Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-2qp6-v7mh-v798

7 месяцев назад

SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2qp6-q6vf-5x4c

около 4 лет назад

Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.

EPSS: Низкий
github логотип

GHSA-2qp5-wv2r-fqw5

больше 4 лет назад

SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

EPSS: Низкий
github логотип

GHSA-2qp5-r5hx-q27p

около 1 месяца назад

Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication.  An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can later replay the same pair of transmissions repeatedly. During testing, replaying the first captured transmission caused the RKES to enter a state in which replaying the second captured transmission resulted in a successful lock or unlock operation of the vehicle. Tested and confirmed on a 2024 Suzuki Swift (SWIFT ISG GLS AC 1.2 5P 4x2 TM).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2qp5-r446-qvgh

около 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.

EPSS: Низкий
github логотип

GHSA-2qp5-3jc8-pprj

почти 3 года назад

An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the configuration of any already-registered agent so that all future agent communications are sent to an attacker-chosen URL. An attacker must first successfully obtain valid agent credentials and target agent hostname. All versions prior to 7.14.3.69 are affected.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qp4-xpm8-6jmq

больше 4 лет назад

TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

EPSS: Низкий
github логотип

GHSA-2qp4-x94h-6q6w

почти 3 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themesgrove Onepage Builder allows SQL Injection.This issue affects Onepage Builder: from n/a through 2.4.1.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2qp4-wwrv-gf4c

около 4 лет назад

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.

EPSS: Низкий
github логотип

GHSA-2qp4-g3q3-f92w

больше 4 лет назад

Improper Locking in JetBrains Kotlin

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2qp4-532r-wmc3

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) change workflows or (2) insert cross-site scripting (XSS) sequences.

EPSS: Низкий
github логотип

GHSA-2qp2-pf59-94fr

около 4 лет назад

socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor consumption) via multiple request that are refused based on the (1) sourceport, (2) lowport, (3) range, or (4) tcpwrap restrictions.

EPSS: Низкий
github логотип

GHSA-2qp2-6frj-p9pq

28 дней назад

Duplicate Advisory: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qmx-rjgf-q7p7

около 4 лет назад

In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of these artifacts could have been MITM to maliciously compromise them and infect the build artifacts that were produced. Additionally, if any of these JARs or other dependencies were compromised, any developers using these could continue to be infected past updating to fix this.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2qmx-2jj7-w7qw

около 4 лет назад

The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qmw-pvf7-4mw6

около 2 лет назад

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qmw-g869-r668

9 месяцев назад

Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.

EPSS: Низкий
github логотип

GHSA-2qmw-f5m7-5vh7

около 1 месяца назад

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2qmw-465m-g262

около 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.

EPSS: Низкий
github логотип

GHSA-2qmv-ph7p-fh64

около 4 лет назад

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user permissions on the table through formdata[wdt_ID] parameter. By exploiting this issue an attacker is able to access and manage the data of all users in the same table.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2qp6-v7mh-v798

SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2qp6-q6vf-5x4c

Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2qp5-wv2r-fqw5

SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2qp5-r5hx-q27p

Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication.  An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can later replay the same pair of transmissions repeatedly. During testing, replaying the first captured transmission caused the RKES to enter a state in which replaying the second captured transmission resulted in a successful lock or unlock operation of the vehicle. Tested and confirmed on a 2024 Suzuki Swift (SWIFT ISG GLS AC 1.2 5P 4x2 TM).

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2qp5-r446-qvgh

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2qp5-3jc8-pprj

An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the configuration of any already-registered agent so that all future agent communications are sent to an attacker-chosen URL. An attacker must first successfully obtain valid agent credentials and target agent hostname. All versions prior to 7.14.3.69 are affected.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2qp4-xpm8-6jmq

TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2qp4-x94h-6q6w

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themesgrove Onepage Builder allows SQL Injection.This issue affects Onepage Builder: from n/a through 2.4.1.

CVSS3: 7.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-2qp4-wwrv-gf4c

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2qp4-g3q3-f92w

Improper Locking in JetBrains Kotlin

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2qp4-532r-wmc3

Multiple cross-site request forgery (CSRF) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) change workflows or (2) insert cross-site scripting (XSS) sequences.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qp2-pf59-94fr

socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor consumption) via multiple request that are refused based on the (1) sourceport, (2) lowport, (3) range, or (4) tcpwrap restrictions.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2qp2-6frj-p9pq

Duplicate Advisory: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

CVSS3: 8.8
28 дней назад
github логотип
GHSA-2qmx-rjgf-q7p7

In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of these artifacts could have been MITM to maliciously compromise them and infect the build artifacts that were produced. Additionally, if any of these JARs or other dependencies were compromised, any developers using these could continue to be infected past updating to fix this.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qmx-2jj7-w7qw

The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2qmw-pvf7-4mw6

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2qmw-g869-r668

Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.

0%
Низкий
9 месяцев назад
github логотип
GHSA-2qmw-f5m7-5vh7

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

CVSS3: 8.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2qmw-465m-g262

An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2qmv-ph7p-fh64

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user permissions on the table through formdata[wdt_ID] parameter. By exploiting this issue an attacker is able to access and manage the data of all users in the same table.

CVSS3: 8.1
1%
Низкий
около 4 лет назад

Уязвимостей на страницу