Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v4v-wmpc-5vh5

больше 1 года назад

A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4v4v-fcfx-x6mg

больше 1 года назад

CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v4v-cgjf-p5g2

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 Shortcode Addons allows Stored XSS.This issue affects Shortcode Addons: from n/a through 3.2.5.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4v4v-92cx-x4f4

около 1 года назад

Jenkins Nouvola DiveCloud Plugin vulnerability does not mask keys on its job configuration form

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4v4v-6cx5-x258

больше 4 лет назад

Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).

EPSS: Низкий
github логотип

GHSA-4v4q-xr4r-hm4m

почти 2 года назад

The goTenna Pro ATAK Plugin broadcast key name is always sent unencrypted and could reveal the location of operation.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4v4q-r2mh-q7w6

больше 4 лет назад

Microsoft Defender Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-4v4q-53h2-r6mj

больше 4 лет назад

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy.

EPSS: Низкий
github логотип

GHSA-4v4p-87m3-5423

около 4 лет назад

Known v1.3.1 contains Insecure Direct Object Reference

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4v4m-xjj9-g6j7

больше 4 лет назад

SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.

EPSS: Низкий
github логотип

GHSA-4v4m-mxm3-w2h7

больше 4 лет назад

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with kernel privileges.

EPSS: Низкий
github логотип

GHSA-4v4m-mgj6-c8jv

почти 2 года назад

Windows NT OS Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v4m-hgv5-x3qx

больше 4 лет назад

A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v4j-f74g-gxqv

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install, a different vulnerability than CVE-2013-5905.

EPSS: Низкий
github логотип

GHSA-4v4j-83q8-87wq

больше 4 лет назад

Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS05.

EPSS: Низкий
github логотип

GHSA-4v4h-m2qq-ppgw

3 месяца назад

Kirby: Request header injection in `Http\Remote`

EPSS: Низкий
github логотип

GHSA-4v4h-6mhp-rwxf

около 2 месяцев назад

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-4v4h-3w7f-m5wp

больше 4 лет назад

There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could exploit this vulnerability to decrypt data. Successful exploitation may leak information randomly.Affected product versions include:Product Name version Affected Version;Anne-AL00 versions Versions earlier than 9.1.0.331(C675E9R1P3T8);Berkeley-L09 versions Versions earlier than 10.0.1.1(C675R1);CD16-10 versions Versions earlier than 10.0.2.8;CD17-10 versions Versions earlier than 10.0.2.8;CD17-16 versions Versions earlier than 10.0.2.8;CD18-10 versions Versions earlier than 10.0.2.8;CD18-16 versions Versions earlier than 10.0.2.8;Columbia-TL00B versions Versions earlier than 9.0.0.187(C01E181R1P20T8);E6878-370 versions Versions earlier than 10.0.5.1(H610SP10C00);Honor 10 Lite versions Versions earlier than 10.0.0.182(C675E17R2P2);LelandP-L22A versions Versions earlier than 9.1.0.166(C675E5R1P4T8);TC5200-16 versions

EPSS: Низкий
github логотип

GHSA-4v4g-vfv9-gvgj

11 месяцев назад

Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v4g-7cw5-m7vc

4 месяца назад

A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v4v-wmpc-5vh5

A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-4v4v-fcfx-x6mg

CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v4v-cgjf-p5g2

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 Shortcode Addons allows Stored XSS.This issue affects Shortcode Addons: from n/a through 3.2.5.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-4v4v-92cx-x4f4

Jenkins Nouvola DiveCloud Plugin vulnerability does not mask keys on its job configuration form

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4v4v-6cx5-x258

Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4q-xr4r-hm4m

The goTenna Pro ATAK Plugin broadcast key name is always sent unencrypted and could reveal the location of operation.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-4v4q-r2mh-q7w6

Microsoft Defender Remote Code Execution Vulnerability

CVSS3: 7.8
39%
Средний
больше 4 лет назад
github логотип
GHSA-4v4q-53h2-r6mj

In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4p-87m3-5423

Known v1.3.1 contains Insecure Direct Object Reference

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-4v4m-xjj9-g6j7

SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4m-mxm3-w2h7

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with kernel privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4m-mgj6-c8jv

Windows NT OS Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
4%
Низкий
почти 2 года назад
github логотип
GHSA-4v4m-hgv5-x3qx

A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4j-f74g-gxqv

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install, a different vulnerability than CVE-2013-5905.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4j-83q8-87wq

Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS05.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4h-m2qq-ppgw

Kirby: Request header injection in `Http\Remote`

0%
Низкий
3 месяца назад
github логотип
GHSA-4v4h-6mhp-rwxf

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.

CVSS3: 2.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4v4h-3w7f-m5wp

There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could exploit this vulnerability to decrypt data. Successful exploitation may leak information randomly.Affected product versions include:Product Name version Affected Version;Anne-AL00 versions Versions earlier than 9.1.0.331(C675E9R1P3T8);Berkeley-L09 versions Versions earlier than 10.0.1.1(C675R1);CD16-10 versions Versions earlier than 10.0.2.8;CD17-10 versions Versions earlier than 10.0.2.8;CD17-16 versions Versions earlier than 10.0.2.8;CD18-10 versions Versions earlier than 10.0.2.8;CD18-16 versions Versions earlier than 10.0.2.8;Columbia-TL00B versions Versions earlier than 9.0.0.187(C01E181R1P20T8);E6878-370 versions Versions earlier than 10.0.5.1(H610SP10C00);Honor 10 Lite versions Versions earlier than 10.0.0.182(C675E17R2P2);LelandP-L22A versions Versions earlier than 9.1.0.166(C675E5R1P4T8);TC5200-16 versions

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4g-vfv9-gvgj

Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-4v4g-7cw5-m7vc

A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service.

CVSS3: 8.8
0%
Низкий
4 месяца назад

Уязвимостей на страницу