Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xgc4-84f6-p6xr

больше 4 лет назад

VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xgc4-4vwx-6v94

больше 2 лет назад

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgc3-m89p-vr3x

около 5 лет назад

Heap buffer overflow in `Conv2DBackpropFilter`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-xgc2-q928-27wv

больше 4 лет назад

TYPO3 Sensitive Information Disclosure via escapeStrForLike method

EPSS: Низкий
github логотип

GHSA-xg9x-h37w-h3r3

3 месяца назад

ezsystems/ezpublish-legacy has a SQL injection in dfscleanup

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xg9x-3893-67r8

больше 4 лет назад

SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php.

EPSS: Низкий
github логотип

GHSA-xg9w-vg3g-6m68

7 месяцев назад

GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE

EPSS: Низкий
github логотип

GHSA-xg9w-r469-m455

около 2 лет назад

ZendFramework Potential Information Disclosure and Insufficient Entropy vulnerabilities

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xg9w-c4g2-7vr7

больше 4 лет назад

Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-xg9w-79qq-wr22

около 4 лет назад

In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120665616

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xg9w-6w45-pp95

11 месяцев назад

VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xg9w-53r5-frqr

12 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xg9v-jc69-p54f

8 месяцев назад

A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0 Update 10), Solid Edge SE2026 (All versions < V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xg9v-76c9-465p

больше 2 лет назад

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xg9v-2cvq-43hg

больше 4 лет назад

PHP remote file inclusion vulnerability in phpbb_security.php in phpBB Security 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the php_root_path parameter.

EPSS: Низкий
github логотип

GHSA-xg9r-w6fx-9996

около 3 лет назад

In certain EZVIZ products, two stack buffer overflows in netClientSetWlanCfg function of the EZVIZ SDK command server can allow an authenticated attacker present on the same local network as the camera to achieve remote code execution. This affects CS-C6N-B0-1G2WF Firmware versions before V5.3.0 build 230215 and CS-C6N-R101-1G2WF Firmware versions before V5.3.0 build 230215 and CS-CV310-A0-1B2WFR Firmware versions before V5.3.0 build 230221 and CS-CV310-A0-1C2WFR-C Firmware versions before V5.3.2 build 230221 and CS-C6N-A0-1C2WFR-MUL Firmware versions before V5.3.2 build 230218 and CS-CV310-A0-3C2WFRL-1080p Firmware versions before V5.2.7 build 230302 and CS-CV310-A0-1C2WFR Wifi IP66 2.8mm 1080p Firmware versions before V5.3.2 build 230214 and CS-CV248-A0-32WMFR Firmware versions before V5.2.3 build 230217 and EZVIZ LC1C Firmware versions before V5.3.4 build 230214. The impact is: execute arbitrary code (remote).

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xg9r-gfrv-w846

больше 4 лет назад

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xg9q-pjxw-xhgr

больше 4 лет назад

Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.

EPSS: Низкий
github логотип

GHSA-xg9q-jwhp-4c98

14 дней назад

A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xg9q-4rvh-3xhc

9 месяцев назад

Rejected reason: Not used

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgc4-84f6-p6xr

VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgc4-4vwx-6v94

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-xgc3-m89p-vr3x

Heap buffer overflow in `Conv2DBackpropFilter`

CVSS3: 2.5
0%
Низкий
около 5 лет назад
github логотип
GHSA-xgc2-q928-27wv

TYPO3 Sensitive Information Disclosure via escapeStrForLike method

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9x-h37w-h3r3

ezsystems/ezpublish-legacy has a SQL injection in dfscleanup

CVSS3: 7.1
3 месяца назад
github логотип
GHSA-xg9x-3893-67r8

SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9w-vg3g-6m68

GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE

1%
Низкий
7 месяцев назад
github логотип
GHSA-xg9w-r469-m455

ZendFramework Potential Information Disclosure and Insufficient Entropy vulnerabilities

CVSS3: 7.4
около 2 лет назад
github логотип
GHSA-xg9w-c4g2-7vr7

Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/. NOTE: some of these details are obtained from third party information.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9w-79qq-wr22

In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120665616

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xg9w-6w45-pp95

VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-xg9w-53r5-frqr

Rejected reason: Not used

12 месяцев назад
github логотип
GHSA-xg9v-jc69-p54f

A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0 Update 10), Solid Edge SE2026 (All versions < V226.0 Update 1). The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

CVSS3: 7.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xg9v-76c9-465p

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVSS3: 8.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xg9v-2cvq-43hg

PHP remote file inclusion vulnerability in phpbb_security.php in phpBB Security 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the php_root_path parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9r-w6fx-9996

In certain EZVIZ products, two stack buffer overflows in netClientSetWlanCfg function of the EZVIZ SDK command server can allow an authenticated attacker present on the same local network as the camera to achieve remote code execution. This affects CS-C6N-B0-1G2WF Firmware versions before V5.3.0 build 230215 and CS-C6N-R101-1G2WF Firmware versions before V5.3.0 build 230215 and CS-CV310-A0-1B2WFR Firmware versions before V5.3.0 build 230221 and CS-CV310-A0-1C2WFR-C Firmware versions before V5.3.2 build 230221 and CS-C6N-A0-1C2WFR-MUL Firmware versions before V5.3.2 build 230218 and CS-CV310-A0-3C2WFRL-1080p Firmware versions before V5.2.7 build 230302 and CS-CV310-A0-1C2WFR Wifi IP66 2.8mm 1080p Firmware versions before V5.3.2 build 230214 and CS-CV248-A0-32WMFR Firmware versions before V5.2.3 build 230217 and EZVIZ LC1C Firmware versions before V5.3.4 build 230214. The impact is: execute arbitrary code (remote).

CVSS3: 8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xg9r-gfrv-w846

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t...

CVSS3: 7.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9q-pjxw-xhgr

Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg9q-jwhp-4c98

A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.

CVSS3: 7.2
2%
Низкий
14 дней назад
github логотип
GHSA-xg9q-4rvh-3xhc

Rejected reason: Not used

9 месяцев назад

Уязвимостей на страницу