Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-49rv-55mv-j6cw

почти 3 года назад

Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49rv-46ph-6jmv

3 месяца назад

A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept of the component POST Request Handler. The manipulation of the argument submit-url leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-49rv-22xj-r3r3

почти 3 года назад

A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details. 

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-49rr-mq22-qwpx

около 2 месяцев назад

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 2.6 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L).

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-49rr-hfxh-8f4c

21 день назад

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply arbitrary SQL through the filter condition, giving full read of the database.

EPSS: Низкий
github логотип

GHSA-49rr-39cq-x5ph

около 2 месяцев назад

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-49rr-34j5-r8mw

больше 1 года назад

juzaweb CMS allows cross-site scripting by uploading an SVG file

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-49rr-2fpg-hfw9

почти 2 года назад

Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49rq-vv34-q63r

больше 4 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-49rq-rc9q-m764

больше 4 лет назад

The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:\" substring and contains a full pathname in the ini field. NOTE: this can be leveraged for code execution by writing to a Startup folder.

EPSS: Низкий
github логотип

GHSA-49rq-p3m9-2cqc

больше 4 лет назад

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-49rq-hwc3-x77w

больше 3 лет назад

TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49rq-5w7r-4rrp

больше 3 лет назад

In the Linux kernel before 5.17, an error path in dwc3_qcom_acpi_register_core in drivers/usb/dwc3/dwc3-qcom.c lacks certain platform_device_put and kfree calls.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-49rm-rmg5-26vv

около 4 лет назад

Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49rm-fhc6-pjjq

почти 4 года назад

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-49rm-7f9x-mx4g

около 1 года назад

A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the file /goform/formSetWanDhcpplus. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-49rj-9fvp-4h2h

3 месяца назад

React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-49rj-992g-44xv

больше 4 лет назад

Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption.

EPSS: Низкий
github логотип

GHSA-49rj-8gmm-9hrq

больше 4 лет назад

Unspecified vulnerability in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AAC-encoded file that triggers memory corruption.

EPSS: Низкий
github логотип

GHSA-49rh-g874-x54c

больше 4 лет назад

Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets from the Scan Safe Tower, aka Bug ID CSCub85451.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-49rv-55mv-j6cw

Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-49rv-46ph-6jmv

A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept of the component POST Request Handler. The manipulation of the argument submit-url leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
2%
Низкий
3 месяца назад
github логотип
GHSA-49rv-22xj-r3r3

A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details. 

CVSS3: 5.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-49rr-mq22-qwpx

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 2.6 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L).

CVSS3: 2.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-49rr-hfxh-8f4c

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply arbitrary SQL through the filter condition, giving full read of the database.

0%
Низкий
21 день назад
github логотип
GHSA-49rr-39cq-x5ph

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-49rr-34j5-r8mw

juzaweb CMS allows cross-site scripting by uploading an SVG file

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-49rr-2fpg-hfw9

Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-49rq-vv34-q63r

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-49rq-rc9q-m764

The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:\" substring and contains a full pathname in the ini field. NOTE: this can be leveraged for code execution by writing to a Startup folder.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-49rq-p3m9-2cqc

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.

CVSS3: 6.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-49rq-hwc3-x77w

TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-49rq-5w7r-4rrp

In the Linux kernel before 5.17, an error path in dwc3_qcom_acpi_register_core in drivers/usb/dwc3/dwc3-qcom.c lacks certain platform_device_put and kfree calls.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-49rm-rmg5-26vv

Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-49rm-fhc6-pjjq

The Chained Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date' parameter on the 'chainedquiz_list' page in versions up to, and including, 1.3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-49rm-7f9x-mx4g

A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the file /goform/formSetWanDhcpplus. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
5%
Низкий
около 1 года назад
github логотип
GHSA-49rj-9fvp-4h2h

React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-49rj-992g-44xv

Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-49rj-8gmm-9hrq

Unspecified vulnerability in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AAC-encoded file that triggers memory corruption.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-49rh-g874-x54c

Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets from the Scan Safe Tower, aka Bug ID CSCub85451.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу