Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-xvqm-2ccw-fmg4

почти 3 года назад

DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xvqj-p4jj-r7xh

3 месяца назад

A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_content/delete_file of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component Compatible File Service. The manipulation results in missing authentication. The attacker must have access to the local network to execute the attack. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xvqj-4fq7-2gfv

4 месяца назад

Missing Authorization vulnerability in shrikantkale iZooto izooto-web-push allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iZooto: from n/a through <= 3.7.20.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xvqh-pg75-hr4f

15 дней назад

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xvqh-5m2j-7624

больше 3 лет назад

OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvqg-qvqg-pxf2

около 4 лет назад

IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly validate resource-queue metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

EPSS: Низкий
github логотип

GHSA-xvqg-mv25-rwvw

почти 4 года назад

Parsing issue in matrix-org/node-irc leading to room takeovers

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvqc-pp94-fmpx

4 месяца назад

Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xvqc-4q7g-qm76

около 4 лет назад

Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.

EPSS: Низкий
github логотип

GHSA-xvq9-c88q-jf5x

около 3 лет назад

Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvq9-4vpv-227m

больше 2 лет назад

Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvq8-m3ch-hcjv

22 дня назад

Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvq8-m37c-gmmv

7 месяцев назад

A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited. Edimax confirms this issue: "The product mentioned, EDIMAX BR-6208AC V2, has reached its End of Life (EOL) status. It is no longer supported or maintained by Edimax, and it is no longer available for purchase in the market. Consequently, there will be no further firmware updates or patches for this device. We recommend users upgrade to newer models for better security." This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xvq8-f2vm-qf3p

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xvq8-82jr-qr82

около 4 лет назад

The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvq8-2qwv-cr72

больше 4 лет назад

CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

EPSS: Низкий
github логотип

GHSA-xvq7-6cjq-gwh7

около 4 лет назад

There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751

EPSS: Низкий
github логотип

GHSA-xvq6-mh4q-2wm8

больше 4 лет назад

Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.

EPSS: Низкий
github логотип

GHSA-xvq6-h898-wcj8

больше 2 лет назад

Mattermost denial of service vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvq5-pp86-qj79

около 4 лет назад

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvqm-2ccw-fmg4

DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-xvqj-p4jj-r7xh

A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_content/delete_file of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component Compatible File Service. The manipulation results in missing authentication. The attacker must have access to the local network to execute the attack. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xvqj-4fq7-2gfv

Missing Authorization vulnerability in shrikantkale iZooto izooto-web-push allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iZooto: from n/a through <= 3.7.20.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xvqh-pg75-hr4f

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
0%
Низкий
15 дней назад
github логотип
GHSA-xvqh-5m2j-7624

OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xvqg-qvqg-pxf2

IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not properly validate resource-queue metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xvqg-mv25-rwvw

Parsing issue in matrix-org/node-irc leading to room takeovers

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xvqc-pp94-fmpx

Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-xvqc-4q7g-qm76

Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvq9-c88q-jf5x

Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages.

CVSS3: 7.5
4%
Низкий
около 3 лет назад
github логотип
GHSA-xvq9-4vpv-227m

Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xvq8-m3ch-hcjv

Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
22 дня назад
github логотип
GHSA-xvq8-m37c-gmmv

A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited. Edimax confirms this issue: "The product mentioned, EDIMAX BR-6208AC V2, has reached its End of Life (EOL) status. It is no longer supported or maintained by Edimax, and it is no longer available for purchase in the market. Consequently, there will be no further firmware updates or patches for this device. We recommend users upgrade to newer models for better security." This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
5%
Низкий
7 месяцев назад
github логотип
GHSA-xvq8-f2vm-qf3p

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-xvq8-82jr-qr82

The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvq8-2qwv-cr72

CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xvq7-6cjq-gwh7

There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751

0%
Низкий
около 4 лет назад
github логотип
GHSA-xvq6-mh4q-2wm8

Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvq6-h898-wcj8

Mattermost denial of service vulnerability

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xvq5-pp86-qj79

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.

CVSS3: 6.8
1%
Низкий
около 4 лет назад

Уязвимостей на страницу