Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 342 247

Количество 342 247

github логотип

GHSA-2fxc-vhrx-cqc7

больше 4 лет назад

Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2fxc-8v96-j5f3

4 месяца назад

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.

EPSS: Низкий
github логотип

GHSA-2fx9-jj4f-fr73

больше 4 лет назад

Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to a subset of Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-2fx9-2g54-566x

больше 4 лет назад

Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, which causes a tight loop.

EPSS: Низкий
github логотип

GHSA-2fx8-gx73-p72f

больше 4 лет назад

DirectX Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2fx8-69v9-25f6

больше 4 лет назад

A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fx8-5w8c-86ff

почти 2 года назад

The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fx7-q8g7-wxwg

9 месяцев назад

The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to retrieve the output of phpinfo().

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2fx7-mf6r-pff9

больше 2 лет назад

A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fx7-3mgv-p2gp

больше 2 лет назад

A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258034 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2fx6-wf22-3rf5

больше 4 лет назад

The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fx6-r6qx-3c7h

больше 4 лет назад

Path Traversal in Apache Oozie

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fx6-86r8-c487

больше 4 лет назад

Prima Systems FlexAir devices have Hard-coded Credentials.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fx6-2pm7-cwvm

почти 3 года назад

Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2fx5-pggv-6jjr

больше 1 года назад

TYPO3 Potential Open Redirect via Parsing Differences

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2fx4-vwf2-pw99

6 месяцев назад

A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2fx4-qxwh-34x6

больше 4 лет назад

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2fx4-8cc3-3383

около 4 лет назад

In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fx4-27pj-8f74

больше 4 лет назад

ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.

EPSS: Средний
github логотип

GHSA-2fx2-v8hh-86v7

больше 4 лет назад

Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fxc-vhrx-cqc7

Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2fxc-8v96-j5f3

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.

0%
Низкий
4 месяца назад
github логотип
GHSA-2fx9-jj4f-fr73

Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to a subset of Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2fx9-2g54-566x

Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, which causes a tight loop.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2fx8-gx73-p72f

DirectX Elevation of Privilege Vulnerability

CVSS3: 7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2fx8-69v9-25f6

A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2fx8-5w8c-86ff

The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2fx7-q8g7-wxwg

The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to retrieve the output of phpinfo().

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-2fx7-mf6r-pff9

A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2fx7-3mgv-p2gp

A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258034 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2fx6-wf22-3rf5

The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2fx6-r6qx-3c7h

Path Traversal in Apache Oozie

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2fx6-86r8-c487

Prima Systems FlexAir devices have Hard-coded Credentials.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2fx6-2pm7-cwvm

Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-2fx5-pggv-6jjr

TYPO3 Potential Open Redirect via Parsing Differences

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fx4-vwf2-pw99

A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.

CVSS3: 6.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-2fx4-qxwh-34x6

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2fx4-8cc3-3383

In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2fx4-27pj-8f74

ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.

13%
Средний
больше 4 лет назад
github логотип
GHSA-2fx2-v8hh-86v7

Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу