Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4r63-5qjg-x8mr

больше 4 лет назад

Huawei NE20E-S, NE40E-M, and NE40E-M2 routers with software before V800R007C10SPC100 and NE40E and NE80E routers with software before V800R007C00SPC100 allows remote attackers to send packets to other VPNs and conduct flooding attacks via a crafted MPLS forwarding packet, aka a "VPN routing and forwarding (VRF) hopping vulnerability."

EPSS: Низкий
github логотип

GHSA-4r63-54pq-wf8p

3 месяца назад

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-4r62-v4vq-hr96

больше 5 лет назад

Regular Expression Denial of Service (REDoS) in Marked

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4r5x-x993-p7cp

5 дней назад

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Actions). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-4r5x-x283-wm96

почти 3 года назад

Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4r5x-qjqc-p579

около 6 лет назад

Tracking Module in botbait

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4r5w-h6p7-33h7

больше 4 лет назад

Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

EPSS: Низкий
github логотип

GHSA-4r5w-gxp2-jf38

больше 4 лет назад

SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.

EPSS: Низкий
github логотип

GHSA-4r5w-76r7-ch99

11 месяцев назад

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r5w-3xv4-56jm

3 месяца назад

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-4r5v-83pg-j94v

больше 4 лет назад

In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4r5v-6p2m-qfm6

2 месяца назад

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data as well as unauthorized read access to a subset of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4r5v-2f2w-h6rr

больше 4 лет назад

Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate.

EPSS: Низкий
github логотип

GHSA-4r5r-p2hf-qwww

8 месяцев назад

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4r5r-fq7c-w555

больше 4 лет назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D files embedded in PDF documents. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-13621.

EPSS: Низкий
github логотип

GHSA-4r5r-ccr6-q6f6

8 месяцев назад

Fleet has an Access Control vulnerability in debug/pprof endpoints

EPSS: Низкий
github логотип

GHSA-4r5q-wgf5-6r7g

больше 2 лет назад

Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4r5q-f55r-9frx

5 месяцев назад

mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19 and below.

EPSS: Низкий
github логотип

GHSA-4r5q-5r5j-gmpm

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-4r5p-qqxr-3jgc

больше 1 года назад

In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4r63-5qjg-x8mr

Huawei NE20E-S, NE40E-M, and NE40E-M2 routers with software before V800R007C10SPC100 and NE40E and NE80E routers with software before V800R007C00SPC100 allows remote attackers to send packets to other VPNs and conduct flooding attacks via a crafted MPLS forwarding packet, aka a "VPN routing and forwarding (VRF) hopping vulnerability."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r63-54pq-wf8p

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 9.6
0%
Низкий
3 месяца назад
github логотип
GHSA-4r62-v4vq-hr96

Regular Expression Denial of Service (REDoS) in Marked

CVSS3: 5.3
2%
Низкий
больше 5 лет назад
github логотип
GHSA-4r5x-x993-p7cp

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Actions). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

CVSS3: 8.5
0%
Низкий
5 дней назад
github логотип
GHSA-4r5x-x283-wm96

Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell

CVSS3: 6.4
2%
Низкий
почти 3 года назад
github логотип
GHSA-4r5x-qjqc-p579

Tracking Module in botbait

CVSS3: 5.3
1%
Низкий
около 6 лет назад
github логотип
GHSA-4r5w-h6p7-33h7

Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r5w-gxp2-jf38

SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r5w-76r7-ch99

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-4r5w-3xv4-56jm

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.

CVSS3: 9.9
0%
Низкий
3 месяца назад
github логотип
GHSA-4r5v-83pg-j94v

In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r5v-6p2m-qfm6

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data as well as unauthorized read access to a subset of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

CVSS3: 5.4
0%
Низкий
2 месяца назад
github логотип
GHSA-4r5v-2f2w-h6rr

Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r5r-p2hf-qwww

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3.

CVSS3: 9.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-4r5r-fq7c-w555

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D files embedded in PDF documents. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-13621.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r5r-ccr6-q6f6

Fleet has an Access Control vulnerability in debug/pprof endpoints

0%
Низкий
8 месяцев назад
github логотип
GHSA-4r5q-wgf5-6r7g

Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4r5q-f55r-9frx

mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19 and below.

0%
Низкий
5 месяцев назад
github логотип
GHSA-4r5q-5r5j-gmpm

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r5p-qqxr-3jgc

In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу