Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-xvg3-g835-ccc9

около 4 лет назад

An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads to remote code execution via shell metacharacters in a JSON value.

EPSS: Низкий
github логотип

GHSA-xvg3-935w-4mv9

2 месяца назад

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The show_complete_user_agent_tooltip setting must be explicitly enabled by an administrator (disabled by default) for the stored payload to be rendered and executed.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xvg3-58p8-whhm

больше 4 лет назад

The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the hashes function to return NULL.

EPSS: Низкий
github логотип

GHSA-xvg2-wrv6-8v46

больше 4 лет назад

SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.

EPSS: Низкий
github логотип

GHSA-xvg2-phf2-rwq7

больше 4 лет назад

PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.

EPSS: Низкий
github логотип

GHSA-xvg2-gfxv-qc4c

больше 4 лет назад

The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.

EPSS: Низкий
github логотип

GHSA-xvg2-cgv6-6h7v

7 дней назад

netfoil: Incorrect block responses could lead to localhost traffic

EPSS: Низкий
github логотип

GHSA-xvfx-x2hm-pgf5

около 1 года назад

Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvfw-xwr5-7xvc

около 4 лет назад

Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment). Supported versions that are affected are 18.0 and 19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).

EPSS: Низкий
github логотип

GHSA-xvfw-jjhx-vm37

около 4 лет назад

The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Setup AndX request with a certain 0x8003 field value.

EPSS: Низкий
github логотип

GHSA-xvfv-x947-hhgf

больше 4 лет назад

TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.

EPSS: Низкий
github логотип

GHSA-xvfv-hp97-ff3g

около 4 лет назад

Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvfr-r8m7-6v65

около 4 лет назад

In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvfr-h5h6-78m3

больше 2 лет назад

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvfq-f68m-7mwg

около 4 лет назад

In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xvfq-4q6q-gxx7

около 2 месяцев назад

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvfp-x78m-7x4j

около 4 лет назад

A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, aka 'Windows Defender Firewall Security Feature Bypass Vulnerability'.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvfp-4c8p-rwfv

около 4 лет назад

AdvancePro Advanceware allows remote authenticated users to obtain sensitive information about arbitrary customers' orders via a modified id parameter.

EPSS: Низкий
github логотип

GHSA-xvfm-vcfx-8599

4 месяца назад

The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xvfj-9qc8-3jgp

около 3 лет назад

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. An app may be able to gain root privileges

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvg3-g835-ccc9

An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads to remote code execution via shell metacharacters in a JSON value.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xvg3-935w-4mv9

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The show_complete_user_agent_tooltip setting must be explicitly enabled by an administrator (disabled by default) for the stored payload to be rendered and executed.

CVSS3: 7.2
0%
Низкий
2 месяца назад
github логотип
GHSA-xvg3-58p8-whhm

The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the hashes function to return NULL.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvg2-wrv6-8v46

SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvg2-phf2-rwq7

PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xvg2-gfxv-qc4c

The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvg2-cgv6-6h7v

netfoil: Incorrect block responses could lead to localhost traffic

7 дней назад
github логотип
GHSA-xvfx-x2hm-pgf5

Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.

CVSS3: 6.5
2%
Низкий
около 1 года назад
github логотип
GHSA-xvfw-xwr5-7xvc

Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment). Supported versions that are affected are 18.0 and 19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvfw-jjhx-vm37

The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Setup AndX request with a certain 0x8003 field value.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xvfv-x947-hhgf

TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvfv-hp97-ff3g

Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvfr-r8m7-6v65

In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.

CVSS3: 5.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xvfr-h5h6-78m3

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xvfq-f68m-7mwg

In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server.

CVSS3: 5.9
0%
Низкий
около 4 лет назад
github логотип
GHSA-xvfq-4q6q-gxx7

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xvfp-x78m-7x4j

A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, aka 'Windows Defender Firewall Security Feature Bypass Vulnerability'.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xvfp-4c8p-rwfv

AdvancePro Advanceware allows remote authenticated users to obtain sensitive information about arbitrary customers' orders via a modified id parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvfm-vcfx-8599

The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xvfj-9qc8-3jgp

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. An app may be able to gain root privileges

CVSS3: 7.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу