Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xgxr-qjxv-x6mv

больше 4 лет назад

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Apache Tomcat.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xgxr-7w9r-3m55

около 4 лет назад

The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.

EPSS: Низкий
github логотип

GHSA-xgxr-3384-47xm

около 3 лет назад

A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xgxp-wxpw-r9x6

больше 4 лет назад

mount in util-linux 2.19 and earlier does not remove the /etc/mtab.tmp file after a failed attempt to add a mount entry, which allows local users to trigger corruption of the /etc/mtab file via multiple invocations.

EPSS: Низкий
github логотип

GHSA-xgxp-f695-6vrp

5 месяцев назад

In Soft Serve, an authenticated repo import can clone server-local private repositories

EPSS: Низкий
github логотип

GHSA-xgxp-cc5r-jfjq

около 4 лет назад

An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.

EPSS: Низкий
github логотип

GHSA-xgxp-9x8p-gcw4

больше 4 лет назад

SQL Injection

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xgxp-5498-vvcw

4 месяца назад

Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgxj-j98c-59rv

больше 2 лет назад

Mattermost fails to properly restrict the access of files attached to posts

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xgxj-cfph-mm49

больше 3 лет назад

** DISPUTED ** A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The attack may be initiated remotely. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 667c3e2e9178f15c23d7918b5db25cd0792c8472. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216251. NOTE: Most sources redirect to the encrypted site which limits the possibilities of an attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgxh-897r-pw22

около 2 лет назад

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the authenticated user to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xgxg-vmfc-h42h

около 4 лет назад

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. A malformed input file could result in double free of an allocated buffer that leads to a crash. An attacker could leverage this vulnerability to cause denial of service condition. (CNVD-C-2021-79295)

EPSS: Низкий
github логотип

GHSA-xgxg-r58g-f7pr

больше 4 лет назад

Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability."

EPSS: Средний
github логотип

GHSA-xgxg-m2p7-6pr3

около 4 лет назад

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xgxg-434x-64m4

около 3 лет назад

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgxg-3wg9-5qvg

около 4 лет назад

The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xgxf-923g-4wjc

почти 2 года назад

A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/policy/HookWhiteListService.java. The manipulation of the argument policyId leads to sql injection. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xgxc-v2qg-chmh

больше 5 лет назад

Directory Traversal in Django

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xgxc-m69w-gg4w

26 дней назад

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xgxc-757p-24w9

больше 4 лет назад

Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgxr-qjxv-x6mv

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Apache Tomcat.

CVSS3: 7.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgxr-7w9r-3m55

The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xgxr-3384-47xm

A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xgxp-wxpw-r9x6

mount in util-linux 2.19 and earlier does not remove the /etc/mtab.tmp file after a failed attempt to add a mount entry, which allows local users to trigger corruption of the /etc/mtab file via multiple invocations.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xgxp-f695-6vrp

In Soft Serve, an authenticated repo import can clone server-local private repositories

0%
Низкий
5 месяцев назад
github логотип
GHSA-xgxp-cc5r-jfjq

An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xgxp-9x8p-gcw4

SQL Injection

CVSS3: 8.8
46%
Средний
больше 4 лет назад
github логотип
GHSA-xgxp-5498-vvcw

Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xgxj-j98c-59rv

Mattermost fails to properly restrict the access of files attached to posts

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xgxj-cfph-mm49

** DISPUTED ** A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The attack may be initiated remotely. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 667c3e2e9178f15c23d7918b5db25cd0792c8472. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216251. NOTE: Most sources redirect to the encrypted site which limits the possibilities of an attack.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xgxh-897r-pw22

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the authenticated user to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xgxg-vmfc-h42h

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. A malformed input file could result in double free of an allocated buffer that leads to a crash. An attacker could leverage this vulnerability to cause denial of service condition. (CNVD-C-2021-79295)

1%
Низкий
около 4 лет назад
github логотип
GHSA-xgxg-r58g-f7pr

Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability."

27%
Средний
больше 4 лет назад
github логотип
GHSA-xgxg-m2p7-6pr3

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.

CVSS3: 5.3
3%
Низкий
около 4 лет назад
github логотип
GHSA-xgxg-434x-64m4

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xgxg-3wg9-5qvg

The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xgxf-923g-4wjc

A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/policy/HookWhiteListService.java. The manipulation of the argument policyId leads to sql injection. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-xgxc-v2qg-chmh

Directory Traversal in Django

CVSS3: 5.3
4%
Низкий
больше 5 лет назад
github логотип
GHSA-xgxc-m69w-gg4w

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 9.9
0%
Низкий
26 дней назад
github логотип
GHSA-xgxc-757p-24w9

Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу