Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 087

Количество 366 087

github логотип

GHSA-3xxr-vfgj-3gw3

около 4 лет назад

In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3xxr-729f-x6v9

больше 4 лет назад

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3xxp-88xx-wwq3

24 дня назад

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3xxp-73wf-27cp

около 4 лет назад

DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3xxm-pww7-gf82

больше 4 лет назад

In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-124524315

EPSS: Низкий
github логотип

GHSA-3xxm-cx7p-m4p6

больше 4 лет назад

joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3xxm-3g3c-w579

почти 3 года назад

Moodle Code Injection vulnerability

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3xxj-wpwj-gxhm

больше 4 лет назад

An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xxj-rv47-9w5r

6 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Chroma chroma allows PHP Local File Inclusion.This issue affects Chroma: from n/a through <= 1.11.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3xxj-rfjr-w6h5

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3xxj-pcr2-rvh7

больше 4 лет назад

NULL Pointer Dereference in Homebrew mruby prior to 3.2.

EPSS: Низкий
github логотип

GHSA-3xxh-w577-324m

больше 3 лет назад

The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3xxh-hm67-x74r

около 1 месяца назад

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3xxh-2rc7-7mx7

больше 4 лет назад

SQL injection vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3xxg-cfxh-f9rh

больше 4 лет назад

** DISPUTED ** Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem.

EPSS: Низкий
github логотип

GHSA-3xxg-9vrr-9g96

около 2 лет назад

Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3xxf-f9pw-rwm5

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3xxf-776r-vvm4

около 3 лет назад

In executeSetClientTarget of ComposerCommandEngine.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-252764410

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3xxc-v62h-9qfv

больше 4 лет назад

run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands.

EPSS: Низкий
github логотип

GHSA-3xxc-pwj6-jgrj

5 месяцев назад

rfc3161-client Has Improper Certificate Validation

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3xxr-vfgj-3gw3

In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-3xxr-729f-x6v9

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xxp-88xx-wwq3

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
1%
Низкий
24 дня назад
github логотип
GHSA-3xxp-73wf-27cp

DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3xxm-pww7-gf82

In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-124524315

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3xxm-cx7p-m4p6

joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xxm-3g3c-w579

Moodle Code Injection vulnerability

CVSS3: 4.7
2%
Низкий
почти 3 года назад
github логотип
GHSA-3xxj-wpwj-gxhm

An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xxj-rv47-9w5r

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Chroma chroma allows PHP Local File Inclusion.This issue affects Chroma: from n/a through <= 1.11.

CVSS3: 8.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-3xxj-rfjr-w6h5

Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3xxj-pcr2-rvh7

NULL Pointer Dereference in Homebrew mruby prior to 3.2.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xxh-w577-324m

The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3xxh-hm67-x74r

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3xxh-2rc7-7mx7

SQL injection vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xxg-cfxh-f9rh

** DISPUTED ** Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3xxg-9vrr-9g96

Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.

CVSS3: 8.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3xxf-f9pw-rwm5

In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3xxf-776r-vvm4

In executeSetClientTarget of ComposerCommandEngine.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-252764410

CVSS3: 4.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-3xxc-v62h-9qfv

run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3xxc-pwj6-jgrj

rfc3161-client Has Improper Certificate Validation

CVSS3: 6.2
0%
Низкий
5 месяцев назад

Уязвимостей на страницу