Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4cqp-9w5w-6x84

больше 4 лет назад

The Kavita KS (aka com.snaplion.kavitaks) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4cqp-8pqq-phx4

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Abu Bakar TWB Woocommerce Reviews allows Cross Site Request Forgery. This issue affects TWB Woocommerce Reviews: from n/a through 1.7.7.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4cqm-xv6v-78c5

больше 4 лет назад

Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.

EPSS: Низкий
github логотип

GHSA-4cqm-q6hh-xmp9

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

EPSS: Низкий
github логотип

GHSA-4cqm-fq4g-r4vq

около 1 месяца назад

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4cqm-42fg-6pwv

больше 2 лет назад

There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4cqj-vg46-4946

больше 1 года назад

There is an insufficient integrity vulnerability in Huawei products. A module does not perform sufficient integrity check in a specific scenario. Attackers can exploit the vulnerability by physically install malware. This could compromise normal service of the affected device. (Vulnerability ID: HWPSIRT-2020-00145) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9210.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4cqj-3j65-q8rq

больше 4 лет назад

While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC_CTX in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-13, a use-after-free condition may potentially occur.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4cqh-vv5h-qg69

около 3 лет назад

D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cqh-vr3j-xc4q

больше 4 лет назад

Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications.

EPSS: Низкий
github логотип

GHSA-4cqh-mqrw-7qqg

больше 4 лет назад

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

EPSS: Низкий
github логотип

GHSA-4cqh-m7pg-qhqj

6 месяцев назад

A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cqg-vc7j-pmhv

больше 4 лет назад

H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.

EPSS: Низкий
github логотип

GHSA-4cqg-g3vf-73q9

больше 4 лет назад

Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-4cqf-xfcw-xgjv

7 месяцев назад

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4cqf-vpcq-9pvx

больше 4 лет назад

Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).

EPSS: Низкий
github логотип

GHSA-4cqc-m2p5-mfxw

больше 1 года назад

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typically sanitizes data using wp_kses, like comments, in all versions up to, and including, 7.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4cqc-hc5r-xhj6

больше 4 лет назад

A vulnerability has been identified in SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V2.5 and < V20.8), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions >= V2.5 and < V2.8), SIMATIC S7-1500 Software Controller (All versions >= V2.5 and < V20.8). Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a Denial-of-Service condition. The vulnerability can be triggered if specially crafted UDP packets are sent to the device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the device availability.

EPSS: Низкий
github логотип

GHSA-4cqc-25m3-f64g

больше 4 лет назад

An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_arm_hp_template, demangle_class_name, demangle_fund_type, do_type, do_arg, demangle_args, and demangle_nested_args. This can occur during execution of nm-new.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4cq9-hp6g-498j

7 месяцев назад

Missing Authorization vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Secure Copy Content Protection and Content Locking: from n/a through <= 5.0.0.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4cqp-9w5w-6x84

The Kavita KS (aka com.snaplion.kavitaks) application 2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqp-8pqq-phx4

Cross-Site Request Forgery (CSRF) vulnerability in Abu Bakar TWB Woocommerce Reviews allows Cross Site Request Forgery. This issue affects TWB Woocommerce Reviews: from n/a through 1.7.7.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4cqm-xv6v-78c5

Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqm-q6hh-xmp9

An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqm-fq4g-r4vq

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4cqm-42fg-6pwv

There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below on Windows and Linux that allows a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4cqj-vg46-4946

There is an insufficient integrity vulnerability in Huawei products. A module does not perform sufficient integrity check in a specific scenario. Attackers can exploit the vulnerability by physically install malware. This could compromise normal service of the affected device. (Vulnerability ID: HWPSIRT-2020-00145) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9210.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4cqj-3j65-q8rq

While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC_CTX in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-13, a use-after-free condition may potentially occur.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqh-vv5h-qg69

D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.

CVSS3: 8.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-4cqh-vr3j-xc4q

Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqh-mqrw-7qqg

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqh-m7pg-qhqj

A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-4cqg-vc7j-pmhv

H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqg-g3vf-73q9

Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqf-xfcw-xgjv

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-4cqf-vpcq-9pvx

Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqc-m2p5-mfxw

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typically sanitizes data using wp_kses, like comments, in all versions up to, and including, 7.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-4cqc-hc5r-xhj6

A vulnerability has been identified in SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V2.5 and < V20.8), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions >= V2.5 and < V2.8), SIMATIC S7-1500 Software Controller (All versions >= V2.5 and < V20.8). Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a Denial-of-Service condition. The vulnerability can be triggered if specially crafted UDP packets are sent to the device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the device availability.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cqc-25m3-f64g

An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_arm_hp_template, demangle_class_name, demangle_fund_type, do_type, do_arg, demangle_args, and demangle_nested_args. This can occur during execution of nm-new.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cq9-hp6g-498j

Missing Authorization vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Secure Copy Content Protection and Content Locking: from n/a through <= 5.0.0.

CVSS3: 4.3
0%
Низкий
7 месяцев назад

Уязвимостей на страницу