Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-xvhc-jj62-7h84

12 месяцев назад

The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

EPSS: Низкий
github логотип

GHSA-xvhc-gm7j-mhmc

2 месяца назад

Shopware: Stored XSS via SVG file upload — no SVG sanitization

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xvh9-mfm3-cvfq

около 4 лет назад

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

EPSS: Низкий
github логотип

GHSA-xvh9-jpfj-m9hg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

EPSS: Низкий
github логотип

GHSA-xvh8-gxxm-2h9g

больше 4 лет назад

SQL injection vulnerability in Webmatic before 2.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvh8-g3fx-684w

больше 4 лет назад

D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

EPSS: Низкий
github логотип

GHSA-xvh8-f5vg-49g2

11 месяцев назад

A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvh8-9h96-57r8

7 месяцев назад

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to access the application by impersonating any user, including those with administrative permissions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xvh8-95gq-687q

около 4 лет назад

Huawei DP300, V500R002C00, RP200, V600R006C00, TE30, V100R001C10, V500R002C00,V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00,V600R006C00, TE60, V100R001C10, V500R002C00, V600R006C00, TX50,V500R002C00, V600R006C00 have a buffer overflow vulnerability. An attacker may send specially crafted HTTP messages to the affected products. Due insufficient input validation of three different parameters in the messages, successful exploit may cause some service abnormal.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xvh7-j354-hww5

около 4 лет назад

An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-xvh7-cvv2-7h78

около 4 лет назад

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvh6-vcqc-vqqv

15 дней назад

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvh6-6336-2243

10 месяцев назад

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvh5-h92w-xq3x

24 дня назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvh5-7qcw-cj6q

больше 4 лет назад

Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.

EPSS: Низкий
github логотип

GHSA-xvh5-6cc5-gv2q

около 4 лет назад

An exploitable out-of-bounds vulnerability exists in the xls_addCell function of libxls 1.4. A specially crafted XLS file with a formula record can cause memory corruption resulting in remote code execution. An attacker can send a malicious XLS file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvh5-5qg4-x9qp

4 месяца назад

n8n has In-Process Memory Disclosure in its Task Runner

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvh5-2mp5-pfc3

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in the timestamp extension If userspace provides an unknown or invalid handle anywhere in the handle array the rest of the driver will not handle that well. Fix it by checking handle was looked up successfully or otherwise fail the extension by jumping into the existing unwind. (cherry picked from commit 8d1276d1b8f738c3afe1457d4dff5cc66fc848a3)

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvh4-f7hf-8gj6

почти 3 года назад

A remote code execution vulnerability in the webview component of OPPO Store app.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xvh3-qgp6-m4r6

больше 2 лет назад

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. When a user logs in, a temporary file which contains the configuration of the device (as visible to that user) is created in the /cache folder. An unauthenticated attacker can then attempt to access such a file by sending a specific request to the device trying to guess the name of such a file. Successful exploitation will reveal configuration information. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: * All versions earlier than 20.4R3-S9; * 21.2 versions earlier than 21.2R3-S7; * 21.3 versions earlier than 21.3R3-S5; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvhc-jj62-7h84

The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

0%
Низкий
12 месяцев назад
github логотип
GHSA-xvhc-gm7j-mhmc

Shopware: Stored XSS via SVG file upload — no SVG sanitization

CVSS3: 4.9
0%
Низкий
2 месяца назад
github логотип
GHSA-xvh9-mfm3-cvfq

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

5%
Низкий
около 4 лет назад
github логотип
GHSA-xvh9-jpfj-m9hg

Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvh8-gxxm-2h9g

SQL injection vulnerability in Webmatic before 2.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvh8-g3fx-684w

D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvh8-f5vg-49g2

A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
3%
Низкий
11 месяцев назад
github логотип
GHSA-xvh8-9h96-57r8

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to access the application by impersonating any user, including those with administrative permissions.

CVSS3: 8.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-xvh8-95gq-687q

Huawei DP300, V500R002C00, RP200, V600R006C00, TE30, V100R001C10, V500R002C00,V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00,V600R006C00, TE60, V100R001C10, V500R002C00, V600R006C00, TX50,V500R002C00, V600R006C00 have a buffer overflow vulnerability. An attacker may send specially crafted HTTP messages to the affected products. Due insufficient input validation of three different parameters in the messages, successful exploit may cause some service abnormal.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvh7-j354-hww5

An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvh7-cvv2-7h78

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvh6-vcqc-vqqv

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file

CVSS3: 9.8
0%
Низкий
15 дней назад
github логотип
GHSA-xvh6-6336-2243

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

CVSS3: 6.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-xvh5-h92w-xq3x

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.

CVSS3: 7.1
0%
Низкий
24 дня назад
github логотип
GHSA-xvh5-7qcw-cj6q

Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvh5-6cc5-gv2q

An exploitable out-of-bounds vulnerability exists in the xls_addCell function of libxls 1.4. A specially crafted XLS file with a formula record can cause memory corruption resulting in remote code execution. An attacker can send a malicious XLS file to trigger this vulnerability.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xvh5-5qg4-x9qp

n8n has In-Process Memory Disclosure in its Task Runner

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xvh5-2mp5-pfc3

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in the timestamp extension If userspace provides an unknown or invalid handle anywhere in the handle array the rest of the driver will not handle that well. Fix it by checking handle was looked up successfully or otherwise fail the extension by jumping into the existing unwind. (cherry picked from commit 8d1276d1b8f738c3afe1457d4dff5cc66fc848a3)

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvh4-f7hf-8gj6

A remote code execution vulnerability in the webview component of OPPO Store app.

CVSS3: 7.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-xvh3-qgp6-m4r6

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to access sensitive system information. When a user logs in, a temporary file which contains the configuration of the device (as visible to that user) is created in the /cache folder. An unauthenticated attacker can then attempt to access such a file by sending a specific request to the device trying to guess the name of such a file. Successful exploitation will reveal configuration information. This issue affects Juniper Networks Junos OS on SRX Series and EX Series: * All versions earlier than 20.4R3-S9; * 21.2 versions earlier than 21.2R3-S7; * 21.3 versions earlier than 21.3R3-S5; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S...

CVSS3: 5.3
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу