Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4rhq-vpg8-62j3

почти 3 года назад

In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4rhq-r59j-x4fc

почти 4 года назад

Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chrome security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rhp-v69r-6w59

почти 4 года назад

In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4rhm-m2fp-hx7q

больше 6 лет назад

Potential CSV Injection vector in OctoberCMS

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-4rhm-7j67-99mp

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rhh-qhhp-cw22

9 месяцев назад

NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4rhg-qwrc-fj7f

больше 2 лет назад

Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rhg-p5c5-29q7

больше 4 лет назад

SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4rhg-h8f2-v4jm

4 месяца назад

pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4rhg-f685-m3px

больше 4 лет назад

Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rhg-84mj-rx7h

больше 4 лет назад

admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rhg-7crh-vmfw

больше 4 лет назад

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Local users can gain privileges because of LAF and SBL1 flaws. The LG ID is LVE-SMP-200015 (July 2020).

EPSS: Низкий
github логотип

GHSA-4rhf-x5cr-x2mw

больше 4 лет назад

A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf03514.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4rhf-g669-h99f

3 месяца назад

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-4rhf-85wr-9pxc

около 4 лет назад

A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4rhc-q92g-rm98

больше 1 года назад

A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rhc-pqwm-9j5g

больше 4 лет назад

Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4rhc-g7g9-q5w5

больше 4 лет назад

hoppscotch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4rhc-2pqf-hqj3

больше 1 года назад

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4rh8-xrf7-26m9

11 месяцев назад

Rejected reason: Not used

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4rhq-vpg8-62j3

In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-4rhq-r59j-x4fc

Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chrome security severity: Medium)

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-4rhp-v69r-6w59

In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).

CVSS3: 8.8
23%
Средний
почти 4 года назад
github логотип
GHSA-4rhm-m2fp-hx7q

Potential CSV Injection vector in OctoberCMS

CVSS3: 4
1%
Низкий
больше 6 лет назад
github логотип
GHSA-4rhm-7j67-99mp

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-4rhh-qhhp-cw22

NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application.

CVSS3: 8.2
0%
Низкий
9 месяцев назад
github логотип
GHSA-4rhg-qwrc-fj7f

Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4rhg-p5c5-29q7

SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhg-h8f2-v4jm

pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager

CVSS3: 7
0%
Низкий
4 месяца назад
github логотип
GHSA-4rhg-f685-m3px

Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhg-84mj-rx7h

admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhg-7crh-vmfw

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Local users can gain privileges because of LAF and SBL1 flaws. The LG ID is LVE-SMP-200015 (July 2020).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhf-x5cr-x2mw

A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf03514.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhf-g669-h99f

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 9.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4rhf-85wr-9pxc

A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-4rhc-q92g-rm98

A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4rhc-pqwm-9j5g

Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session cookies via JavaScript.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhc-g7g9-q5w5

hoppscotch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhc-2pqf-hqj3

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4rh8-xrf7-26m9

Rejected reason: Not used

11 месяцев назад

Уязвимостей на страницу