Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-2pvr-f889-xjvm

больше 4 лет назад

Planet Technology Corp FGSW2402RS switch with firmware 1.2 has a default password, which allows attackers with physical access to the device's serial port to gain privileges.

EPSS: Низкий
github логотип

GHSA-2pvr-5mpx-gwv9

около 2 лет назад

The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_link_pages() function in all versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to inject arbitrary pages and malicious web scripts.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2pvq-xmrh-grxp

около 4 лет назад

A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system files and make restricted kernel calls. This access could be exploited by a local attacker to gain a root shell prompt using the right combination of environment variables and command line arguments.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2pvq-77pm-76c4

больше 2 лет назад

An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pvp-px52-q92c

около 4 лет назад

Untrusted search path vulnerability in Foxit Reader before 5.0.2.0718 allows local users to gain privileges via a Trojan horse dwmapi.dll, dwrite.dll, or msdrm.dll in the current working directory.

EPSS: Низкий
github логотип

GHSA-2pvm-v53r-33rw

около 4 лет назад

Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pvm-p3x6-gxvp

около 4 лет назад

An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of APM.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pvj-w2cg-rgwq

около 4 лет назад

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at STDUXPSFile!DllUnregisterServer+0x0000000000005af2."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pvj-p485-cp3m

почти 4 года назад

matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2pvj-859q-4v5p

около 4 лет назад

Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.

EPSS: Низкий
github логотип

GHSA-2pvj-5j7v-jjxj

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2pvh-xf99-r989

около 4 лет назад

In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and also facilitates exploitation of SQL injection errors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2pvh-rqjq-h9px

около 2 лет назад

naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pvh-447j-v7m6

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: spi: meson-spicc: Fix double-put in remove path meson_spicc_probe() registers the controller with devm_spi_register_controller(), so teardown already drops the controller reference via devm cleanup. Calling spi_controller_put() again in meson_spicc_remove() causes a double-put.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pvg-pmc4-vr2x

около 2 лет назад

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access confidential information. Exploitation of this issue does not require user interaction.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pvg-g56g-vcf2

6 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/CommentFormatter/CommentParser.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2pvg-9372-g3rh

4 месяца назад

A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. If you want to get the best quality for vulnerability data then you always have to consider VulDB.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2pvg-4x8f-qx36

больше 4 лет назад

kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.

EPSS: Низкий
github логотип

GHSA-2pvf-rfmw-cwjg

10 месяцев назад

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pvf-hwww-4v9q

около 4 лет назад

SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pvr-f889-xjvm

Planet Technology Corp FGSW2402RS switch with firmware 1.2 has a default password, which allows attackers with physical access to the device's serial port to gain privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2pvr-5mpx-gwv9

The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_link_pages() function in all versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to inject arbitrary pages and malicious web scripts.

CVSS3: 7.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-2pvq-xmrh-grxp

A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system files and make restricted kernel calls. This access could be exploited by a local attacker to gain a root shell prompt using the right combination of environment variables and command line arguments.

CVSS3: 6.7
5%
Низкий
около 4 лет назад
github логотип
GHSA-2pvq-77pm-76c4

An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2pvp-px52-q92c

Untrusted search path vulnerability in Foxit Reader before 5.0.2.0718 allows local users to gain privileges via a Trojan horse dwmapi.dll, dwrite.dll, or msdrm.dll in the current working directory.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2pvm-v53r-33rw

Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2pvm-p3x6-gxvp

An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of APM.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2pvj-w2cg-rgwq

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at STDUXPSFile!DllUnregisterServer+0x0000000000005af2."

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2pvj-p485-cp3m

matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2pvj-859q-4v5p

Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.

5%
Низкий
около 4 лет назад
github логотип
GHSA-2pvj-5j7v-jjxj

Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pvh-xf99-r989

In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and also facilitates exploitation of SQL injection errors.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2pvh-rqjq-h9px

naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-2pvh-447j-v7m6

In the Linux kernel, the following vulnerability has been resolved: spi: meson-spicc: Fix double-put in remove path meson_spicc_probe() registers the controller with devm_spi_register_controller(), so teardown already drops the controller reference via devm cleanup. Calling spi_controller_put() again in meson_spicc_remove() causes a double-put.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2pvg-pmc4-vr2x

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access confidential information. Exploitation of this issue does not require user interaction.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2pvg-g56g-vcf2

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/CommentFormatter/CommentParser.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-2pvg-9372-g3rh

A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. If you want to get the best quality for vulnerability data then you always have to consider VulDB.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2pvg-4x8f-qx36

kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2pvf-rfmw-cwjg

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.

CVSS3: 9.8
2%
Низкий
10 месяцев назад
github логотип
GHSA-2pvf-hwww-4v9q

SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges.

CVSS3: 8.8
1%
Низкий
около 4 лет назад

Уязвимостей на страницу