Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4f4r-wgv2-jjvg

почти 3 года назад

Quarkus HTTP vulnerable to incorrect evaluation of permissions

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4f4q-xvfm-58g2

9 месяцев назад

In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4f4q-pprq-947q

около 3 лет назад

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4f4q-2g4m-9h57

больше 4 лет назад

kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.

EPSS: Низкий
github логотип

GHSA-4f4p-9vfr-w7m4

12 месяцев назад

Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows a attacker to inject an arbitrary scripts may be executed on the user's browser.

EPSS: Низкий
github логотип

GHSA-4f4p-52mc-m3g8

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi reCAPTCHA for all allows Cross Site Request Forgery. This issue affects reCAPTCHA for all: from n/a through 2.26.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4f4m-2qm7-575f

2 месяца назад

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT payload keys whose names appear in the admin-configured `jwt_payload` list — leaving any attacker-supplied identity claims such as `email`, `id`, or `username` intact and signed into the JWT with the site's HS256 secret. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an Administrator by injecting a target administrator's email address into the `payload` parameter at the `/wp-json/simple-jwt-login/v1/auth` endpoint, then redeeming the resulting JWT at the `/autologin` endpoint to obtain a fully authenticated session as that administrator.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f4h-jgjp-3vfg

больше 4 лет назад

Subrion CMS CSV injection via Export Language

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4f4h-6cgm-pgpx

больше 4 лет назад

Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.

EPSS: Низкий
github логотип

GHSA-4f4h-4mvr-gm9g

больше 4 лет назад

An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library generates insufficiently random numbers for robot secret_key values used for local and cloud authentication/authorization. If an attacker knows the serial number and is able to estimate the time of first provisioning of a robot, he is able to brute force the generated secret_key of the robot. This is because the entropy of the secret_key exclusively relies on these two values, due to not seeding the random generator and using several constant inputs for secret_key computation. Serial numbers are printed on the packaging and equal the MAC address of the robot.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4f4g-mjgj-wqjc

почти 2 года назад

The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f4g-m6h2-8q23

больше 4 лет назад

In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive information from kernel stack memory, aka CID-df7e40425813.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f4c-rhjv-4wgv

почти 3 года назад

Cross-Site Request Forgery with QueryOnXWiki allows arbitrary database queries

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f4c-qjgf-q2g9

больше 4 лет назад

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4f4c-f6w3-8rrm

5 дней назад

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4f49-fqv9-jwhv

около 1 года назад

A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formPortFw of the component HTTP POST Message Handler. The manipulation of the argument service_type leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f49-557j-w78c

20 дней назад

The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.

EPSS: Низкий
github логотип

GHSA-4f48-w364-xw45

больше 4 лет назад

ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f48-qpch-4ppx

больше 3 лет назад

Insecure Permissions issue in jeecg-boot

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f48-qjgq-932g

больше 4 лет назад

The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f4r-wgv2-jjvg

Quarkus HTTP vulnerable to incorrect evaluation of permissions

CVSS3: 8.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-4f4q-xvfm-58g2

In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-4f4q-pprq-947q

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-4f4q-2g4m-9h57

kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f4p-9vfr-w7m4

Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows a attacker to inject an arbitrary scripts may be executed on the user's browser.

0%
Низкий
12 месяцев назад
github логотип
GHSA-4f4p-52mc-m3g8

Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi reCAPTCHA for all allows Cross Site Request Forgery. This issue affects reCAPTCHA for all: from n/a through 2.26.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4f4m-2qm7-575f

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT payload keys whose names appear in the admin-configured `jwt_payload` list — leaving any attacker-supplied identity claims such as `email`, `id`, or `username` intact and signed into the JWT with the site's HS256 secret. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an Administrator by injecting a target administrator's email address into the `payload` parameter at the `/wp-json/simple-jwt-login/v1/auth` endpoint, then redeeming the resulting JWT at the `/autologin` endpoint to obtain a fully authenticated session as that administrator.

CVSS3: 8.8
1%
Низкий
2 месяца назад
github логотип
GHSA-4f4h-jgjp-3vfg

Subrion CMS CSV injection via Export Language

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f4h-6cgm-pgpx

Deserialization of untrusted data in the login page of ASSUWEB 359.3 build 1 subcomponent of ACA ASSUREX RENTES product allows a remote attacker to inject unsecure serialized Java object using a specially crafted HTTP request, resulting in an unauthenticated remote code execution on the server.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4f4h-4mvr-gm9g

An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library generates insufficiently random numbers for robot secret_key values used for local and cloud authentication/authorization. If an attacker knows the serial number and is able to estimate the time of first provisioning of a robot, he is able to brute force the generated secret_key of the robot. This is because the entropy of the secret_key exclusively relies on these two values, due to not seeding the random generator and using several constant inputs for secret_key computation. Serial numbers are printed on the packaging and equal the MAC address of the robot.

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f4g-mjgj-wqjc

The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-4f4g-m6h2-8q23

In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive information from kernel stack memory, aka CID-df7e40425813.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f4c-rhjv-4wgv

Cross-Site Request Forgery with QueryOnXWiki allows arbitrary database queries

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-4f4c-qjgf-q2g9

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component.

CVSS3: 9.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4f4c-f6w3-8rrm

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.

CVSS3: 5.3
2%
Низкий
5 дней назад
github логотип
GHSA-4f49-fqv9-jwhv

A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formPortFw of the component HTTP POST Message Handler. The manipulation of the argument service_type leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-4f49-557j-w78c

The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.

0%
Низкий
20 дней назад
github логотип
GHSA-4f48-w364-xw45

ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4f48-qpch-4ppx

Insecure Permissions issue in jeecg-boot

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-4f48-qjgq-932g

The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

CVSS3: 8.8
41%
Средний
больше 4 лет назад

Уязвимостей на страницу