Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2mw5-m74c-gphm

около 4 лет назад

Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by uploading a PHP file as an Avatar, then accessing the avatar via a direct request.

EPSS: Низкий
github логотип

GHSA-2mw5-5xxw-vv7j

почти 2 года назад

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mw4-wj8c-7f93

почти 3 года назад

Eclipse Glassfish remote code execution issue

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2mw4-5fh2-j3wh

около 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mw3-cgxq-9prq

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through <= 5.5.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mw3-7xc5-vcfm

около 2 месяцев назад

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass. This issue affects QR Menu: from s1.05.07 before v1.05.12.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2mw3-4c3p-vv6p

почти 3 года назад

Harman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project name.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2mw2-pgcq-48mv

больше 2 лет назад

Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the list1 parameter from fromDhcpListClient function.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-2mw2-m8pw-m382

около 4 лет назад

An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0742, CVE-2020-0749, CVE-2020-0750.

EPSS: Низкий
github логотип

GHSA-2mw2-gj79-mjf4

9 месяцев назад

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to cause unexpected system termination.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mvx-m58q-vfmv

больше 1 года назад

A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component GLOB Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2mvx-f5qm-v2ch

4 месяца назад

Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog in My Calendar

EPSS: Низкий
github логотип

GHSA-2mvw-xxr6-2f56

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Frontend Dashboard allows Stored XSS. This issue affects Frontend Dashboard: from n/a through 2.2.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mvw-r55c-8x68

24 дня назад

Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.

EPSS: Низкий
github логотип

GHSA-2mvw-r265-49q6

13 дней назад

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2mvw-pgf2-gf3j

около 4 лет назад

SQL injection vulnerability in the Yet Another Calendar (ke_yac) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2mvw-cmvf-9wp4

больше 1 года назад

The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2mvv-v998-h3gj

5 месяцев назад

HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information disclosure.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2mvr-x656-xc89

около 4 лет назад

Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to sys_reboot.html. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-2mvr-v67w-f6vh

около 4 лет назад

An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. A local-privilege-escalation race condition in pbx_exchange can occur when a local user connects to a socket before permissions are secured.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mw5-m74c-gphm

Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by uploading a PHP file as an Avatar, then accessing the avatar via a direct request.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2mw5-5xxw-vv7j

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2mw4-wj8c-7f93

Eclipse Glassfish remote code execution issue

CVSS3: 6.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-2mw4-5fh2-j3wh

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4. It was possible to exploit a stored cross-site-scripting in merge request via a specifically crafted branch name.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mw3-cgxq-9prq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through <= 5.5.0.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2mw3-7xc5-vcfm

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass. This issue affects QR Menu: from s1.05.07 before v1.05.12.

CVSS3: 8.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2mw3-4c3p-vv6p

Harman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project name.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2mw2-pgcq-48mv

Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the list1 parameter from fromDhcpListClient function.

CVSS3: 5.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2mw2-m8pw-m382

An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0741, CVE-2020-0742, CVE-2020-0749, CVE-2020-0750.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mw2-gj79-mjf4

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to cause unexpected system termination.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2mvx-m58q-vfmv

A vulnerability was found in PCMan FTP Server up to 2.0.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component GLOB Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2mvx-f5qm-v2ch

Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog in My Calendar

1%
Низкий
4 месяца назад
github логотип
GHSA-2mvw-xxr6-2f56

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Frontend Dashboard allows Stored XSS. This issue affects Frontend Dashboard: from n/a through 2.2.8.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2mvw-r55c-8x68

Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.

0%
Низкий
24 дня назад
github логотип
GHSA-2mvw-r265-49q6

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.3
0%
Низкий
13 дней назад
github логотип
GHSA-2mvw-pgf2-gf3j

SQL injection vulnerability in the Yet Another Calendar (ke_yac) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mvw-cmvf-9wp4

The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2mvv-v998-h3gj

HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information disclosure.

CVSS3: 3.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2mvr-x656-xc89

Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to sys_reboot.html. NOTE: some of these details are obtained from third party information.

12%
Средний
около 4 лет назад
github логотип
GHSA-2mvr-v67w-f6vh

An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. A local-privilege-escalation race condition in pbx_exchange can occur when a local user connects to a socket before permissions are secured.

CVSS3: 7
0%
Низкий
около 4 лет назад

Уязвимостей на страницу