Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-xrx4-52w3-mpjx

около 4 лет назад

The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.

EPSS: Низкий
github логотип

GHSA-xrx3-f4cm-9v4f

больше 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. TestFtp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrx3-4r6h-5xp6

больше 4 лет назад

Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.

EPSS: Средний
github логотип

GHSA-xrx2-hcfr-w76f

около 4 лет назад

mediaserver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 29161895 and MediaTek internal bug ALPS02770870.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrwx-phm3-vhq4

около 4 лет назад

In avb_vbmeta_image_verify of avb_vbmeta_image.c there is a possible out of bounds read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-133164384

EPSS: Низкий
github логотип

GHSA-xrww-68c4-qq72

больше 3 лет назад

Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xrww-67cv-gqrx

больше 3 лет назад

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'firmwall srcmac (WORD|null) srcip (A.B.C.D|null) dstip (A.B.C.D|null) protocol (none|tcp|udp|icmp) srcport (<1-65535>|null) dstport (<1-65535>|null) policy (drop|accept) description (WORD|null)' command template.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrww-3rp8-cfmx

около 4 лет назад

A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper authentication. It is possible to initiate the attack remotely.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrwv-x9mf-8rh3

около 2 лет назад

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xrwv-jchf-q5j2

около 4 лет назад

Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a response.

EPSS: Низкий
github логотип

GHSA-xrwv-8jhj-x69w

больше 1 года назад

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrwv-6rch-f7vv

почти 4 года назад

Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrwr-pg2p-3r5m

около 4 лет назад

The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and SeaMonkey before 2.13.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xrwr-fgmg-h9xp

почти 2 года назад

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xrwr-fcw6-fmq8

4 месяца назад

Weblate: SSRF via Project-Level Machinery Configuration

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xrwr-3m4h-cqcx

больше 2 лет назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrwq-v96x-p8vf

8 месяцев назад

An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrwq-4gxw-wvh5

около 4 лет назад

Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrwp-4qvv-59wr

больше 4 лет назад

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrwm-6gg9-475c

около 4 лет назад

xmlfile.py in aptoncd 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/aptoncd temporary file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrx4-52w3-mpjx

The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xrx3-f4cm-9v4f

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. TestFtp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xrx3-4r6h-5xp6

Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.

22%
Средний
больше 4 лет назад
github логотип
GHSA-xrx2-hcfr-w76f

mediaserver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 29161895 and MediaTek internal bug ALPS02770870.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xrwx-phm3-vhq4

In avb_vbmeta_image_verify of avb_vbmeta_image.c there is a possible out of bounds read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-133164384

0%
Низкий
около 4 лет назад
github логотип
GHSA-xrww-68c4-qq72

Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrww-67cv-gqrx

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'firmwall srcmac (WORD|null) srcip (A.B.C.D|null) dstip (A.B.C.D|null) protocol (none|tcp|udp|icmp) srcport (<1-65535>|null) dstport (<1-65535>|null) policy (drop|accept) description (WORD|null)' command template.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrww-3rp8-cfmx

A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper authentication. It is possible to initiate the attack remotely.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrwv-x9mf-8rh3

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

CVSS3: 8.3
3%
Низкий
около 2 лет назад
github логотип
GHSA-xrwv-jchf-q5j2

Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a response.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xrwv-8jhj-x69w

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xrwv-6rch-f7vv

Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Exploitation of this issue requires low-privilege access to AEM.

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-xrwr-pg2p-3r5m

The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and SeaMonkey before 2.13.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xrwr-fgmg-h9xp

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

CVSS3: 7.3
2%
Низкий
почти 2 года назад
github логотип
GHSA-xrwr-fcw6-fmq8

Weblate: SSRF via Project-Level Machinery Configuration

CVSS3: 5
0%
Низкий
4 месяца назад
github логотип
GHSA-xrwr-3m4h-cqcx

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrwq-v96x-p8vf

An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xrwq-4gxw-wvh5

Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrwp-4qvv-59wr

A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xrwm-6gg9-475c

xmlfile.py in aptoncd 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/aptoncd temporary file.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу