Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-xrh3-5ph8-43qv

около 4 лет назад

The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted disk image.

EPSS: Низкий
github логотип

GHSA-xrh2-ccmq-qj77

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the qTranslate plugin 2.5.34 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xrh2-c3rm-35jr

около 4 лет назад

HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrh2-77qw-v55j

больше 2 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrgx-x8mj-82rp

около 4 лет назад

drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arbitrary code via a crafted application compromising a privileged process.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xrgw-2g7f-5735

больше 4 лет назад

Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.

EPSS: Средний
github логотип

GHSA-xrgv-hpqj-2pcx

около 4 лет назад

Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xrgv-hghj-6jpj

больше 3 лет назад

Memory corruption in HAB Memory management due to broad system privileges via physical address.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xrgv-34cc-q765

5 месяцев назад

Duplicate Advisory: OpenClaw's system.run allowlist bypass via shell line-continuation command substitution

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xrgv-2w7g-m84q

больше 4 лет назад

IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.

EPSS: Низкий
github логотип

GHSA-xrgr-fwmm-m4vx

больше 4 лет назад

Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 10.1.2.0.1, 10.1.2.0.2, and 10.1.2.1.0 has unknown impact and remote attack vectors related to the PHP Module, aka Vuln# OHS03.

EPSS: Низкий
github логотип

GHSA-xrgq-7wvh-c25q

около 3 лет назад

A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233477 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Средний
github логотип

GHSA-xrgp-qvwm-9p29

около 4 лет назад

There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrgp-m4m8-gq98

около 4 лет назад

Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter.

EPSS: Низкий
github логотип

GHSA-xrgp-j4fj-fqwr

больше 2 лет назад

A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-xrgp-8cmq-343v

почти 3 года назад

Memory corruption in RIL while trying to send apdu packet.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xrgm-w999-2hpq

2 месяца назад

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrgj-4jq4-397w

около 4 лет назад

Vulnerability in the Oracle XML Gateway component of Oracle E-Business Suite (subcomponent: Oracle Transport Agent). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle XML Gateway, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data as well as unauthorized update, insert or delete access to some of Oracle XML Gateway accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xrgh-xg67-h68q

почти 4 года назад

A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrgh-5p34-46f6

около 1 года назад

The Affiliate Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘numColumns’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrh3-5ph8-43qv

The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted disk image.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xrh2-ccmq-qj77

Cross-site request forgery (CSRF) vulnerability in the qTranslate plugin 2.5.34 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xrh2-c3rm-35jr

HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrh2-77qw-v55j

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrgx-x8mj-82rp

drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arbitrary code via a crafted application compromising a privileged process.

CVSS3: 7
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrgw-2g7f-5735

Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.

50%
Средний
больше 4 лет назад
github логотип
GHSA-xrgv-hpqj-2pcx

Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xrgv-hghj-6jpj

Memory corruption in HAB Memory management due to broad system privileges via physical address.

CVSS3: 8.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrgv-34cc-q765

Duplicate Advisory: OpenClaw's system.run allowlist bypass via shell line-continuation command substitution

CVSS3: 5.9
5 месяцев назад
github логотип
GHSA-xrgv-2w7g-m84q

IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xrgr-fwmm-m4vx

Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 10.1.2.0.1, 10.1.2.0.2, and 10.1.2.1.0 has unknown impact and remote attack vectors related to the PHP Module, aka Vuln# OHS03.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xrgq-7wvh-c25q

A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233477 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
12%
Средний
около 3 лет назад
github логотип
GHSA-xrgp-qvwm-9p29

There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrgp-m4m8-gq98

Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xrgp-j4fj-fqwr

A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

CVSS3: 5.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrgp-8cmq-343v

Memory corruption in RIL while trying to send apdu packet.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-xrgm-w999-2hpq

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.

CVSS3: 7.8
1%
Низкий
2 месяца назад
github логотип
GHSA-xrgj-4jq4-397w

Vulnerability in the Oracle XML Gateway component of Oracle E-Business Suite (subcomponent: Oracle Transport Agent). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle XML Gateway, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data as well as unauthorized update, insert or delete access to some of Oracle XML Gateway accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
2%
Низкий
около 4 лет назад
github логотип
GHSA-xrgh-xg67-h68q

A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xrgh-5p34-46f6

The Affiliate Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘numColumns’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу