Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 385

Количество 362 385

github логотип

GHSA-3hmq-5gjv-x3xg

больше 2 лет назад

In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3hmp-qggx-jm2c

около 3 лет назад

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3hmp-mj77-wcxf

больше 4 лет назад

In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hmp-hq97-xvfh

больше 1 года назад

Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts allows Object Injection. This issue affects Crafts & Arts: from n/a through 2.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hmp-fwjp-mm5f

больше 4 лет назад

Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

EPSS: Низкий
github логотип

GHSA-3hmm-fj7j-6c8j

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a (1) GET parameter, (2) POST parameter, or (3) Referer HTTP header.

EPSS: Низкий
github логотип

GHSA-3hmm-67m3-g4fx

8 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3hmm-5fqm-mg46

около 3 лет назад

emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hmm-3q3p-7x72

7 месяцев назад

ASDA-Soft Stack-based Buffer Overflow Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hmj-jp49-3cjx

больше 3 лет назад

The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3hmh-pp49-r9jr

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hmg-xvx8-wwj4

около 1 года назад

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as problematic. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument Host leads to open redirect. The attack may be initiated remotely. Upgrading to version 1.0.2 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3hmg-j35p-w2ww

больше 4 лет назад

TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hmg-cm34-vrf6

почти 3 года назад

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hmg-5j42-p3q3

больше 4 лет назад

A CWE-538: File and Directory Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to pack or unpack the archive with the firmware for the controller and modules using the usual tar archiver resulting in an information exposure.

EPSS: Низкий
github логотип

GHSA-3hmf-fwjp-fj3m

больше 4 лет назад

Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable information disclosure via local access.

EPSS: Низкий
github логотип

GHSA-3hmc-px3x-2cjr

около 2 месяцев назад

A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to access live video streams.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hmc-jxr7-rw7j

почти 3 года назад

The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hmc-2fvj-7wmx

больше 4 лет назад

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3hmc-2cg9-g3wx

15 дней назад

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hmq-5gjv-x3xg

In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hmp-qggx-jm2c

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVSS3: 7.2
3%
Низкий
около 3 лет назад
github логотип
GHSA-3hmp-mj77-wcxf

In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmp-hq97-xvfh

Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts allows Object Injection. This issue affects Crafts & Arts: from n/a through 2.5.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3hmp-fwjp-mm5f

Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmm-fj7j-6c8j

Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a (1) GET parameter, (2) POST parameter, or (3) Referer HTTP header.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmm-67m3-g4fx

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

8 месяцев назад
github логотип
GHSA-3hmm-5fqm-mg46

emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-3hmm-3q3p-7x72

ASDA-Soft Stack-based Buffer Overflow Vulnerability

CVSS3: 7.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-3hmj-jp49-3cjx

The Watu Quiz WordPress plugin before 3.3.8.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hmh-pp49-r9jr

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmg-xvx8-wwj4

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as problematic. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument Host leads to open redirect. The attack may be initiated remotely. Upgrading to version 1.0.2 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3hmg-j35p-w2ww

TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmg-cm34-vrf6

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3hmg-5j42-p3q3

A CWE-538: File and Directory Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to pack or unpack the archive with the firmware for the controller and modules using the usual tar archiver resulting in an information exposure.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmf-fwjp-fj3m

Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable information disclosure via local access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmc-px3x-2cjr

A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to access live video streams.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3hmc-jxr7-rw7j

The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3hmc-2fvj-7wmx

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting from 14.6.0 before 14.6.4, all versions starting from 14.7.0 before 14.7.1. GitLab was not correctly handling bulk requests to delete existing packages from the package registries which could result in a Denial of Service under specific conditions.

CVSS3: 4.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hmc-2cg9-g3wx

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.

CVSS3: 4.8
0%
Низкий
15 дней назад

Уязвимостей на страницу