Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-xrr5-fhq2-5w4h

около 2 месяцев назад

The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L (8.6 High). When combined with CVE-2026-50082, CVE-50083, and CVE-50084, this can lead to a fully unauthenticated, remote takeover of affected devices.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xrr5-3hrr-35jx

больше 3 лет назад

CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via a template side-channel attack because of intermediate data leakage of one vector.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrr4-p6fq-hjg7

почти 9 лет назад

Directory traversal vulnerability in Action View in Ruby on Rails

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-xrr4-m4hg-53xg

5 месяцев назад

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xrr4-j32g-hj8m

больше 2 лет назад

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrr4-74mc-rpjc

почти 8 лет назад

Pyro mishandles pid files in temporary directory locations and opening the pid file as root

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrr3-cmxq-9jq6

больше 4 лет назад

SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.

EPSS: Низкий
github логотип

GHSA-xrr2-rvc6-5mhw

9 месяцев назад

Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xrr2-rr4f-w9p3

около 3 лет назад

The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrqx-mp2q-94fc

около 4 лет назад

/opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration.

EPSS: Низкий
github логотип

GHSA-xrqx-j38x-m6pj

около 4 лет назад

A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects, aka 'Windows Media Audio Decoder Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1508.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xrqw-7396-fjm2

почти 4 года назад

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to exposure of this sensitive data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrqw-4q5c-x35c

около 4 лет назад

Integer overflow in the in_nsv plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to improper allocation of memory for NSV metadata, a different vulnerability than CVE-2010-2586.

EPSS: Низкий
github логотип

GHSA-xrqw-3rrv-vx5w

5 дней назад

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrqv-3gq7-88qw

около 4 лет назад

Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.

EPSS: Низкий
github логотип

GHSA-xrqq-wqh4-5hg2

больше 3 лет назад

svg-sanitizer has Cross-site Scripting Bypass

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xrqq-rjw2-jp5x

больше 4 лет назад

SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter, a different vector than CVE-2008-4465.

EPSS: Низкий
github логотип

GHSA-xrqq-qf24-xjgx

около 2 лет назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xrqq-m9vv-pq36

6 месяцев назад

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrqq-74w4-x876

9 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver log=(file) construct allows the user to specify an arbitrary file for the JDBC driver to write its log information to.  If an application allows an end user to specify a value for the SpyAttributes connection option then an attacker could cause java script to be written to a log file.  If the log file was in the correct location with the correct extension, an application server could see that log file as a resource to be served.  The attacker could fetch the resource from the server causing the java script to be executed. This issue affects: DataDirect Connect for JDBC for Amazon R...

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrr5-fhq2-5w4h

The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L (8.6 High). When combined with CVE-2026-50082, CVE-50083, and CVE-50084, this can lead to a fully unauthenticated, remote takeover of affected devices.

CVSS3: 8.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xrr5-3hrr-35jx

CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via a template side-channel attack because of intermediate data leakage of one vector.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrr4-p6fq-hjg7

Directory traversal vulnerability in Action View in Ruby on Rails

CVSS3: 7.5
96%
Критический
почти 9 лет назад
github логотип
GHSA-xrr4-m4hg-53xg

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

CVSS3: 4.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xrr4-j32g-hj8m

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrr4-74mc-rpjc

Pyro mishandles pid files in temporary directory locations and opening the pid file as root

CVSS3: 7.5
2%
Низкий
почти 8 лет назад
github логотип
GHSA-xrr3-cmxq-9jq6

SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xrr2-rvc6-5mhw

Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file

CVSS3: 9.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-xrr2-rr4f-w9p3

The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-xrqx-mp2q-94fc

/opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xrqx-j38x-m6pj

A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects, aka 'Windows Media Audio Decoder Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1508.

CVSS3: 7.6
3%
Низкий
около 4 лет назад
github логотип
GHSA-xrqw-7396-fjm2

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to exposure of this sensitive data.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xrqw-4q5c-x35c

Integer overflow in the in_nsv plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to improper allocation of memory for NSV metadata, a different vulnerability than CVE-2010-2586.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xrqw-3rrv-vx5w

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames without proper validation. An attacker can exploit this by publishing a malicious Hugging Face Hub repository with a crafted `tokenizer_config.json` file. When a victim downloads and saves the tokenizer or processor, the attacker-controlled keys can escape the intended save directory, enabling arbitrary file writes with attacker-controlled content. This vulnerability affects multiple processors inheriting from `ProcessorMixin`, including Idefics, Florence, Gemma, Phi, and Qwen-VL.

CVSS3: 7.1
0%
Низкий
5 дней назад
github логотип
GHSA-xrqv-3gq7-88qw

Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xrqq-wqh4-5hg2

svg-sanitizer has Cross-site Scripting Bypass

CVSS3: 5.3
больше 3 лет назад
github логотип
GHSA-xrqq-rjw2-jp5x

SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter, a different vector than CVE-2008-4465.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xrqq-qf24-xjgx

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.

CVSS3: 4.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xrqq-m9vv-pq36

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xrqq-74w4-x876

Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver log=(file) construct allows the user to specify an arbitrary file for the JDBC driver to write its log information to.  If an application allows an end user to specify a value for the SpyAttributes connection option then an attacker could cause java script to be written to a log file.  If the log file was in the correct location with the correct extension, an application server could see that log file as a resource to be served.  The attacker could fetch the resource from the server causing the java script to be executed. This issue affects: DataDirect Connect for JDBC for Amazon R...

0%
Низкий
9 месяцев назад

Уязвимостей на страницу