Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 805

Количество 323 805

github логотип

GHSA-xvq8-m37c-gmmv

3 месяца назад

A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited. Edimax confirms this issue: "The product mentioned, EDIMAX BR-6208AC V2, has reached its End of Life (EOL) status. It is no longer supported or maintained by Edimax, and it is no longer available for purchase in the market. Consequently, there will be no further firmware updates or patches for this device. We recommend users upgrade to newer models for better security." This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xvq8-f2vm-qf3p

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xvq8-82jr-qr82

почти 4 года назад

The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvq8-2qwv-cr72

почти 4 года назад

CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

EPSS: Низкий
github логотип

GHSA-xvq7-6cjq-gwh7

почти 4 года назад

There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751

EPSS: Низкий
github логотип

GHSA-xvq6-mh4q-2wm8

почти 4 года назад

Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.

EPSS: Низкий
github логотип

GHSA-xvq6-h898-wcj8

больше 2 лет назад

Mattermost denial of service vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvq5-pp86-qj79

почти 4 года назад

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xvq4-9j7v-qqhv

3 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-xvq3-j3j3-hfjp

почти 4 года назад

SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

EPSS: Низкий
github логотип

GHSA-xvpx-6hh8-7h72

почти 4 года назад

Magento XML Injection vulnerability in the 'City' field

EPSS: Средний
github логотип

GHSA-xvpw-pp3c-gx2x

3 месяца назад

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SAS Core Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27677.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvpw-j9f9-fw7v

почти 4 года назад

Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.

EPSS: Низкий
github логотип

GHSA-xvpr-22g7-3fc2

почти 4 года назад

The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.

EPSS: Низкий
github логотип

GHSA-xvpq-v2cq-9v92

почти 4 года назад

Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.

EPSS: Низкий
github логотип

GHSA-xvpp-m96v-c2pr

почти 4 года назад

D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.

EPSS: Средний
github логотип

GHSA-xvpp-hhff-gp7v

около 3 лет назад

In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xvpp-959v-c63p

почти 4 года назад

Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.

EPSS: Средний
github логотип

GHSA-xvpp-5hc3-fp4m

больше 2 лет назад

Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvpm-v9x9-vg99

почти 4 года назад

Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvq8-m37c-gmmv

A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited. Edimax confirms this issue: "The product mentioned, EDIMAX BR-6208AC V2, has reached its End of Life (EOL) status. It is no longer supported or maintained by Edimax, and it is no longer available for purchase in the market. Consequently, there will be no further firmware updates or patches for this device. We recommend users upgrade to newer models for better security." This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xvq8-f2vm-qf3p

Rejected reason: Not used

8 месяцев назад
github логотип
GHSA-xvq8-82jr-qr82

The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvq8-2qwv-cr72

CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

4%
Низкий
почти 4 года назад
github логотип
GHSA-xvq7-6cjq-gwh7

There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvq6-mh4q-2wm8

Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvq6-h898-wcj8

Mattermost denial of service vulnerability

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvq5-pp86-qj79

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.

CVSS3: 6.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvq4-9j7v-qqhv

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

3 месяца назад
github логотип
GHSA-xvq3-j3j3-hfjp

SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvpx-6hh8-7h72

Magento XML Injection vulnerability in the 'City' field

31%
Средний
почти 4 года назад
github логотип
GHSA-xvpw-pp3c-gx2x

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SAS Core Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27677.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xvpw-j9f9-fw7v

Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvpr-22g7-3fc2

The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvpq-v2cq-9v92

Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvpp-m96v-c2pr

D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.

22%
Средний
почти 4 года назад
github логотип
GHSA-xvpp-hhff-gp7v

In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.

CVSS3: 9.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-xvpp-959v-c63p

Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.

18%
Средний
почти 4 года назад
github логотип
GHSA-xvpp-5hc3-fp4m

Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvpm-v9x9-vg99

Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу