Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-xw5m-5vch-x6g5

9 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw5j-gv2g-mjm2

больше 3 лет назад

Miscompilation in cortex-m-rt 0.7.1 and 0.7.2

EPSS: Низкий
github логотип

GHSA-xw5j-8gp6-p2vj

около 4 лет назад

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw5j-6ccc-rwh9

больше 4 лет назад

IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.

EPSS: Низкий
github логотип

GHSA-xw5j-5p2q-fr86

3 месяца назад

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw5j-4h78-77h2

больше 4 лет назад

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw5h-h3cf-m4mx

больше 4 лет назад

Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.

EPSS: Низкий
github логотип

GHSA-xw5h-cmh3-8j6j

3 месяца назад

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xw5h-8j92-59pp

почти 4 года назад

open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw5h-2294-wjv4

5 дней назад

In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xw5g-qgw7-x534

больше 4 лет назад

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xw5g-644p-8357

около 1 месяца назад

Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xw5g-39g7-vh7x

около 4 лет назад

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xw5f-m9q2-678f

больше 4 лет назад

Microsoft SharePoint Denial of Service Update

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xw5f-g937-wgm2

больше 4 лет назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw5f-2w3q-6c92

больше 4 лет назад

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xw5c-xwc7-95gf

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw5c-jc7x-gf75

5 месяцев назад

PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw59-hvm2-8pj6

6 месяцев назад

DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xw59-4mp5-9chf

больше 4 лет назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw5m-5vch-x6g5

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-xw5j-gv2g-mjm2

Miscompilation in cortex-m-rt 0.7.1 and 0.7.2

больше 3 лет назад
github логотип
GHSA-xw5j-8gp6-p2vj

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw5j-6ccc-rwh9

IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5j-5p2q-fr86

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xw5j-4h78-77h2

Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5h-h3cf-m4mx

Directory traversal vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to upload files into arbitrary directories via a .. (dot dot) in the id_document parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5h-cmh3-8j6j

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

CVSS3: 9.8
1%
Низкий
3 месяца назад
github логотип
GHSA-xw5h-8j92-59pp

open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xw5h-2294-wjv4

In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.8
0%
Низкий
5 дней назад
github логотип
GHSA-xw5g-qgw7-x534

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120255805

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5g-644p-8357

Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xw5g-39g7-vh7x

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw5f-m9q2-678f

Microsoft SharePoint Denial of Service Update

CVSS3: 5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5f-g937-wgm2

ChakraCore RCE Vulnerability

CVSS3: 7.5
9%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5f-2w3q-6c92

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241.

CVSS3: 8.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xw5c-xwc7-95gf

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

CVSS3: 5.3
4%
Низкий
больше 3 лет назад
github логотип
GHSA-xw5c-jc7x-gf75

PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xw59-hvm2-8pj6

DNS Rebinding Protection Disabled by Default in Model Context Protocol Go SDK for Servers Running on Localhost

CVSS3: 8.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-xw59-4mp5-9chf

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1557, CVE-2020-1558, CVE-2020-1564.

CVSS3: 7
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу