Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 060

Количество 365 060

github логотип

GHSA-3v49-pp4c-p3j5

почти 2 года назад

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device. This vulnerability is due to a lack of authentication on specific HTTP endpoints. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow the attacker to view or delete the configuration or change the firmware.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3v49-j6p7-86pc

почти 4 года назад

An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3v49-f236-jv89

около 4 лет назад

The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v49-5224-w9p6

больше 4 лет назад

Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.

EPSS: Низкий
github логотип

GHSA-3v49-2fcm-3rcj

12 дней назад

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3v49-294p-4c7w

больше 2 лет назад

The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the admin panel. Also vulnerable to account takeover and arbitrary password change.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v48-283x-f2w4

около 1 года назад

File Browser's password protection of links is bypassable

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3v47-mwg3-xvq2

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: stop hash:* range iteration at end The following hash set variants: hash:ip,mark hash:ip,port hash:ip,port,ip hash:ip,port,net iterate IPv4 ranges with a 32-bit iterator. The iterator must stop once the last address in the requested range has been processed. Advancing it once more can move the traversal state past the end of the request, so a later retry may continue from an unintended position. Handle the iterator increment explicitly at the end of the loop and stop once the upper bound has been processed. This keeps the existing retry behaviour intact for valid ranges while preventing traversal from continuing past the original boundary.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v46-4j7g-63ff

14 дней назад

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. A remote attacker may be able to cause unexpected system termination.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v46-43qj-3vpg

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3v45-w9r6-863p

больше 4 лет назад

SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v45-f3vh-wg7m

2 месяца назад

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

EPSS: Низкий
github логотип

GHSA-3v44-m29v-5rc5

больше 4 лет назад

Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.

EPSS: Низкий
github логотип

GHSA-3v44-382q-55f4

больше 7 лет назад

Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v44-23hf-q5wp

почти 2 года назад

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3v43-hgv9-g7jj

больше 2 лет назад

A vulnerability classified as critical was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function fromqossetting of the file /goform/fromqossetting. The manipulation of the argument qos leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260911. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v43-8vv8-27j2

около 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeFlavors Vimeotheque: Vimeo WordPress Plugin <= 2.2.1 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3v43-877x-qgmq

почти 7 лет назад

Moderate severity vulnerability that affects league/commonmark

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3v42-qjhq-4fjh

больше 4 лет назад

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3135 and CVE-2015-4432.

EPSS: Средний
github логотип

GHSA-3v3x-mvj6-m5jc

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v49-pp4c-p3j5

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device. This vulnerability is due to a lack of authentication on specific HTTP endpoints. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow the attacker to view or delete the configuration or change the firmware.

CVSS3: 8.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-3v49-j6p7-86pc

An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-3v49-f236-jv89

The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3v49-5224-w9p6

Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3v49-2fcm-3rcj

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

CVSS3: 9.1
1%
Низкий
12 дней назад
github логотип
GHSA-3v49-294p-4c7w

The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the admin panel. Also vulnerable to account takeover and arbitrary password change.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3v48-283x-f2w4

File Browser's password protection of links is bypassable

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3v47-mwg3-xvq2

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: stop hash:* range iteration at end The following hash set variants: hash:ip,mark hash:ip,port hash:ip,port,ip hash:ip,port,net iterate IPv4 ranges with a 32-bit iterator. The iterator must stop once the last address in the requested range has been processed. Advancing it once more can move the traversal state past the end of the request, so a later retry may continue from an unintended position. Handle the iterator increment explicitly at the end of the loop and stop once the upper bound has been processed. This keeps the existing retry behaviour intact for valid ranges while preventing traversal from continuing past the original boundary.

CVSS3: 5.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3v46-4j7g-63ff

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. A remote attacker may be able to cause unexpected system termination.

CVSS3: 7.5
0%
Низкий
14 дней назад
github логотип
GHSA-3v46-43qj-3vpg

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3v45-w9r6-863p

SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3v45-f3vh-wg7m

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

0%
Низкий
2 месяца назад
github логотип
GHSA-3v44-m29v-5rc5

Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v44-382q-55f4

Moderate severity vulnerability that affects org.apache.hadoop:hadoop-main

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
github логотип
GHSA-3v44-23hf-q5wp

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3v43-hgv9-g7jj

A vulnerability classified as critical was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function fromqossetting of the file /goform/fromqossetting. The manipulation of the argument qos leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260911. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3v43-8vv8-27j2

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeFlavors Vimeotheque: Vimeo WordPress Plugin <= 2.2.1 versions.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3v43-877x-qgmq

Moderate severity vulnerability that affects league/commonmark

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
github логотип
GHSA-3v42-qjhq-4fjh

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3135 and CVE-2015-4432.

28%
Средний
больше 4 лет назад
github логотип
GHSA-3v3x-mvj6-m5jc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported.

CVSS3: 9.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу