Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-xvxg-wp8f-g8h4

около 4 лет назад

HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5) have an out-of-bounds read and write vulnerability. An attacker with specific permissions crafts malformed packet with specific parameter and sends the packet to the affected products. Due to insufficient validation of packet, which may be exploited to cause the information leakage or arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xvxg-vgch-8ccv

больше 4 лет назад

Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories.

EPSS: Низкий
github логотип

GHSA-xvxf-m2rv-ff79

больше 2 лет назад

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xvxf-7p3q-7mmg

около 4 лет назад

** UNSUPPORTED WHEN ASSIGNED ** An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvxc-929r-6mvq

около 4 лет назад

NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xvx9-w67v-7f8g

больше 4 лет назад

Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal Reports Server XI, and BusinessObjects Enterprise XI, allows remote attackers to cause a denial of service (application hang) via certain network traffic, possibly involving multiple simultaneous TCP connections.

EPSS: Низкий
github логотип

GHSA-xvx8-mgqv-q2fj

около 4 лет назад

An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to inject packets that could potentially disrupt the availability of the device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvx8-77m6-gwg6

5 месяцев назад

OpenClaw: Sandbox `writeFile` commit could race outside the validated path

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xvx7-w8qq-jr55

12 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xvx7-cgrp-p764

около 4 лет назад

Insufficient access control in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.

EPSS: Низкий
github логотип

GHSA-xvx7-78wp-jmp4

больше 4 лет назад

The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR.

EPSS: Низкий
github логотип

GHSA-xvx6-rgcr-cjh6

почти 2 года назад

The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xvx6-9cq2-q2x7

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phplist before 2.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvx6-286h-35qm

около 1 года назад

Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xvx5-4wp8-4f6g

около 4 лет назад

WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4768.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvx4-v362-295f

больше 1 года назад

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvx4-fr25-r858

около 4 лет назад

QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xvx3-whgp-7rq7

около 4 лет назад

The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvx3-jwjj-m2g9

25 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-xvx3-23h3-m25g

около 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect availability via vectors related to XML Publisher.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvxg-wp8f-g8h4

HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5) have an out-of-bounds read and write vulnerability. An attacker with specific permissions crafts malformed packet with specific parameter and sends the packet to the affected products. Due to insufficient validation of packet, which may be exploited to cause the information leakage or arbitrary code execution.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xvxg-vgch-8ccv

Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvxf-m2rv-ff79

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xvxf-7p3q-7mmg

** UNSUPPORTED WHEN ASSIGNED ** An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-xvxc-929r-6mvq

NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvx9-w67v-7f8g

Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal Reports Server XI, and BusinessObjects Enterprise XI, allows remote attackers to cause a denial of service (application hang) via certain network traffic, possibly involving multiple simultaneous TCP connections.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvx8-mgqv-q2fj

An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to inject packets that could potentially disrupt the availability of the device.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xvx8-77m6-gwg6

OpenClaw: Sandbox `writeFile` commit could race outside the validated path

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xvx7-w8qq-jr55

Rejected reason: Not used

12 месяцев назад
github логотип
GHSA-xvx7-cgrp-p764

Insufficient access control in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvx7-78wp-jmp4

The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvx6-rgcr-cjh6

The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvx6-9cq2-q2x7

Multiple cross-site scripting (XSS) vulnerabilities in phplist before 2.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvx6-286h-35qm

Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.

CVSS3: 5.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xvx5-4wp8-4f6g

WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4768.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xvx4-v362-295f

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvx4-fr25-r858

QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-xvx3-whgp-7rq7

The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvx3-jwjj-m2g9

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

25 дней назад
github логотип
GHSA-xvx3-23h3-m25g

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect availability via vectors related to XML Publisher.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу