Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-xv6f-5jw7-pmw8

больше 4 лет назад

In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.

EPSS: Низкий
github логотип

GHSA-xv6f-4q9w-8q96

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: parisc: BTLB: Fix crash when setting up BTLB at CPU bringup When using hotplug and bringing up a 32-bit CPU, ask the firmware about the BTLB information to set up the static (block) TLB entries. For that write access to the static btlb_info struct is needed, but since it is marked __ro_after_init the kernel segfaults with missing write permissions. Fix the crash by dropping the __ro_after_init annotation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv6c-f5jj-3wwc

больше 4 лет назад

An issued existed in the naming of screenshots. The issue was corrected with improved naming. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Screenshots of the Messages app may reveal additional message content.

EPSS: Низкий
github логотип

GHSA-xv69-hhpr-w3r5

больше 4 лет назад

Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_files and (3) extensions/login/frontend/pages/antihacker.php, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-xv69-f7x5-r4qw

почти 7 лет назад

Magento Cross-Site Scripting via Attribute Set Name

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv69-6rf3-w5g2

больше 4 лет назад

Missing permission check in Jenkins Cloud Statistics Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv68-vxp8-qj76

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv68-rrmw-9xwf

около 2 лет назад

Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xv67-vhc4-3v47

9 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through <= 3.2.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv66-85xp-gvq8

12 месяцев назад

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Editor-level access and above, to update the plugin's settings.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xv65-m527-x787

больше 2 лет назад

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xv64-wpfr-x2m3

больше 4 лет назад

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xv64-q73j-cvqp

почти 2 года назад

Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22272.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv64-jjpm-mgjv

больше 4 лет назад

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

EPSS: Низкий
github логотип

GHSA-xv64-cc6j-5cjp

больше 4 лет назад

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.

EPSS: Низкий
github логотип

GHSA-xv64-8p4r-94gq

больше 2 лет назад

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xv63-cpgc-6g6c

больше 4 лет назад

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1306, CVE-2020-1334.

EPSS: Низкий
github логотип

GHSA-xv63-838w-fgf7

больше 4 лет назад

ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv63-73qr-p568

больше 4 лет назад

In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.

EPSS: Низкий
github логотип

GHSA-xv62-77m9-3736

4 месяца назад

A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv6f-5jw7-pmw8

In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to workitems that do not belong to them.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv6f-4q9w-8q96

In the Linux kernel, the following vulnerability has been resolved: parisc: BTLB: Fix crash when setting up BTLB at CPU bringup When using hotplug and bringing up a 32-bit CPU, ask the firmware about the BTLB information to set up the static (block) TLB entries. For that write access to the static btlb_info struct is needed, but since it is marked __ro_after_init the kernel segfaults with missing write permissions. Fix the crash by dropping the __ro_after_init annotation.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv6c-f5jj-3wwc

An issued existed in the naming of screenshots. The issue was corrected with improved naming. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Screenshots of the Messages app may reveal additional message content.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv69-hhpr-w3r5

Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_files and (3) extensions/login/frontend/pages/antihacker.php, which reveals the installation path in an error message.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv69-f7x5-r4qw

Magento Cross-Site Scripting via Attribute Set Name

CVSS3: 5.4
1%
Низкий
почти 7 лет назад
github логотип
GHSA-xv69-6rf3-w5g2

Missing permission check in Jenkins Cloud Statistics Plugin

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv68-vxp8-qj76

Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xv68-rrmw-9xwf

Mautic vulnerable to Cross-site Scripting (XSS) - stored (edit form HTML field)

CVSS3: 4.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xv67-vhc4-3v47

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through <= 3.2.2.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xv66-85xp-gvq8

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Editor-level access and above, to update the plugin's settings.

CVSS3: 2.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-xv65-m527-x787

Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.

CVSS3: 8.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xv64-wpfr-x2m3

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv64-q73j-cvqp

Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22272.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv64-jjpm-mgjv

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv64-cc6j-5cjp

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv64-8p4r-94gq

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv63-cpgc-6g6c

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1306, CVE-2020-1334.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xv63-838w-fgf7

ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv63-73qr-p568

In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv62-77m9-3736

A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote.

CVSS3: 9.8
7%
Низкий
4 месяца назад

Уязвимостей на страницу