Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 571

Количество 323 571

github логотип

GHSA-xw67-vhv2-m2p4

почти 4 года назад

CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.

EPSS: Низкий
github логотип

GHSA-xw67-hqxc-2h5x

почти 4 года назад

Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xw66-fwrq-35x6

около 2 лет назад

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xw66-7hgg-w34f

почти 4 года назад

Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.

EPSS: Низкий
github логотип

GHSA-xw65-r59v-qpqc

почти 4 года назад

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw65-jr46-vvcm

почти 4 года назад

The No Fuss Home Loans (aka com.soln.SA2CAA74BBC3AFEFE7C8BE3F3AAC499E7) application 1.0035.b0035 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xw65-g8p2-hc6q

почти 4 года назад

It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.

EPSS: Низкий
github логотип

GHSA-xw65-8v8j-f5mq

почти 2 года назад

The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.13. This is due to missing or incorrect nonce validation on the duplicateForm() function. This makes it possible for unauthenticated attackers to duplicate forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xw65-87w9-v79c

почти 4 года назад

There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xw64-mvx9-6946

5 месяцев назад

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xw63-wh8f-q2fm

6 месяцев назад

A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted is an unknown function of the file /Profilers/PriProfile/COUNT3s7.php. The manipulation of the argument cbe leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xw63-m43m-c93h

почти 4 года назад

MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xw62-w8g4-hmhx

почти 4 года назад

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xw62-rx45-hvr3

5 месяцев назад

The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials.

EPSS: Низкий
github логотип

GHSA-xw62-fv8f-gc9h

почти 4 года назад

Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial of service (application crash) via a crafted speed (aka rate) value.

EPSS: Низкий
github логотип

GHSA-xw5w-5r82-mf3j

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xw5v-rpqc-44jg

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection.This issue affects Scienta: before 20230630.1953.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xw5r-6r86-qg74

почти 4 года назад

LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port" sequence; or (2) a malformed Range header, which triggers misparsing in parse_play_time_range in RTSP_Play, as demonstrated by an empty Range header.

EPSS: Низкий
github логотип

GHSA-xw5r-2555-jwfv

почти 4 года назад

Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Низкий
github логотип

GHSA-xw5q-g62x-2qjc

9 месяцев назад

electron ASAR Integrity bypass by just modifying the content

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw67-vhv2-m2p4

CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw67-hqxc-2h5x

Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xw66-fwrq-35x6

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xw66-7hgg-w34f

Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xw65-r59v-qpqc

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xw65-jr46-vvcm

The No Fuss Home Loans (aka com.soln.SA2CAA74BBC3AFEFE7C8BE3F3AAC499E7) application 1.0035.b0035 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw65-g8p2-hc6q

It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw65-8v8j-f5mq

The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.13. This is due to missing or incorrect nonce validation on the duplicateForm() function. This makes it possible for unauthenticated attackers to duplicate forms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xw65-87w9-v79c

There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xw64-mvx9-6946

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 2.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-xw63-wh8f-q2fm

A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted is an unknown function of the file /Profilers/PriProfile/COUNT3s7.php. The manipulation of the argument cbe leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xw63-m43m-c93h

MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.

CVSS3: 9.8
38%
Средний
почти 4 года назад
github логотип
GHSA-xw62-w8g4-hmhx

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xw62-rx45-hvr3

The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could allow attackers to gain shell access without valid credentials.

0%
Низкий
5 месяцев назад
github логотип
GHSA-xw62-fv8f-gc9h

Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial of service (application crash) via a crafted speed (aka rate) value.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xw5w-5r82-mf3j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.

CVSS3: 5.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-xw5v-rpqc-44jg

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection.This issue affects Scienta: before 20230630.1953.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xw5r-6r86-qg74

LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port" sequence; or (2) a malformed Range header, which triggers misparsing in parse_play_time_range in RTSP_Play, as demonstrated by an empty Range header.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xw5r-2555-jwfv

Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xw5q-g62x-2qjc

electron ASAR Integrity bypass by just modifying the content

CVSS3: 7.8
0%
Низкий
9 месяцев назад

Уязвимостей на страницу