Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-2pw9-32q2-4pxm

около 2 лет назад

Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2pw8-r6j9-6vm6

около 4 лет назад

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

CVSS3: 6.1
EPSS: Критический
github логотип

GHSA-2pw8-phr9-8fj4

больше 3 лет назад

In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-241611867

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pw8-g87h-mhmj

около 4 лет назад

DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pw7-g86g-76q7

2 месяца назад

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2pw7-5gjq-98f6

10 месяцев назад

Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facilitate user enumeration and increase the likelihood of targeted brute-force or credential-stuffing attacks.

EPSS: Низкий
github логотип

GHSA-2pw7-4hp6-pq53

около 4 лет назад

Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2pw5-gqhj-5pj7

около 4 лет назад

The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pw5-cx79-f464

около 4 лет назад

Unrestricted file upload vulnerability in usercp.php in AlilG Application AliBoard Beta allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in uploads/avatars/.

EPSS: Низкий
github логотип

GHSA-2pw2-qpcp-m47x

около 4 лет назад

Silverstripe CMS XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2pw2-qmfv-w897

около 4 лет назад

The mintToken function of a smart contract implementation for ESH, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2pw2-q246-gg26

больше 4 лет назад

Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, as demonstrated by packets sent by nmap.

EPSS: Низкий
github логотип

GHSA-2pw2-g6vj-5cwh

около 4 лет назад

Google Chrome before 21.0.1180.89 does not properly perform line breaking, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.

EPSS: Низкий
github логотип

GHSA-2pvx-3x6v-8phh

больше 4 лет назад

Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFileSystem function in the File System (Standard) module (plugins/access.fs/class.fsAccessWrapper.php), or the (3) revision parameter to the Subversion Repository module (plugins/meta.svn/class.SvnManager.php).

EPSS: Низкий
github логотип

GHSA-2pvw-4fwr-jv5w

около 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2pvv-x6hx-hgmv

больше 1 года назад

Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pvv-q344-xvjh

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 5.9.15.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pvv-8r4m-4f4m

больше 4 лет назад

PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the website parameter.

EPSS: Низкий
github логотип

GHSA-2pvv-7qr9-h5rq

8 месяцев назад

This issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pvr-wf23-7pc7

около 2 месяцев назад

Astro: Host header SSRF in prerendered error page fetch

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pw9-32q2-4pxm

Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2pw8-r6j9-6vm6

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

CVSS3: 6.1
98%
Критический
около 4 лет назад
github логотип
GHSA-2pw8-phr9-8fj4

In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-241611867

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pw8-g87h-mhmj

DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pw7-g86g-76q7

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.

CVSS3: 8.2
0%
Низкий
2 месяца назад
github логотип
GHSA-2pw7-5gjq-98f6

Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facilitate user enumeration and increase the likelihood of targeted brute-force or credential-stuffing attacks.

1%
Низкий
10 месяцев назад
github логотип
GHSA-2pw7-4hp6-pq53

Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2pw5-gqhj-5pj7

The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pw5-cx79-f464

Unrestricted file upload vulnerability in usercp.php in AlilG Application AliBoard Beta allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in uploads/avatars/.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2pw2-qpcp-m47x

Silverstripe CMS XSS Vulnerability

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pw2-qmfv-w897

The mintToken function of a smart contract implementation for ESH, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pw2-q246-gg26

Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, as demonstrated by packets sent by nmap.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2pw2-g6vj-5cwh

Google Chrome before 21.0.1180.89 does not properly perform line breaking, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2pvx-3x6v-8phh

Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFileSystem function in the File System (Standard) module (plugins/access.fs/class.fsAccessWrapper.php), or the (3) revision parameter to the Subversion Repository module (plugins/meta.svn/class.SvnManager.php).

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2pvw-4fwr-jv5w

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2pvv-x6hx-hgmv

Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2pvv-q344-xvjh

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 5.9.15.

CVSS3: 6.5
около 2 лет назад
github логотип
GHSA-2pvv-8r4m-4f4m

PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the website parameter.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-2pvv-7qr9-h5rq

This issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2pvr-wf23-7pc7

Astro: Host header SSRF in prerendered error page fetch

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу