Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-xr44-7hqv-mrgr

8 месяцев назад

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr44-2pv4-gw8r

больше 2 лет назад

SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xr43-rqjg-v94q

около 4 лет назад

The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafted SIP message that is not properly handled during processing of an XML document, aka Bug ID CSCtq76428.

EPSS: Низкий
github логотип

GHSA-xr43-cwp6-p6wf

почти 2 года назад

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xr42-288c-hwmj

около 4 лет назад

WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1153 and CVE-2015-1154.

EPSS: Низкий
github логотип

GHSA-xr3x-xv96-4f83

больше 2 лет назад

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr3x-pg7w-4w2p

около 4 лет назад

Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remote attackers to execute arbitrary programs via an encrypted command.

EPSS: Низкий
github логотип

GHSA-xr3x-fw3p-85fp

около 4 лет назад

IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131769.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr3x-62qw-vc4w

около 4 лет назад

Grafana stored XSS

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr3x-3m9h-jg3r

9 месяцев назад

Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr3w-rmvj-f6m7

10 месяцев назад

Mattermost has an Observable Timing Discrepancy vulnerability

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xr3w-fg6m-256q

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.

EPSS: Низкий
github логотип

GHSA-xr3w-8pvj-85f8

больше 4 лет назад

Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable expansion such as tilde expansion for the HOME environment variable, and (3) a long -f (aka reffile) command line argument.

EPSS: Низкий
github логотип

GHSA-xr3w-885c-4x3x

почти 4 года назад

Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xr3v-r79c-636q

около 4 лет назад

In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System privileges required. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-69808833.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xr3v-q79w-54x4

почти 3 года назад

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processing an image may result in disclosure of process memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr3v-856v-p7jm

12 месяцев назад

A security flaw has been discovered in oitcode samarium up to 0.9.6. This vulnerability affects unknown code of the file /cms/webpage/ of the component Pages Image Handler. The manipulation results in cross site scripting. The attack may be performed from a remote location. The exploit has been released to the public and may be exploited.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-xr3r-h3qr-pm77

около 4 лет назад

An SQL injection vulnerability exists in the Alias.asmx Web Service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Parameter OrigID in Alias.asmx is vulnerable to unauthenticated SQL injection attacks An attacker can send unauthenticated HTTP requests to trigger this vulnerability.

EPSS: Низкий
github логотип

GHSA-xr3q-grc8-j3mx

больше 1 года назад

PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xr3q-3pcr-52mg

около 4 лет назад

SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr44-7hqv-mrgr

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xr44-2pv4-gw8r

SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xr43-rqjg-v94q

The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafted SIP message that is not properly handled during processing of an XML document, aka Bug ID CSCtq76428.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xr43-cwp6-p6wf

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

CVSS3: 4.9
1%
Низкий
почти 2 года назад
github логотип
GHSA-xr42-288c-hwmj

WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1153 and CVE-2015-1154.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xr3x-xv96-4f83

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters

CVSS3: 8.8
3%
Низкий
больше 2 лет назад
github логотип
GHSA-xr3x-pg7w-4w2p

Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remote attackers to execute arbitrary programs via an encrypted command.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xr3x-fw3p-85fp

IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131769.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr3x-62qw-vc4w

Grafana stored XSS

CVSS3: 5.4
10%
Низкий
около 4 лет назад
github логотип
GHSA-xr3x-3m9h-jg3r

Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xr3w-rmvj-f6m7

Mattermost has an Observable Timing Discrepancy vulnerability

CVSS3: 3.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-xr3w-fg6m-256q

Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-xr3w-8pvj-85f8

Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable expansion such as tilde expansion for the HOME environment variable, and (3) a long -f (aka reffile) command line argument.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xr3w-885c-4x3x

Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr3v-r79c-636q

In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System privileges required. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-69808833.

CVSS3: 6.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-xr3v-q79w-54x4

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processing an image may result in disclosure of process memory.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xr3v-856v-p7jm

A security flaw has been discovered in oitcode samarium up to 0.9.6. This vulnerability affects unknown code of the file /cms/webpage/ of the component Pages Image Handler. The manipulation results in cross site scripting. The attack may be performed from a remote location. The exploit has been released to the public and may be exploited.

CVSS3: 2.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-xr3r-h3qr-pm77

An SQL injection vulnerability exists in the Alias.asmx Web Service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Parameter OrigID in Alias.asmx is vulnerable to unauthenticated SQL injection attacks An attacker can send unauthenticated HTTP requests to trigger this vulnerability.

около 4 лет назад
github логотип
GHSA-xr3q-grc8-j3mx

PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xr3q-3pcr-52mg

SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.

CVSS3: 9.8
2%
Низкий
около 4 лет назад

Уязвимостей на страницу