Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4f8x-f25f-pp6r

больше 1 года назад

Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4f8x-8m63-7qx4

больше 4 лет назад

In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-205995178References: N/A

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4f8x-4r4g-29qq

больше 4 лет назад

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).

EPSS: Низкий
github логотип

GHSA-4f8w-fmh5-hcxr

около 1 месяца назад

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of realms from the request, rather than all realms. Because HashSet iteration order is non-deterministic, an authenticated attacker who includes alarm-asset links from both their own realm and a victim realm can, with roughly 50% probability per request (retryable), persist cross-tenant links and disclose victim asset names (returned via @Formula fields) through GET requests on the attacker's own alarm. Fixed in 1.27.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4f8w-7rrv-r75q

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yendif Player Another Events Calendar allows Reflected XSS. This issue affects Another Events Calendar: from n/a through 1.7.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4f8w-7gfm-cwp8

больше 4 лет назад

IOKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption and application crash) via a malformed plist.

EPSS: Низкий
github логотип

GHSA-4f8w-48h8-77c3

больше 4 лет назад

IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4f8v-jp98-cpv3

2 месяца назад

AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vulnerability in the Meet plugin's getMeetInfo.json.php endpoint. When a participant joins a public meeting, the raw HTTP User-Agent header is stored (meet_join_log.user_agent) without sanitization (bypassing AVideo's setter-level xss_esc() layer) and later echoed without output encoding (no htmlspecialchars()) in the Participants management panel, which is accessible to the meeting host and site administrators. An anonymous, unauthenticated attacker can join any public meeting while supplying a User-Agent header containing an HTML/JavaScript payload; the payload is persisted and executes in the privileged, authenticated browser session of the meeting host or a site administrator when they open the participant list. The issue was unpatched at the time of the report.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4f8v-gh3f-vqfj

больше 4 лет назад

Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors.

EPSS: Низкий
github логотип

GHSA-4f8r-r8j4-c56j

больше 4 лет назад

The SportsPress plugin before 2.7.2 for WordPress allows XSS.

EPSS: Низкий
github логотип

GHSA-4f8r-qqr9-fq8j

почти 2 года назад

Incorrect delegation lookups can make go-tuf download the wrong artifact

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f8r-922h-2vgv

4 месяца назад

js-libp2p: Memory DoS via subscription flood of unique topics

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f8q-mwgc-3mwc

больше 1 года назад

Drupal OAuth2 Server Missing Authorization vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f8q-56wq-r4gw

почти 2 года назад

A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f8p-h8vg-88vj

почти 3 года назад

Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f8p-8r7v-qj37

больше 4 лет назад

Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 mishandle signed disk images, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4f8p-5r29-jr72

больше 4 лет назад

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

EPSS: Высокий
github логотип

GHSA-4f8m-x9c7-gvcq

больше 4 лет назад

Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f8m-hgv8-w5q2

больше 4 лет назад

Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports.

EPSS: Низкий
github логотип

GHSA-4f8m-8mgg-8vf4

8 месяцев назад

GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer. Attackers can generate a payload of 8000 repeated characters to overwhelm the input field and cause the application to become unresponsive.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f8x-f25f-pp6r

Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.

CVSS3: 7.1
4%
Низкий
больше 1 года назад
github логотип
GHSA-4f8x-8m63-7qx4

In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-205995178References: N/A

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8x-4r4g-29qq

Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8w-fmh5-hcxr

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of realms from the request, rather than all realms. Because HashSet iteration order is non-deterministic, an authenticated attacker who includes alarm-asset links from both their own realm and a victim realm can, with roughly 50% probability per request (retryable), persist cross-tenant links and disclose victim asset names (returned via @Formula fields) through GET requests on the attacker's own alarm. Fixed in 1.27.0.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4f8w-7rrv-r75q

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yendif Player Another Events Calendar allows Reflected XSS. This issue affects Another Events Calendar: from n/a through 1.7.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4f8w-7gfm-cwp8

IOKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption and application crash) via a malformed plist.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8w-48h8-77c3

IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.

CVSS3: 9.1
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8v-jp98-cpv3

AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vulnerability in the Meet plugin's getMeetInfo.json.php endpoint. When a participant joins a public meeting, the raw HTTP User-Agent header is stored (meet_join_log.user_agent) without sanitization (bypassing AVideo's setter-level xss_esc() layer) and later echoed without output encoding (no htmlspecialchars()) in the Participants management panel, which is accessible to the meeting host and site administrators. An anonymous, unauthenticated attacker can join any public meeting while supplying a User-Agent header containing an HTML/JavaScript payload; the payload is persisted and executes in the privileged, authenticated browser session of the meeting host or a site administrator when they open the participant list. The issue was unpatched at the time of the report.

CVSS3: 6.1
0%
Низкий
2 месяца назад
github логотип
GHSA-4f8v-gh3f-vqfj

Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8r-r8j4-c56j

The SportsPress plugin before 2.7.2 for WordPress allows XSS.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8r-qqr9-fq8j

Incorrect delegation lookups can make go-tuf download the wrong artifact

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-4f8r-922h-2vgv

js-libp2p: Memory DoS via subscription flood of unique topics

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4f8q-mwgc-3mwc

Drupal OAuth2 Server Missing Authorization vulnerability

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4f8q-56wq-r4gw

A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-4f8p-h8vg-88vj

Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-4f8p-8r7v-qj37

Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 mishandle signed disk images, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8p-5r29-jr72

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

73%
Высокий
больше 4 лет назад
github логотип
GHSA-4f8m-x9c7-gvcq

Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8m-hgv8-w5q2

Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f8m-8mgg-8vf4

GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer. Attackers can generate a payload of 8000 repeated characters to overwhelm the input field and cause the application to become unresponsive.

CVSS3: 7.5
0%
Низкий
8 месяцев назад

Уязвимостей на страницу