Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35fr-hhpx-vpg2

больше 1 года назад

Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-35fr-h7jr-hh86

больше 6 лет назад

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') in Armeria

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35fr-79wv-f9r8

около 4 лет назад

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35fq-rqch-cg5p

около 4 лет назад

Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation of certain privilege, the attacker could trick the user into installing a malicious application before the user turns on student mode function. Successful exploit could allow the attacker to bypass the limit of student mode function.

EPSS: Низкий
github логотип

GHSA-35fp-phpv-hrqw

больше 4 лет назад

Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35fp-m999-3h79

6 месяцев назад

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35fp-g4mv-5w6v

10 месяцев назад

Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35fp-65cr-47q7

больше 4 лет назад

The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-35fm-pgcc-7jwh

больше 4 лет назад

The DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a filename with shell metacharacters.

EPSS: Низкий
github логотип

GHSA-35fm-c34x-gh5w

около 3 лет назад

A vulnerability, which was classified as problematic, was found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/add-category.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235245 was assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-35fm-4q2r-j938

больше 4 лет назад

A vulnerability has been identified in SINEC NMS (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an unintended sphere of control. This could allow an authenticated low privileged user to achieve privilege escalation.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-35fj-h53g-7cqv

около 4 лет назад

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

CVSS3: 2.3
EPSS: Низкий
github логотип

GHSA-35fh-vqwm-xx6m

около 4 лет назад

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server.

EPSS: Низкий
github логотип

GHSA-35fh-m76w-53g4

9 месяцев назад

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing a user to update the user role through the $user->set_role() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35fh-hcwr-mcv6

около 4 лет назад

Windows Kernel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34508.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-35fg-hjcr-j65f

больше 4 лет назад

Information exposure in xwiki-platform

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-35fg-2f67-63x2

10 месяцев назад

A vulnerability was determined in code-projects Web-Based Inventory and POS System 1.0. This impacts an unknown function of the file /login.php. Executing manipulation of the argument emailid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-35ff-rw37-67v2

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boopathi Rajan WP Test Email wp-test-email allows Reflected XSS.This issue affects WP Test Email: from n/a through <= 1.1.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35ff-c49r-m93w

больше 1 года назад

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /orders/view_order.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-35fc-9hrj-3585

больше 1 года назад

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35fr-hhpx-vpg2

Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-35fr-h7jr-hh86

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') in Armeria

CVSS3: 6.5
больше 6 лет назад
github логотип
GHSA-35fr-79wv-f9r8

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-35fq-rqch-cg5p

Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation of certain privilege, the attacker could trick the user into installing a malicious application before the user turns on student mode function. Successful exploit could allow the attacker to bypass the limit of student mode function.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35fp-phpv-hrqw

Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35fp-m999-3h79

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-35fp-g4mv-5w6v

Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-35fp-65cr-47q7

The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique

CVSS3: 9.8
22%
Средний
больше 4 лет назад
github логотип
GHSA-35fm-pgcc-7jwh

The DownloadLoop function in main.c for greed 0.81p allows remote attackers to execute arbitrary code via a GRX file containing a filename with shell metacharacters.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-35fm-c34x-gh5w

A vulnerability, which was classified as problematic, was found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/add-category.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235245 was assigned to this vulnerability.

CVSS3: 3.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-35fm-4q2r-j938

A vulnerability has been identified in SINEC NMS (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an unintended sphere of control. This could allow an authenticated low privileged user to achieve privilege escalation.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35fj-h53g-7cqv

In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.

CVSS3: 2.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-35fh-vqwm-xx6m

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35fh-m76w-53g4

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing a user to update the user role through the $user->set_role() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-35fh-hcwr-mcv6

Windows Kernel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34508.

CVSS3: 9.9
3%
Низкий
около 4 лет назад
github логотип
GHSA-35fg-hjcr-j65f

Information exposure in xwiki-platform

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35fg-2f67-63x2

A vulnerability was determined in code-projects Web-Based Inventory and POS System 1.0. This impacts an unknown function of the file /login.php. Executing manipulation of the argument emailid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVSS3: 7.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-35ff-rw37-67v2

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boopathi Rajan WP Test Email wp-test-email allows Reflected XSS.This issue affects WP Test Email: from n/a through <= 1.1.7.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-35ff-c49r-m93w

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /orders/view_order.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-35fc-9hrj-3585

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

CVSS3: 6.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу