Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 867

Количество 364 867

github логотип

GHSA-3r7q-94c4-jm45

12 месяцев назад

A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions. This vulnerability was fixed in 9.0.20.100 and above.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r7q-4x75-jgjm

7 месяцев назад

A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Load of the file YZSoft/Forms/XForm/BM/BusComManagement/TireMng.aspx. Executing a manipulation of the argument key can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3r7q-27vw-j482

больше 4 лет назад

The successsecrets (aka com.alek.successsecrets) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3r7p-5g7m-j435

больше 4 лет назад

Integer overflow in wxBitcoin and bitcoind before 0.3.11 allows remote attackers to bypass intended economic restrictions and create many bitcoins via a crafted Bitcoin transaction.

EPSS: Низкий
github логотип

GHSA-3r7m-q5px-rp76

больше 4 лет назад

The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to AssetService.scala.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3r7m-hxcx-w9m7

почти 3 года назад

Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3r7j-8mqh-6qhx

почти 4 года назад

Jadx-gui vulnerable to swing HTML Denial of Service (DoS) attack

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3r7h-wxv5-qw3v

больше 4 лет назад

A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.

EPSS: Низкий
github логотип

GHSA-3r7g-xhpj-j87w

больше 4 лет назад

The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token without the need for correct password to gain access to the mobile application as that victim user.

EPSS: Низкий
github логотип

GHSA-3r7g-wrpr-j5g4

больше 4 лет назад

Improper Authentication in django-mfa3

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3r7g-q6cg-q2vx

26 дней назад

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r7g-gjfg-fgpr

2 месяца назад

Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract sensitive database information.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3r7g-67q5-53gf

2 месяца назад

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3r7c-wgmw-38g7

больше 3 лет назад

Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r7c-cf5v-4v53

больше 4 лет назад

OX App Suite 7.10.1 and 7.10.2 allows SSRF.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3r7c-93gc-73gw

больше 4 лет назад

Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r79-62f7-6gcx

около 1 года назад

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators. Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server.

EPSS: Низкий
github логотип

GHSA-3r78-rqg8-95gg

5 месяцев назад

Duplicate Advisory: OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r77-w9f5-q8q6

больше 4 лет назад

Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to execute arbitrary code via unspecified vectors to the (1) PrintSiteImage, (2) PlaySiteAllChannel, (3) StopSiteAllChannel, or (4) SaveSiteImage function.

EPSS: Средний
github логотип

GHSA-3r77-vxv8-f245

больше 4 лет назад

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to cause a denial of service condition or to execute arbitrary code. The vulnerability is due to improper boundary restrictions on user-supplied input in the Guest user feature of the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device, triggering a buffer overflow condition. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a denial of service condition, or could allow the attacker to execute arbitrary code.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3r7q-94c4-jm45

A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions. This vulnerability was fixed in 9.0.20.100 and above.

CVSS3: 8.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-3r7q-4x75-jgjm

A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Load of the file YZSoft/Forms/XForm/BM/BusComManagement/TireMng.aspx. Executing a manipulation of the argument key can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3r7q-27vw-j482

The successsecrets (aka com.alek.successsecrets) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3r7p-5g7m-j435

Integer overflow in wxBitcoin and bitcoind before 0.3.11 allows remote attackers to bypass intended economic restrictions and create many bitcoins via a crafted Bitcoin transaction.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3r7m-q5px-rp76

The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to AssetService.scala.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3r7m-hxcx-w9m7

Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.

CVSS3: 9.8
2%
Низкий
почти 3 года назад
github логотип
GHSA-3r7j-8mqh-6qhx

Jadx-gui vulnerable to swing HTML Denial of Service (DoS) attack

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3r7h-wxv5-qw3v

A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3r7g-xhpj-j87w

The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration, an attacker is able to forge a User specific token without the need for correct password to gain access to the mobile application as that victim user.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3r7g-wrpr-j5g4

Improper Authentication in django-mfa3

CVSS3: 7.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3r7g-q6cg-q2vx

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

CVSS3: 6.5
0%
Низкий
26 дней назад
github логотип
GHSA-3r7g-gjfg-fgpr

Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract sensitive database information.

CVSS3: 8.2
0%
Низкий
2 месяца назад
github логотип
GHSA-3r7g-67q5-53gf

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-3r7c-wgmw-38g7

Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3r7c-cf5v-4v53

OX App Suite 7.10.1 and 7.10.2 allows SSRF.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3r7c-93gc-73gw

Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3r79-62f7-6gcx

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators. Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server.

10%
Низкий
около 1 года назад
github логотип
GHSA-3r78-rqg8-95gg

Duplicate Advisory: OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse

CVSS3: 6.5
5 месяцев назад
github логотип
GHSA-3r77-w9f5-q8q6

Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to execute arbitrary code via unspecified vectors to the (1) PrintSiteImage, (2) PlaySiteAllChannel, (3) StopSiteAllChannel, or (4) SaveSiteImage function.

14%
Средний
больше 4 лет назад
github логотип
GHSA-3r77-vxv8-f245

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to cause a denial of service condition or to execute arbitrary code. The vulnerability is due to improper boundary restrictions on user-supplied input in the Guest user feature of the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device, triggering a buffer overflow condition. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a denial of service condition, or could allow the attacker to execute arbitrary code.

CVSS3: 8.1
6%
Низкий
больше 4 лет назад

Уязвимостей на страницу