Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v7m-745p-mv2f

больше 4 лет назад

An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), N(7.x), and O(8.0) software. There is a kernel pointer leak in the USB gadget driver. The Samsung ID is SVE-2017-10993 (March 2018).

EPSS: Низкий
github логотип

GHSA-4v7j-4mvr-5975

2 месяца назад

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4v7h-33pf-w9h6

около 2 лет назад

Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-4v7f-gpgp-5q79

больше 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4v7f-g678-5xwv

4 месяца назад

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4v7c-97mg-h3wh

7 месяцев назад

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v7c-4xff-r4v7

больше 4 лет назад

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v79-g36g-gxp6

больше 3 лет назад

The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing nonce validation on the gmace_manager_server function called via the wp_ajax_gmace_manager AJAX action. This makes it possible for unauthenticated attackers to modify arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v78-j8g9-rpv2

около 1 года назад

Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended curator-group assignment checks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4v78-h2mp-2rp3

больше 4 лет назад

Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4v78-7jx6-mhrg

больше 1 года назад

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v77-vppr-hv2g

больше 3 лет назад

Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 98.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v77-6pxw-9whf

больше 4 лет назад

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v76-pc3g-jgg8

больше 4 лет назад

The Management Software application in GarrettCom Magnum MNS-6K before 4.4.0, and 14.x before 14.4.0, has a hardcoded password for an administrative account, which allows local users to gain privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4v76-jcg6-9p6m

9 месяцев назад

A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v76-cw68-4vc9

3 месяца назад

SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v75-4r3r-343g

почти 3 года назад

The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.7.7. due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4v73-g3hv-w298

больше 4 лет назад

IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182907.

EPSS: Низкий
github логотип

GHSA-4v73-45hj-cf9x

больше 1 года назад

A vulnerability was found in H3C GR-1800AX up to 100R008 and classified as critical. Affected by this issue is the function EnableIpv6 of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4v72-6p9w-2mww

больше 4 лет назад

In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run any command with root privileges on that server.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v7m-745p-mv2f

An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), N(7.x), and O(8.0) software. There is a kernel pointer leak in the USB gadget driver. The Samsung ID is SVE-2017-10993 (March 2018).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v7j-4mvr-5975

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680

CVSS3: 5.9
0%
Низкий
2 месяца назад
github логотип
GHSA-4v7h-33pf-w9h6

Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension.

CVSS3: 9.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-4v7f-gpgp-5q79

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4v7f-g678-5xwv

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.

CVSS3: 4.8
0%
Низкий
4 месяца назад
github логотип
GHSA-4v7c-97mg-h3wh

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-4v7c-4xff-r4v7

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v79-g36g-gxp6

The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing nonce validation on the gmace_manager_server function called via the wp_ajax_gmace_manager AJAX action. This makes it possible for unauthenticated attackers to modify arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4v78-j8g9-rpv2

Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended curator-group assignment checks.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-4v78-h2mp-2rp3

Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.

CVSS3: 4.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v78-7jx6-mhrg

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-4v77-vppr-hv2g

Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 98.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4v77-6pxw-9whf

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v76-pc3g-jgg8

The Management Software application in GarrettCom Magnum MNS-6K before 4.4.0, and 14.x before 14.4.0, has a hardcoded password for an administrative account, which allows local users to gain privileges via unspecified vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v76-jcg6-9p6m

A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

CVSS3: 8.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-4v76-cw68-4vc9

SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required

CVSS3: 6.5
3 месяца назад
github логотип
GHSA-4v75-4r3r-343g

The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.7.7. due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-4v73-g3hv-w298

IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182907.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v73-45hj-cf9x

A vulnerability was found in H3C GR-1800AX up to 100R008 and classified as critical. Affected by this issue is the function EnableIpv6 of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used.

CVSS3: 8
1%
Низкий
больше 1 года назад
github логотип
GHSA-4v72-6p9w-2mww

In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run any command with root privileges on that server.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу