Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-434j-26h4-7637

3 месяца назад

Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often through local or near-local access such as connecting to the USB or Ethernet ports beneath the table - the built-in credentials permit administrative login and full control of the system. Once authenticated, an attacker can access firmware utilities, modify controller software, and establish persistent compromise. Remote attack paths via network, cellular, or telemetry links may exist in specific configurations but generally require additional capabilities or operator error. The vendor reports that USB access has been disabled in current firmware builds.

EPSS: Низкий
github логотип

GHSA-434h-wc6g-q7f3

6 месяцев назад

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerability via the setddns_pip_system() function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-434h-p4gx-jm89

больше 4 лет назад

Observable Response Discrepancy in Flask-AppBuilder

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-434g-2637-qmqr

больше 1 года назад

Elliptic's verify function omits uniqueness validation

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-434f-v35r-xr4j

около 1 года назад

The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-434f-9q9x-rchx

почти 4 года назад

The IM Server (aka IMserve or IMserver) 2.0.5.30 and probably earlier in Ipswitch Instant Messaging before 2.07 in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (daemon crash) via certain data to TCP port 5179 that overwrites a destructor, as reachable by the (1) DoAttachVideoSender, (2) DoAttachVideoReceiver, (3) DoAttachAudioSender, and (4) DoAttachAudioReceiver functions.

EPSS: Низкий
github логотип

GHSA-434c-w883-rf5w

почти 3 года назад

IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 230264.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-434c-j4qc-vvcw

почти 4 года назад

Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-434c-grmw-6675

больше 3 лет назад

The REST interface in Cisco Unified Communications Manager IM and Presence Service 11.5(1) allows remote attackers to cause a denial of service (SIP proxy service restart) via a crafted HTTP request, aka Bug ID CSCuw31632.

EPSS: Низкий
github логотип

GHSA-434c-3rv6-6g4q

почти 4 года назад

Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.

EPSS: Низкий
github логотип

GHSA-4349-2x5x-f444

почти 4 года назад

SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.

EPSS: Низкий
github логотип

GHSA-4348-x292-h437

около 3 лет назад

Duplicate Advisory: GoBase Race Condition vulnerability

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4348-ggrm-4839

8 месяцев назад

In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4348-cfw6-3v28

почти 4 года назад

A vulnerability has been identified in COMOS (All versions < V10.4.1). The COMOS Web component of COMOS uses a flawed implementation of CSRF prevention. An attacker could exploit this vulnerability to perform Cross-Site-Request-Forgery attacks.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4348-9wcm-575r

больше 3 лет назад

Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Interface). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4348-9j97-6mhj

больше 3 лет назад

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text is the correct size for its buffer.

EPSS: Низкий
github логотип

GHSA-4348-8467-8wg9

больше 3 лет назад

Huawei Email APP Vicky-AL00 smartphones with software of earlier than VKY-AL00C00B171 versions has a stored cross-site scripting vulnerability. A remote attacker could exploit this vulnerability to send email that storing malicious code to a smartphone and waiting for a user to access this email that triggers execution of the code. An exploit could allow the attacker to execute arbitrary script code on the affected device.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4348-7php-hxmg

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in function.php in Zenphoto 1.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the "request logging" feature. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-4348-46gx-472v

почти 3 года назад

A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. VDB-220950 is the identifier assigned to this vulnerability.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4346-2577-gf85

больше 3 лет назад

The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-434j-26h4-7637

Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often through local or near-local access such as connecting to the USB or Ethernet ports beneath the table - the built-in credentials permit administrative login and full control of the system. Once authenticated, an attacker can access firmware utilities, modify controller software, and establish persistent compromise. Remote attack paths via network, cellular, or telemetry links may exist in specific configurations but generally require additional capabilities or operator error. The vendor reports that USB access has been disabled in current firmware builds.

0%
Низкий
3 месяца назад
github логотип
GHSA-434h-wc6g-q7f3

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerability via the setddns_pip_system() function.

CVSS3: 6.5
1%
Низкий
6 месяцев назад
github логотип
GHSA-434h-p4gx-jm89

Observable Response Discrepancy in Flask-AppBuilder

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-434g-2637-qmqr

Elliptic's verify function omits uniqueness validation

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-434f-v35r-xr4j

The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-434f-9q9x-rchx

The IM Server (aka IMserve or IMserver) 2.0.5.30 and probably earlier in Ipswitch Instant Messaging before 2.07 in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (daemon crash) via certain data to TCP port 5179 that overwrites a destructor, as reachable by the (1) DoAttachVideoSender, (2) DoAttachVideoReceiver, (3) DoAttachAudioSender, and (4) DoAttachAudioReceiver functions.

0%
Низкий
почти 4 года назад
github логотип
GHSA-434c-w883-rf5w

IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 230264.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-434c-j4qc-vvcw

Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.

CVSS3: 9.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-434c-grmw-6675

The REST interface in Cisco Unified Communications Manager IM and Presence Service 11.5(1) allows remote attackers to cause a denial of service (SIP proxy service restart) via a crafted HTTP request, aka Bug ID CSCuw31632.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-434c-3rv6-6g4q

Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4349-2x5x-f444

SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4348-x292-h437

Duplicate Advisory: GoBase Race Condition vulnerability

CVSS3: 3.7
около 3 лет назад
github логотип
GHSA-4348-ggrm-4839

In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-4348-cfw6-3v28

A vulnerability has been identified in COMOS (All versions < V10.4.1). The COMOS Web component of COMOS uses a flawed implementation of CSRF prevention. An attacker could exploit this vulnerability to perform Cross-Site-Request-Forgery attacks.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-4348-9wcm-575r

Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Interface). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4348-9j97-6mhj

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text is the correct size for its buffer.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4348-8467-8wg9

Huawei Email APP Vicky-AL00 smartphones with software of earlier than VKY-AL00C00B171 versions has a stored cross-site scripting vulnerability. A remote attacker could exploit this vulnerability to send email that storing malicious code to a smartphone and waiting for a user to access this email that triggers execution of the code. An exploit could allow the attacker to execute arbitrary script code on the affected device.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4348-7php-hxmg

Cross-site scripting (XSS) vulnerability in function.php in Zenphoto 1.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the "request logging" feature. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4348-46gx-472v

A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. VDB-220950 is the identifier assigned to this vulnerability.

CVSS3: 8.8
33%
Средний
почти 3 года назад
github логотип
GHSA-4346-2577-gf85

The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
5%
Низкий
больше 3 лет назад

Уязвимостей на страницу