Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-3rq3-733w-v2c4

10 дней назад

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who knows only the victim's password can therefore authenticate, mint a persistent app-scoped app_admin API key that remains valid after the aal1 session is logged out, and perform privileged operations su...

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3rq3-6pw2-f97f

больше 1 года назад

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3rq2-j576-xv9r

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Error Handling). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-3rq2-6mpq-54m8

больше 4 лет назад

The link-log plugin before 2.1 for WordPress has SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rq2-3cgx-j4rh

больше 4 лет назад

Heap-based buffer overflow in the get_answer function in mmsh.c in libmms before 0.6.4 allows remote attackers to execute arbitrary code via a long line in an MMS over HTTP (MMSH) server response.

EPSS: Низкий
github логотип

GHSA-3rpx-pgmf-j96h

почти 3 года назад

Microweber Business Logic Errors

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3rpw-c8rg-p3f5

почти 2 года назад

Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive than what the write privilege intends.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3rpv-j58g-7jfj

больше 2 лет назад

ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3rpr-mg43-xhq4

больше 8 лет назад

auth0-js Privilege Escalation Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rpr-jfwv-ch87

больше 4 лет назад

Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka CORE-1149.

EPSS: Низкий
github логотип

GHSA-3rpr-7wjf-f32w

5 дней назад

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rpq-hq8j-r42p

почти 3 года назад

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3rpq-2xpx-53c4

больше 4 лет назад

Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3rpp-wj27-m2p9

больше 4 лет назад

Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3rpp-4v39-5h22

больше 4 лет назад

Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-3rpm-wgqm-r264

больше 4 лет назад

Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.

EPSS: Низкий
github логотип

GHSA-3rpm-h4f9-j349

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG.This issue affects TinyPNG: from n/a through 3.4.3.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rpm-6p6h-45fh

почти 4 года назад

Windows Resilient File System Elevation of Privilege.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rpm-2rjq-r29f

больше 4 лет назад

Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.

EPSS: Низкий
github логотип

GHSA-3rpj-mvwg-494q

больше 4 лет назад

The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rq3-733w-v2c4

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who knows only the victim's password can therefore authenticate, mint a persistent app-scoped app_admin API key that remains valid after the aal1 session is logged out, and perform privileged operations su...

CVSS3: 8.3
0%
Низкий
10 дней назад
github логотип
GHSA-3rq3-6pw2-f97f

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3rq2-j576-xv9r

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Error Handling). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rq2-6mpq-54m8

The link-log plugin before 2.1 for WordPress has SQL injection.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rq2-3cgx-j4rh

Heap-based buffer overflow in the get_answer function in mmsh.c in libmms before 0.6.4 allows remote attackers to execute arbitrary code via a long line in an MMS over HTTP (MMSH) server response.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3rpx-pgmf-j96h

Microweber Business Logic Errors

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-3rpw-c8rg-p3f5

Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive than what the write privilege intends.

CVSS3: 7.2
2%
Низкий
почти 2 года назад
github логотип
GHSA-3rpv-j58g-7jfj

ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.

CVSS3: 8.3
5%
Низкий
больше 2 лет назад
github логотип
GHSA-3rpr-mg43-xhq4

auth0-js Privilege Escalation Vulnerability

CVSS3: 7.5
1%
Низкий
больше 8 лет назад
github логотип
GHSA-3rpr-jfwv-ch87

Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka CORE-1149.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rpr-7wjf-f32w

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.

CVSS3: 8.8
0%
Низкий
5 дней назад
github логотип
GHSA-3rpq-hq8j-r42p

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 3.3
2%
Низкий
почти 3 года назад
github логотип
GHSA-3rpq-2xpx-53c4

Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rpp-wj27-m2p9

Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rpp-4v39-5h22

Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rpm-wgqm-r264

Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rpm-h4f9-j349

Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG.This issue affects TinyPNG: from n/a through 3.4.3.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3rpm-6p6h-45fh

Windows Resilient File System Elevation of Privilege.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-3rpm-2rjq-r29f

Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rpj-mvwg-494q

The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу