Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4w2h-78cc-554r

больше 4 лет назад

CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4w2g-rx2c-59rp

4 месяца назад

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected app termination.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w2g-r9pq-p6qg

больше 4 лет назад

MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.

EPSS: Низкий
github логотип

GHSA-4w2g-jrqm-g99q

около 1 месяца назад

exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4w2g-jgpv-wc89

больше 4 лет назад

IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4w2g-j23f-x62h

10 месяцев назад

Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4w2g-c9v6-pgv7

около 3 лет назад

Improper access control in Zoom Rooms before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4w2f-r3pq-3wfp

больше 4 лет назад

The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon crash and message data loss) via malformed headers during a WebSockets connection upgrade.

EPSS: Низкий
github логотип

GHSA-4w2f-m236-fggc

почти 2 года назад

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4w2c-mfgm-ff7r

больше 4 лет назад

By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.

EPSS: Низкий
github логотип

GHSA-4w29-23fj-v8v5

больше 4 лет назад

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R7500v2 before 1.0.3.20, R7800 before 1.0.2.38, WN3000RPv3 before 1.0.2.50, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.

EPSS: Низкий
github логотип

GHSA-4w28-6qpv-x7c2

больше 4 лет назад

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a potential heap overflow and memory corruption due to improper error handling in SOC infrastructure.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4w28-4cpv-vvf3

больше 4 лет назад

Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issue affects PAN-OS 9.0 versions prior to 9.0.5-h3 on PA-7080 and PA-7050 devices with an LFC installed and configured. This issue does not affect PA-7000 Series deployments using the first-generation SMC and the Log Processing Card (LPC). This issue does not affect any other PA series devices. This issue does not affect devices without an LFC. This issue does not affect PAN-OS 8.1 or prior releases. This issue only affects a very limited number of customers and we undertook individual outreach to help them upgrade. At the time of publication, all identified customers have upgraded SW or content and are not impacted.

EPSS: Низкий
github логотип

GHSA-4w27-xxvw-958c

больше 4 лет назад

foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4w27-cg72-mj62

больше 4 лет назад

A information disclosure vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: Android kernel. Android ID: A-71359108. References: B-V2018010501.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4w27-8685-x47p

4 месяца назад

Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4w26-p3x4-j4mv

больше 2 лет назад

An insecure logging vulnerability has been identified within ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to access sensitive information via inadequate security measures implemented within the logging mechanisms of ROS2.

EPSS: Низкий
github логотип

GHSA-4w26-8p97-f4jp

больше 1 года назад

AugAssign evaluation order causing OOB write within the object in Vyper

EPSS: Низкий
github логотип

GHSA-4w26-4rcj-vffr

больше 4 лет назад

In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker may be able to capture firmware updates through the adjacent network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w25-cqm4-wf2w

около 1 года назад

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/expense.php. The manipulation of the argument expense_for leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4w2h-78cc-554r

CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w2g-rx2c-59rp

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected app termination.

CVSS3: 7.5
1%
Низкий
4 месяца назад
github логотип
GHSA-4w2g-r9pq-p6qg

MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w2g-jrqm-g99q

exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.

CVSS3: 8.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4w2g-jgpv-wc89

IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w2g-j23f-x62h

Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-4w2g-c9v6-pgv7

Improper access control in Zoom Rooms before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVSS3: 8.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-4w2f-r3pq-3wfp

The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon crash and message data loss) via malformed headers during a WebSockets connection upgrade.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w2f-m236-fggc

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

CVSS3: 5.4
1%
Низкий
почти 2 года назад
github логотип
GHSA-4w2c-mfgm-ff7r

By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w29-23fj-v8v5

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R7500v2 before 1.0.3.20, R7800 before 1.0.2.38, WN3000RPv3 before 1.0.2.50, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w28-6qpv-x7c2

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a potential heap overflow and memory corruption due to improper error handling in SOC infrastructure.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w28-4cpv-vvf3

Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issue affects PAN-OS 9.0 versions prior to 9.0.5-h3 on PA-7080 and PA-7050 devices with an LFC installed and configured. This issue does not affect PA-7000 Series deployments using the first-generation SMC and the Log Processing Card (LPC). This issue does not affect any other PA series devices. This issue does not affect devices without an LFC. This issue does not affect PAN-OS 8.1 or prior releases. This issue only affects a very limited number of customers and we undertook individual outreach to help them upgrade. At the time of publication, all identified customers have upgraded SW or content and are not impacted.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4w27-xxvw-958c

foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w27-cg72-mj62

A information disclosure vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: Android kernel. Android ID: A-71359108. References: B-V2018010501.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w27-8685-x47p

Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4w26-p3x4-j4mv

An insecure logging vulnerability has been identified within ROS2 Iron Irwini versions ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to access sensitive information via inadequate security measures implemented within the logging mechanisms of ROS2.

больше 2 лет назад
github логотип
GHSA-4w26-8p97-f4jp

AugAssign evaluation order causing OOB write within the object in Vyper

1%
Низкий
больше 1 года назад
github логотип
GHSA-4w26-4rcj-vffr

In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker may be able to capture firmware updates through the adjacent network.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w25-cqm4-wf2w

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/operations/expense.php. The manipulation of the argument expense_for leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад

Уязвимостей на страницу