Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43f5-xw85-rggm

больше 4 лет назад

In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-156997193

EPSS: Низкий
github логотип

GHSA-43f5-6jwp-r376

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-43f4-p64j-vrmg

больше 4 лет назад

A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb95951. Known Affected Releases: 12.0(0.99999.2). Known Fixed Releases: 11.0(1.23064.1) 11.5(1.12031.1) 11.5(1.12900.21) 11.5(1.12900.7) 11.5(1.12900.8) 11.6(1.10000.4) 12.0(0.98000.155) 12.0(0.98000.178) 12.0(0.98000.366) 12.0(0.98000.367) 12.0(0.98000.468) 12.0(0.98000.469) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43f4-4889-775c

больше 4 лет назад

DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43f3-h63w-p6f6

почти 2 года назад

Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43f3-c74j-pqxh

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to inject arbitrary web script or HTML via the DisplayFormat parameter.

EPSS: Низкий
github логотип

GHSA-43f2-jmwh-r66h

10 месяцев назад

Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin-login allows Identity Spoofing.This issue affects All In One Login: from n/a through <= 2.0.8.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-43f2-7v5v-7h6m

больше 1 года назад

Missing Authorization vulnerability in Aleksandar Urošević Stock Ticker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Ticker: from n/a through 3.23.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43f2-6v99-hw83

больше 4 лет назад

SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a "the_search_text" action to wp-admin/admin-ajax.php.

EPSS: Низкий
github логотип

GHSA-43cx-jhp3-2qcr

больше 4 лет назад

A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43cw-wcf7-w8fv

больше 4 лет назад

An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 15.4 and iPadOS 15.4. An app may be able to learn information about the current camera view before being granted camera access.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-43cv-jpm2-7rcc

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: uacce: implement mremap in uacce_vm_ops to return -EPERM The current uacce_vm_ops does not support the mremap operation of vm_operations_struct. Implement .mremap to return -EPERM to remind users. The reason we need to explicitly disable mremap is that when the driver does not implement .mremap, it uses the default mremap method. This could lead to a risk scenario: An application might first mmap address p1, then mremap to p2, followed by munmap(p1), and finally munmap(p2). Since the default mremap copies the original vma's vm_private_data (i.e., q) to the new vma, both munmap operations would trigger vma_close, causing q->qfr to be freed twice(qfr will be set to null here, so repeated release is ok).

EPSS: Низкий
github логотип

GHSA-43cv-3rg5-mpgp

больше 4 лет назад

In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local escalation of privilege by creating fake system notifications with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143339775

EPSS: Низкий
github логотип

GHSA-43cr-v8vv-86x6

больше 1 года назад

libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43cq-wxv7-9c4w

больше 2 лет назад

The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43cq-c2gq-pfpw

2 месяца назад

Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check

EPSS: Низкий
github логотип

GHSA-43cp-h386-xgfv

10 месяцев назад

Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials.  This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4. Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43cp-6p3q-2pc4

почти 3 года назад

HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-43cm-mrxj-qjr8

около 1 месяца назад

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-43cm-g4rg-jr2r

больше 2 лет назад

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43f5-xw85-rggm

In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-156997193

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43f5-6jwp-r376

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43f4-p64j-vrmg

A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb95951. Known Affected Releases: 12.0(0.99999.2). Known Fixed Releases: 11.0(1.23064.1) 11.5(1.12031.1) 11.5(1.12900.21) 11.5(1.12900.7) 11.5(1.12900.8) 11.6(1.10000.4) 12.0(0.98000.155) 12.0(0.98000.178) 12.0(0.98000.366) 12.0(0.98000.367) 12.0(0.98000.468) 12.0(0.98000.469) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.98500.6).

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43f4-4889-775c

DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43f3-h63w-p6f6

Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-43f3-c74j-pqxh

Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to inject arbitrary web script or HTML via the DisplayFormat parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43f2-jmwh-r66h

Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin-login allows Identity Spoofing.This issue affects All In One Login: from n/a through <= 2.0.8.

CVSS3: 9.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-43f2-7v5v-7h6m

Missing Authorization vulnerability in Aleksandar Urošević Stock Ticker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Ticker: from n/a through 3.23.0.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-43f2-6v99-hw83

SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a "the_search_text" action to wp-admin/admin-ajax.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43cx-jhp3-2qcr

A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-43cw-wcf7-w8fv

An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 15.4 and iPadOS 15.4. An app may be able to learn information about the current camera view before being granted camera access.

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-43cv-jpm2-7rcc

In the Linux kernel, the following vulnerability has been resolved: uacce: implement mremap in uacce_vm_ops to return -EPERM The current uacce_vm_ops does not support the mremap operation of vm_operations_struct. Implement .mremap to return -EPERM to remind users. The reason we need to explicitly disable mremap is that when the driver does not implement .mremap, it uses the default mremap method. This could lead to a risk scenario: An application might first mmap address p1, then mremap to p2, followed by munmap(p1), and finally munmap(p2). Since the default mremap copies the original vma's vm_private_data (i.e., q) to the new vma, both munmap operations would trigger vma_close, causing q->qfr to be freed twice(qfr will be set to null here, so repeated release is ok).

0%
Низкий
7 месяцев назад
github логотип
GHSA-43cv-3rg5-mpgp

In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local escalation of privilege by creating fake system notifications with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143339775

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43cr-v8vv-86x6

libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-43cq-wxv7-9c4w

The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-43cq-c2gq-pfpw

Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check

0%
Низкий
2 месяца назад
github логотип
GHSA-43cp-h386-xgfv

Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials.  This issue affects WAX610: before 10.8.11.4; WAX610Y: before 10.8.11.4. Devices managed with Insight get automatic updates. If not, please check the firmware version and update to the latest. Fixed in: WAX610 firmware 11.8.0.10 or later. WAX610Y firmware 11.8.0.10 or later.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-43cp-6p3q-2pc4

HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-43cm-mrxj-qjr8

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-43cm-g4rg-jr2r

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу