Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-xrrx-xr48-h4jv

около 2 лет назад

A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268724.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xrrx-hrm6-mxr7

около 4 лет назад

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

EPSS: Средний
github логотип

GHSA-xrrw-wm7v-5p7r

больше 4 лет назад

Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 stores an exception for a hostname when the user accepts an untrusted Exchange server certificate, which causes it to be accepted without prompting in future usage and allows remote Exchange servers to obtain sensitive information such as credentials.

EPSS: Низкий
github логотип

GHSA-xrrw-gmgc-3q22

больше 4 лет назад

dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.

EPSS: Средний
github логотип

GHSA-xrrw-9j78-hpf3

больше 2 лет назад

Jenkins HTML Publisher Plugin Stored XSS vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xrrw-7rr2-829v

больше 2 лет назад

A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xrrv-gjcc-h93v

больше 3 лет назад

Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrrv-33fc-mq2w

около 3 лет назад

Windows Remote Desktop Security Feature Bypass Vulnerability

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xrrr-c6cx-2756

около 1 года назад

A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System up to 8.1 SP2. This affects the function this.oursNetService.getData of the file com\ours\www\ehr\openPlatform1\open4ClientType\controller\ThirdMenuController.class. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xrrq-xrcm-893x

больше 3 лет назад

F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrrq-rrgq-h89w

около 1 года назад

static-alloc vulnerability leads to uninitialized read after allocating MemBump

EPSS: Низкий
github логотип

GHSA-xrrq-qjmc-74g7

около 4 лет назад

Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrrq-jcjx-6cxm

почти 4 года назад

An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrrq-7xx6-v99c

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Active Websight SEO Backlink Monitor allows Reflected XSS.This issue affects SEO Backlink Monitor: from n/a through 1.5.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrrp-v29c-5f2g

6 месяцев назад

Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with LocalSystem permissions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrrp-45rp-88qp

почти 3 года назад

i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrrm-rgr6-3gfq

около 3 лет назад

An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrrm-r8x3-wh4p

больше 1 года назад

In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrrm-6636-87r2

2 дня назад

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrrj-gf93-vr4j

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrrx-xr48-h4jv

A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268724.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-xrrx-hrm6-mxr7

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

59%
Средний
около 4 лет назад
github логотип
GHSA-xrrw-wm7v-5p7r

Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 stores an exception for a hostname when the user accepts an untrusted Exchange server certificate, which causes it to be accepted without prompting in future usage and allows remote Exchange servers to obtain sensitive information such as credentials.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xrrw-gmgc-3q22

dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.

11%
Средний
больше 4 лет назад
github логотип
GHSA-xrrw-9j78-hpf3

Jenkins HTML Publisher Plugin Stored XSS vulnerability

CVSS3: 8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xrrw-7rr2-829v

A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xrrv-gjcc-h93v

Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrrv-33fc-mq2w

Windows Remote Desktop Security Feature Bypass Vulnerability

CVSS3: 6.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xrrr-c6cx-2756

A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System up to 8.1 SP2. This affects the function this.oursNetService.getData of the file com\ours\www\ehr\openPlatform1\open4ClientType\controller\ThirdMenuController.class. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xrrq-xrcm-893x

F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrrq-rrgq-h89w

static-alloc vulnerability leads to uninitialized read after allocating MemBump

около 1 года назад
github логотип
GHSA-xrrq-qjmc-74g7

Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrrq-jcjx-6cxm

An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrrq-7xx6-v99c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Active Websight SEO Backlink Monitor allows Reflected XSS.This issue affects SEO Backlink Monitor: from n/a through 1.5.0.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrrp-v29c-5f2g

Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with LocalSystem permissions.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xrrp-45rp-88qp

i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xrrm-rgr6-3gfq

An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-xrrm-r8x3-wh4p

In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xrrm-6636-87r2

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.

CVSS3: 7.5
0%
Низкий
2 дня назад
github логотип
GHSA-xrrj-gf93-vr4j

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

1%
Низкий
около 4 лет назад

Уязвимостей на страницу