Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xgxc-3m22-3xcf

больше 4 лет назад

The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgx7-92gq-gr3r

больше 4 лет назад

The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it easier for remote attackers to obtain access.

EPSS: Низкий
github логотип

GHSA-xgx6-xwch-wmqq

больше 4 лет назад

The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock contention.

EPSS: Низкий
github логотип

GHSA-xgx6-9f99-6ww5

больше 1 года назад

IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xgx6-92f3-rhqf

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion.This issue affects Soledad: from n/a through <= 8.7.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgx5-xw2j-vm46

больше 4 лет назад

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2007 Console; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4.5.2, and 4.6; and Silverlight 5 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "True Type Font Parsing Information Disclosure Vulnerability."

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-xgx4-q4c8-wrv3

больше 4 лет назад

Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.

EPSS: Низкий
github логотип

GHSA-xgx4-jvp8-p2h2

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: fix NULL pointer dereference when removing debugfs We now remove the device's debugfs entries when unbinding the driver. This now causes a NULL-pointer dereference on module exit because the platform devices are unregistered *after* the global debugfs directory has been recursively removed. Fix it by unregistering the devices first.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xgx4-4h9w-53pv

2 месяца назад

AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle

EPSS: Низкий
github логотип

GHSA-xgx4-2wgv-4jhm

5 месяцев назад

PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xgx3-9xwc-w89c

больше 4 лет назад

Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref parameter to (1) data/modules/contactform/module_info.php, (2) data/modules/blog/module_info.php, and (3) data/modules/albums/module_info.php, different vectors than CVE-2008-3194.

EPSS: Средний
github логотип

GHSA-xgx2-x646-5944

больше 4 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-xgx2-r4f9-h8w3

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in maxfoundry MaxA/B allows Stored XSS. This issue affects MaxA/B: from n/a through 2.2.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xgx2-84j2-cx9m

3 месяца назад

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgx2-332h-9x6q

больше 4 лет назад

SQL Injection in Yeswiki

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgwx-58r3-m625

около 4 лет назад

There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

EPSS: Низкий
github логотип

GHSA-xgww-w8fw-rw7h

больше 4 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xgww-mgcw-pmxc

больше 1 года назад

The Chessgame Shizzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cs_nonce' parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgww-h98f-24qf

около 4 лет назад

Metasploit Framework user exposes Metasploit to same deserialization issue that is exploited by that module

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xgwv-vx48-69hc

6 месяцев назад

Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgxc-3m22-3xcf

The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgx7-92gq-gr3r

The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it easier for remote attackers to obtain access.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgx6-xwch-wmqq

The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock contention.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xgx6-9f99-6ww5

IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xgx6-92f3-rhqf

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion.This issue affects Soledad: from n/a through <= 8.7.0.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xgx5-xw2j-vm46

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2007 Console; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4.5.2, and 4.6; and Silverlight 5 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "True Type Font Parsing Information Disclosure Vulnerability."

CVSS3: 5.5
54%
Средний
больше 4 лет назад
github логотип
GHSA-xgx4-q4c8-wrv3

Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xgx4-jvp8-p2h2

In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: fix NULL pointer dereference when removing debugfs We now remove the device's debugfs entries when unbinding the driver. This now causes a NULL-pointer dereference on module exit because the platform devices are unregistered *after* the global debugfs directory has been recursively removed. Fix it by unregistering the devices first.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xgx4-4h9w-53pv

AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle

0%
Низкий
2 месяца назад
github логотип
GHSA-xgx4-2wgv-4jhm

PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel

CVSS3: 4.4
5 месяцев назад
github логотип
GHSA-xgx3-9xwc-w89c

Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref parameter to (1) data/modules/contactform/module_info.php, (2) data/modules/blog/module_info.php, and (3) data/modules/albums/module_info.php, different vectors than CVE-2008-3194.

15%
Средний
больше 4 лет назад
github логотип
GHSA-xgx2-x646-5944

Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

15%
Средний
больше 4 лет назад
github логотип
GHSA-xgx2-r4f9-h8w3

Cross-Site Request Forgery (CSRF) vulnerability in maxfoundry MaxA/B allows Stored XSS. This issue affects MaxA/B: from n/a through 2.2.2.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xgx2-84j2-cx9m

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xgx2-332h-9x6q

SQL Injection in Yeswiki

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgwx-58r3-m625

There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xgww-w8fw-rw7h

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xgww-mgcw-pmxc

The Chessgame Shizzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cs_nonce' parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xgww-h98f-24qf

Metasploit Framework user exposes Metasploit to same deserialization issue that is exploited by that module

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xgwv-vx48-69hc

Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

CVSS3: 8.3
0%
Низкий
6 месяцев назад

Уязвимостей на страницу