Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 635

Количество 367 635

github логотип

GHSA-45rx-2jwx-cxfr

около 2 месяцев назад

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-45rw-4r25-jvg7

больше 4 лет назад

Moodle Logged in users could view all calendar events

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-45rv-q5wp-f6c4

больше 4 лет назад

There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby exploit this vulnerability. A successful exploitation of this vulnerability can compromise the device's data security and functional availability.

EPSS: Низкий
github логотип

GHSA-45rv-3qw6-q326

больше 4 лет назад

Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.

EPSS: Низкий
github логотип

GHSA-45rr-q6mf-fx4v

больше 4 лет назад

An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-45rr-p56g-wc84

больше 1 года назад

A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-45rr-gg9f-wfcm

около 4 лет назад

An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45rr-9gf8-j69p

больше 4 лет назад

An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is not checked, and is used for internal memory operations. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.

EPSS: Средний
github логотип

GHSA-45rr-9399-9pp6

6 месяцев назад

A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the file /goform/exeCommand of the component HTTP Handler. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-45rq-wggf-p92p

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.

EPSS: Низкий
github логотип

GHSA-45rq-hjm9-cgvx

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5543.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-45rp-q25w-4426

около 2 лет назад

pretix Stored Cross-site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-45rp-9p97-h852

6 месяцев назад

NocoDB Vulnerable to SQL Injection via DATEADD Formula

EPSS: Низкий
github логотип

GHSA-45rp-8p4h-8m88

больше 4 лет назад

Savant Web Server stores user credentials in plaintext in the Savant\Users registry key, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-45rm-2893-5f49

больше 3 лет назад

liquidjs may leak properties of a prototype

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-45rj-x2cx-hfmx

11 месяцев назад

A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the argument product_code causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-45rj-f59r-4398

больше 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

EPSS: Низкий
github логотип

GHSA-45rj-9f26-3gf5

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully If it looks like there's another subframe in the A-MSDU but the header isn't fully there, we can end up reading data out of bounds, only to discard later. Make this a bit more careful and check if the subframe header can even be present.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-45rj-89w3-wrqm

больше 4 лет назад

Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0547, and CVE-2016-0548.

EPSS: Низкий
github логотип

GHSA-45rj-457p-57xq

больше 4 лет назад

111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by footer.php and certain other files.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-45rx-2jwx-cxfr

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-45rw-4r25-jvg7

Moodle Logged in users could view all calendar events

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45rv-q5wp-f6c4

There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby exploit this vulnerability. A successful exploitation of this vulnerability can compromise the device's data security and functional availability.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-45rv-3qw6-q326

Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-45rr-q6mf-fx4v

An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.

CVSS3: 8.8
12%
Средний
больше 4 лет назад
github логотип
GHSA-45rr-p56g-wc84

A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-45rr-gg9f-wfcm

An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-45rr-9gf8-j69p

An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is not checked, and is used for internal memory operations. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.

54%
Средний
больше 4 лет назад
github логотип
GHSA-45rr-9399-9pp6

A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the file /goform/exeCommand of the component HTTP Handler. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-45rq-wggf-p92p

Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45rq-hjm9-cgvx

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5543.

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-45rp-q25w-4426

pretix Stored Cross-site Scripting vulnerability

0%
Низкий
около 2 лет назад
github логотип
GHSA-45rp-9p97-h852

NocoDB Vulnerable to SQL Injection via DATEADD Formula

0%
Низкий
6 месяцев назад
github логотип
GHSA-45rp-8p4h-8m88

Savant Web Server stores user credentials in plaintext in the Savant\Users registry key, which allows local users to gain privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-45rm-2893-5f49

liquidjs may leak properties of a prototype

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-45rj-x2cx-hfmx

A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the argument product_code causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-45rj-f59r-4398

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45rj-9f26-3gf5

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: check A-MSDU format more carefully If it looks like there's another subframe in the A-MSDU but the header isn't fully there, we can end up reading data out of bounds, only to discard later. Make this a bit more careful and check if the subframe header can even be present.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-45rj-89w3-wrqm

Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0547, and CVE-2016-0548.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-45rj-457p-57xq

111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by footer.php and certain other files.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу