Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-xw5j-5p2q-fr86

около 1 месяца назад

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw5j-4h78-77h2

больше 4 лет назад

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw5h-h3cf-m4mx

больше 4 лет назад

Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.

EPSS: Низкий
github логотип

GHSA-xw5h-cmh3-8j6j

около 2 месяцев назад

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xw5h-8j92-59pp

почти 4 года назад

open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw5g-qgw7-x534

около 4 лет назад

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xw5g-39g7-vh7x

около 4 лет назад

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xw5f-m9q2-678f

около 4 лет назад

Microsoft SharePoint Denial of Service Update

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xw5f-g937-wgm2

около 4 лет назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw5f-2w3q-6c92

около 4 лет назад

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xw5c-xwc7-95gf

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw5c-jc7x-gf75

4 месяца назад

PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw59-hvm2-8pj6

4 месяца назад

DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xw59-4mp5-9chf

около 4 лет назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xw58-crph-crhm

больше 2 лет назад

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xw58-64fr-3323

больше 1 года назад

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to overwrite arbitrary files.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xw57-xggj-g8vq

больше 4 лет назад

SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter.

EPSS: Низкий
github логотип

GHSA-xw57-qhqx-v67p

больше 1 года назад

A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xw57-23p8-9wc5

около 1 месяца назад

@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)

EPSS: Низкий
github логотип

GHSA-xw55-hvqx-m963

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw5j-5p2q-fr86

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xw5j-4h78-77h2

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5h-h3cf-m4mx

Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5h-cmh3-8j6j

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-xw5h-8j92-59pp

open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xw5g-qgw7-x534

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xw5g-39g7-vh7x

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw5f-m9q2-678f

Microsoft SharePoint Denial of Service Update

CVSS3: 5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xw5f-g937-wgm2

ChakraCore RCE Vulnerability

CVSS3: 7.5
9%
Низкий
около 4 лет назад
github логотип
GHSA-xw5f-2w3q-6c92

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.

CVSS3: 8.3
3%
Низкий
около 4 лет назад
github логотип
GHSA-xw5c-xwc7-95gf

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

CVSS3: 5.3
4%
Низкий
больше 3 лет назад
github логотип
GHSA-xw5c-jc7x-gf75

PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xw59-hvm2-8pj6

DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

CVSS3: 8.1
0%
Низкий
4 месяца назад
github логотип
GHSA-xw59-4mp5-9chf

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564.

CVSS3: 7
3%
Низкий
около 4 лет назад
github логотип
GHSA-xw58-crph-crhm

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

CVSS3: 9.8
40%
Средний
больше 2 лет назад
github логотип
GHSA-xw58-64fr-3323

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to overwrite arbitrary files.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xw57-xggj-g8vq

SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw57-qhqx-v67p

A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xw57-23p8-9wc5

@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)

около 1 месяца назад
github логотип
GHSA-xw55-hvqx-m963

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад

Уязвимостей на страницу