Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2mxp-xv42-39jh

около 4 лет назад

The MeiPai (aka com.meitu.meipaimv) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2mxp-83cx-hqmp

около 4 лет назад

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mxm-mhxp-766x

около 4 лет назад

Adobe Experience Manager versions 6.5, 6.4 and 6.3 have a cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mxm-4g25-p6w9

около 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Management.

EPSS: Низкий
github логотип

GHSA-2mxm-3cxj-6cmp

больше 1 года назад

Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager Advanced Edition: from 4.8.0.0 through 4.8.7.0102, 4.9.0.0.

EPSS: Низкий
github логотип

GHSA-2mxm-357j-92vr

8 месяцев назад

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.1, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2mxj-rgg6-f45q

около 3 лет назад

A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8), Teamcenter Visualization V14.2 (All versions < V14.2.0.3). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted CGM files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2mxj-r96x-vpcm

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts Syzbot reported an slab-out-of-bounds Read in thrustmaster_probe() bug. The root case is in missing validation check of actual number of endpoints. Code should not blindly access usb_host_interface::endpoint array, since it may contain less endpoints than code expects. Fix it by adding missing validaion check and print an error if number of endpoints do not match expected number

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2mxj-pg8q-6c2c

около 4 лет назад

The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue

EPSS: Низкий
github логотип

GHSA-2mxj-3ggv-wm2c

3 месяца назад

A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the attack remotely.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2mxh-xfhw-gmr5

около 4 лет назад

Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.

EPSS: Низкий
github логотип

GHSA-2mxh-w2fv-g692

около 4 лет назад

In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mxh-qvf4-48jc

около 3 лет назад

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2mxh-qrpv-mfvx

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: mctp: i2c: fix skb memory leak in receive path When 'midev->allow_rx' is false, the newly allocated skb isn't consumed by netif_rx(), it needs to free the skb directly.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mxh-j9g4-gj85

почти 2 года назад

Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mxg-rvhc-jqf9

около 4 лет назад

A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by gaining access to the static credential that is stored on the local device. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.

EPSS: Низкий
github логотип

GHSA-2mxg-q6g7-4jvg

около 4 лет назад

The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mxg-7m2h-mvgg

больше 4 лет назад

Banex PHP MySQL Banner Exchange 2.21 stores lib.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as database usernames and passwords.

EPSS: Низкий
github логотип

GHSA-2mxg-3cqh-524j

около 4 лет назад

Cross-site scripting (XSS) vulnerability in SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to inject arbitrary web script or HTML via the ServiceClass field to the Edit Service Parameters page.

EPSS: Низкий
github логотип

GHSA-2mxf-g57h-fggq

около 3 лет назад

In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mxp-xv42-39jh

The MeiPai (aka com.meitu.meipaimv) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2mxp-83cx-hqmp

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mxm-mhxp-766x

Adobe Experience Manager versions 6.5, 6.4 and 6.3 have a cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mxm-4g25-p6w9

Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Management.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mxm-3cxj-6cmp

Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager Advanced Edition: from 4.8.0.0 through 4.8.7.0102, 4.9.0.0.

0%
Низкий
больше 1 года назад
github логотип
GHSA-2mxm-357j-92vr

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.1, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests

CVSS3: 7.2
0%
Низкий
8 месяцев назад
github логотип
GHSA-2mxj-rgg6-f45q

A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8), Teamcenter Visualization V14.2 (All versions < V14.2.0.3). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted CGM files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2mxj-r96x-vpcm

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts Syzbot reported an slab-out-of-bounds Read in thrustmaster_probe() bug. The root case is in missing validation check of actual number of endpoints. Code should not blindly access usb_host_interface::endpoint array, since it may contain less endpoints than code expects. Fix it by adding missing validaion check and print an error if number of endpoints do not match expected number

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2mxj-pg8q-6c2c

The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mxj-3ggv-wm2c

A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the attack remotely.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2mxh-xfhw-gmr5

Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mxh-w2fv-g692

In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mxh-qvf4-48jc

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)

CVSS3: 7.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-2mxh-qrpv-mfvx

In the Linux kernel, the following vulnerability has been resolved: mctp: i2c: fix skb memory leak in receive path When 'midev->allow_rx' is false, the newly allocated skb isn't consumed by netif_rx(), it needs to free the skb directly.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2mxh-j9g4-gj85

Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2mxg-rvhc-jqf9

A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by gaining access to the static credential that is stored on the local device. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2mxg-q6g7-4jvg

The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mxg-7m2h-mvgg

Banex PHP MySQL Banner Exchange 2.21 stores lib.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as database usernames and passwords.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mxg-3cqh-524j

Cross-site scripting (XSS) vulnerability in SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to inject arbitrary web script or HTML via the ServiceClass field to the Edit Service Parameters page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mxf-g57h-fggq

In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

CVSS3: 5.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу