Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 914

Количество 377 914

github логотип

GHSA-52r4-jr79-62gj

3 месяца назад

Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-52r3-m642-mp2f

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-52r3-f6x8-h7v5

больше 4 лет назад

The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.

EPSS: Низкий
github логотип

GHSA-52r3-7vqc-4rq7

больше 4 лет назад

ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52r2-xf63-fp2q

больше 4 лет назад

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-52r2-7jx8-c8gc

больше 4 лет назад

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52qx-x9h4-rv8r

больше 2 лет назад

Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52qw-w4c5-82h4

3 месяца назад

Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-52qw-pvqg-c2g3

больше 4 лет назад

TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.

EPSS: Низкий
github логотип

GHSA-52qv-74wq-8rcv

больше 4 лет назад

AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52qv-5pm8-p78h

почти 5 лет назад

In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197328178

EPSS: Низкий
github логотип

GHSA-52qr-8f69-pcpq

2 месяца назад

A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-52qr-2974-mpj9

больше 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. rtmp=start param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52qr-28j9-p9j3

больше 4 лет назад

Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.

EPSS: Низкий
github логотип

GHSA-52qq-78xg-p62c

около 1 года назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Code Injection. This issue affects Alone: from n/a through n/a.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52qp-jpq7-6c54

больше 5 лет назад

Insecure Deserialization of untrusted data in rmccue/requests

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52qp-gwwh-qrg4

больше 5 лет назад

Missing Handler in @scandipwa/magento-scripts

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-52qp-94q2-h5wv

больше 4 лет назад

The Dog Whistle (aka com.dogwhistle.dogtrainingandroidapp) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-52qm-v8p3-wc8p

больше 4 лет назад

Heap-based buffer overflow in the nsBlockFrame::MarkLineDirty function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-52qm-pr2g-7h6x

4 месяца назад

The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52r4-jr79-62gj

Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-52r3-m642-mp2f

Cross-site scripting (XSS) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52r3-f6x8-h7v5

The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52r3-7vqc-4rq7

ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52r2-xf63-fp2q

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

16%
Средний
больше 4 лет назад
github логотип
GHSA-52r2-7jx8-c8gc

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-52qx-x9h4-rv8r

Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-52qw-w4c5-82h4

Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.

CVSS3: 8.2
0%
Низкий
3 месяца назад
github логотип
GHSA-52qw-pvqg-c2g3

TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-52qv-74wq-8rcv

AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-52qv-5pm8-p78h

In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197328178

0%
Низкий
почти 5 лет назад
github логотип
GHSA-52qr-8f69-pcpq

A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

CVSS3: 7
0%
Низкий
2 месяца назад
github логотип
GHSA-52qr-2974-mpj9

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. rtmp=start param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52qr-28j9-p9j3

Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-52qq-78xg-p62c

Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Code Injection. This issue affects Alone: from n/a through n/a.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-52qp-jpq7-6c54

Insecure Deserialization of untrusted data in rmccue/requests

CVSS3: 9.8
2%
Низкий
больше 5 лет назад
github логотип
GHSA-52qp-gwwh-qrg4

Missing Handler in @scandipwa/magento-scripts

CVSS3: 6.2
1%
Низкий
больше 5 лет назад
github логотип
GHSA-52qp-94q2-h5wv

The Dog Whistle (aka com.dogwhistle.dogtrainingandroidapp) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-52qm-v8p3-wc8p

Heap-based buffer overflow in the nsBlockFrame::MarkLineDirty function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via unspecified vectors.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-52qm-pr2g-7h6x

The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.

CVSS3: 5.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу