460References: Upstream kernel

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xhmw-wmwj-jvwr

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in ThemeinProgress WIP Custom Login plugin <= 1.2.9 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xhmw-j639-ph2m

около 4 лет назад

A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhmw-hwm7-v657

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline) inodes is within the allowed range when reading inodes from disk (gfs2_dinode_in()). This prevents us from on-disk corruption. The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just truncate inline data to the maximum allowed size don't actually make sense, and they can be removed now as well.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xhmw-9xf2-ph22

около 4 лет назад

Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.

EPSS: Низкий
github логотип

GHSA-xhmv-px8h-fmgp

больше 2 лет назад

Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhmv-mw7v-7gv2

больше 2 лет назад

Memory corruption when the channel ID passed by user is not validated and further used.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhmv-gf55-q7fw

около 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-xhmv-f9rq-3vrg

около 3 лет назад

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xhmr-rh9j-mc27

8 месяцев назад

A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduct.php?action=edit. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xhmr-m6c6-4xcf

около 4 лет назад

13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.

EPSS: Низкий
github логотип

GHSA-xhmr-j39f-mv9p

больше 4 лет назад

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhmp-rwc3-2j56

17 дней назад

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhp5-pvv6-r659

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

39%
Средний
около 4 лет назад
github логотип
GHSA-xhp4-6g9v-4xvj

setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xhp3-g75g-8f9j

An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.

CVSS3: 8.7
1%
Низкий
около 3 лет назад
github логотип
GHSA-xhp2-qq28-gm5m

In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhmx-mwfm-vrhx

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xhmx-jv3j-5wf8

Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xhmx-j9vh-76xp

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49.31, 8.50.20, and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2011-2274.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhmx-2vhp-f3pq

In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216825460References: Upstream kernel

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xhmw-wmwj-jvwr

Cross-Site Request Forgery (CSRF) vulnerability in ThemeinProgress WIP Custom Login plugin <= 1.2.9 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xhmw-j639-ph2m

A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xhmw-hwm7-v657

In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline) inodes is within the allowed range when reading inodes from disk (gfs2_dinode_in()). This prevents us from on-disk corruption. The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just truncate inline data to the maximum allowed size don't actually make sense, and they can be removed now as well.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xhmw-9xf2-ph22

Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhmv-px8h-fmgp

Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xhmv-mw7v-7gv2

Memory corruption when the channel ID passed by user is not validated and further used.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xhmv-gf55-q7fw

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

около 1 года назад
github логотип
GHSA-xhmv-f9rq-3vrg

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.

CVSS3: 9.8
29%
Средний
около 3 лет назад
github логотип
GHSA-xhmr-rh9j-mc27

A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduct.php?action=edit. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xhmr-m6c6-4xcf

13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhmr-j39f-mv9p

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xhmp-rwc3-2j56

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

CVSS3: 7.8
0%
Низкий
17 дней назад

Уязвимостей на страницу