Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-4c47-49qq-pq45

около 3 лет назад

ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4c46-9f7j-r9vq

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_counter: serialize reset with spinlock Add a global static spinlock to serialize counter fetch+reset operations, preventing concurrent dump-and-reset from underrunning values. The lock is taken before fetching the total so that two parallel resets cannot both read the same counter values and then both subtract them. A global lock is used for simplicity since resets are infrequent. If this becomes a bottleneck, it can be replaced with a per-net lock later.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4c46-93x9-557q

13 дней назад

Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4c45-wmm4-4hq2

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4c45-vj44-g553

больше 4 лет назад

An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the same OTA verification keys, and the fact that both products share the same 'ro.build.product' system property, attackers can install OTAs of one product over the other, even on locked bootloaders. That could theoretically allow for exploitation of vulnerabilities patched on one image but not on the other, in addition to expansion of the attack surface. Moreover, the vulnerability may result in having the device unusable until a Factory Reset is performed. This vulnerability can be exploited by Man-in-the-Middle (MiTM) attackers targeting the update process. This is possible because the update transaction does not occur over TLS (CVE-2016-10370). In addition, physical attackers can reboot the phone into recovery, and then use 'adb sideload' to push the OTA.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4c45-725m-4wqx

больше 4 лет назад

The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4c45-3gcv-m98f

около 4 лет назад

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4c45-3482-x925

больше 4 лет назад

The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local users to obtain sensitive information by reading a log file.

EPSS: Низкий
github логотип

GHSA-4c44-wpv3-4f58

больше 1 года назад

The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking records, and restarting the system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4c44-r8rm-3p39

12 месяцев назад

Mangati NovoSGA XSS vulnerability in /admin

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-4c44-843m-j2x2

больше 4 лет назад

SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

EPSS: Низкий
github логотип

GHSA-4c43-mrmc-223j

около 1 года назад

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4c43-cwvx-9crh

больше 4 лет назад

Improper Access Control in Apache Tomcat

EPSS: Средний
github логотип

GHSA-4c42-9cxr-m69j

11 месяцев назад

Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-4c42-4rxm-x6qf

больше 4 лет назад

Django Denial of Service Vulnerability in the authentication framework

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4c3x-wrfg-6pjr

больше 2 лет назад

An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4c3v-rh37-vhvm

около 4 лет назад

Memory corruption due to buffer overflow while parsing MKV clips with invalid bitmap size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4c3v-jr8f-g5h4

больше 4 лет назад

Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.

EPSS: Средний
github логотип

GHSA-4c3q-x735-j3r5

5 месяцев назад

Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4c3q-r84r-q6pp

около 3 лет назад

Jenkins mabl Plugin vulnerable to exposure of system-scooped credentials

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4c47-49qq-pq45

ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-4c46-9f7j-r9vq

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_counter: serialize reset with spinlock Add a global static spinlock to serialize counter fetch+reset operations, preventing concurrent dump-and-reset from underrunning values. The lock is taken before fetching the total so that two parallel resets cannot both read the same counter values and then both subtract them. A global lock is used for simplicity since resets are infrequent. If this becomes a bottleneck, it can be replaced with a per-net lock later.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4c46-93x9-557q

Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 4.3
0%
Низкий
13 дней назад
github логотип
GHSA-4c45-wmm4-4hq2

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4c45-vj44-g553

An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the same OTA verification keys, and the fact that both products share the same 'ro.build.product' system property, attackers can install OTAs of one product over the other, even on locked bootloaders. That could theoretically allow for exploitation of vulnerabilities patched on one image but not on the other, in addition to expansion of the attack surface. Moreover, the vulnerability may result in having the device unusable until a Factory Reset is performed. This vulnerability can be exploited by Man-in-the-Middle (MiTM) attackers targeting the update process. This is possible because the update transaction does not occur over TLS (CVE-2016-10370). In addition, physical attackers can reboot the phone into recovery, and then use 'adb sideload' to push the OTA.

CVSS3: 5.9
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4c45-725m-4wqx

The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-4c45-3gcv-m98f

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-4c45-3482-x925

The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local users to obtain sensitive information by reading a log file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4c44-wpv3-4f58

The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking records, and restarting the system.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-4c44-r8rm-3p39

Mangati NovoSGA XSS vulnerability in /admin

CVSS3: 2.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-4c44-843m-j2x2

SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c43-mrmc-223j

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
1%
Низкий
около 1 года назад
github логотип
GHSA-4c43-cwvx-9crh

Improper Access Control in Apache Tomcat

14%
Средний
больше 4 лет назад
github логотип
GHSA-4c42-9cxr-m69j

Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.

CVSS3: 4
0%
Низкий
11 месяцев назад
github логотип
GHSA-4c42-4rxm-x6qf

Django Denial of Service Vulnerability in the authentication framework

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4c3x-wrfg-6pjr

An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.

CVSS3: 7.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4c3v-rh37-vhvm

Memory corruption due to buffer overflow while parsing MKV clips with invalid bitmap size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-4c3v-jr8f-g5h4

Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.

23%
Средний
больше 4 лет назад
github логотип
GHSA-4c3q-x735-j3r5

Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing

CVSS3: 8.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-4c3q-r84r-q6pp

Jenkins mabl Plugin vulnerable to exposure of system-scooped credentials

CVSS3: 6.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу