Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2mr8-vgrf-mcf6

около 4 лет назад

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data prior to performing further free operations on an object when parsing BMP files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13060)

EPSS: Низкий
github логотип

GHSA-2mr6-xpjw-3h35

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.

EPSS: Низкий
github логотип

GHSA-2mr5-pjm8-xqxj

почти 3 года назад

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "add_white_node,"

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mr4-jwhc-j589

около 2 лет назад

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2mr4-c9g2-mv44

около 4 лет назад

Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers to bypass local security protection via a crafted HTTP post packet.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-2mr4-86fw-5c9r

около 4 лет назад

Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET ENVIRONMENT statement.

EPSS: Низкий
github логотип

GHSA-2mr4-2f9p-76x9

больше 4 лет назад

SQL injection vulnerability in the A21glossary Advanced Output (a21glossary_advanced_output) extension before 0.1.12 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2mr3-pj2m-q569

9 месяцев назад

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts. CVE-2024-13995 addresses a similar vulnerability with a potentially incomplete fix for the underlying problem in earlier versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mr3-m5q5-wgp6

5 месяцев назад

Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mr3-j246-x7x3

около 1 года назад

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2mr3-f6h2-pxx4

около 3 лет назад

In swpm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID: ALPS07780926.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2mr3-36qv-4rmf

около 2 лет назад

There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can pass a limited length script to be run by another administrator. The scope is unchanged, there is no loss of confidentiality. Impact to system integrity is high, impact to system availability is none.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-2mr2-h34m-mpr7

около 1 года назад

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could cause user-controlled code to run with administrator privilege.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mqx-xpw9-6crj

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1017.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mqx-vr27-49pv

около 4 лет назад

Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300 V200R005C32; SRG2300 V200R005C32; SRG3300 V200R005C32 have an out-of-bounds write vulnerability. When a user executes a query command after the device received an abnormal OSPF message, the software writes data past the end of the intended buffer due to the insufficient verification of the input data. An unauthenticated, remote attacker could exploit this vulnerability by sending abnormal OSPF messages to the device. A successful exploit could cause the system to crash.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mqx-pp9v-pgr6

около 4 лет назад

Use-after-free vulnerability in the GPU process in Google Chrome before 10.0.648.205 allows remote attackers to execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2mqw-xvh5-rv38

больше 1 года назад

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embedai/chats/send_message".

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-2mqw-rq5m-8hc8

больше 1 года назад

Snowflake.Data has weak temporary files permissions

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2mqw-gxvv-6qrc

около 4 лет назад

E6878-370 versions 10.0.3.1(H557SP27C233),10.0.3.1(H563SP21C233) and E6878-870 versions 10.0.3.1(H557SP27C233),10.0.3.1(H563SP11C233) have a denial of service vulnerability. The system does not properly check some events, an attacker could launch the events continually, successful exploit could cause reboot of the process.

EPSS: Низкий
github логотип

GHSA-2mqv-mwvq-mv8h

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in jazzigor price-calc allows Stored XSS. This issue affects price-calc: from n/a through 0.6.3.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mr8-vgrf-mcf6

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data prior to performing further free operations on an object when parsing BMP files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13060)

2%
Низкий
около 4 лет назад
github логотип
GHSA-2mr6-xpjw-3h35

Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2mr5-pjm8-xqxj

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "add_white_node,"

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-2mr4-jwhc-j589

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-2mr4-c9g2-mv44

Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers to bypass local security protection via a crafted HTTP post packet.

CVSS3: 10
4%
Низкий
около 4 лет назад
github логотип
GHSA-2mr4-86fw-5c9r

Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET ENVIRONMENT statement.

5%
Низкий
около 4 лет назад
github логотип
GHSA-2mr4-2f9p-76x9

SQL injection vulnerability in the A21glossary Advanced Output (a21glossary_advanced_output) extension before 0.1.12 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mr3-pj2m-q569

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts. CVE-2024-13995 addresses a similar vulnerability with a potentially incomplete fix for the underlying problem in earlier versions.

CVSS3: 6.5
1%
Низкий
9 месяцев назад
github логотип
GHSA-2mr3-m5q5-wgp6

Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2mr3-j246-x7x3

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.

CVSS3: 9.8
24%
Средний
около 1 года назад
github логотип
GHSA-2mr3-f6h2-pxx4

In swpm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID: ALPS07780926.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-2mr3-36qv-4rmf

There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can pass a limited length script to be run by another administrator. The scope is unchanged, there is no loss of confidentiality. Impact to system integrity is high, impact to system availability is none.

CVSS3: 4.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2mr2-h34m-mpr7

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could cause user-controlled code to run with administrator privilege.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2mqx-xpw9-6crj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1017.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2mqx-vr27-49pv

Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300 V200R005C32; SRG2300 V200R005C32; SRG3300 V200R005C32 have an out-of-bounds write vulnerability. When a user executes a query command after the device received an abnormal OSPF message, the software writes data past the end of the intended buffer due to the insufficient verification of the input data. An unauthenticated, remote attacker could exploit this vulnerability by sending abnormal OSPF messages to the device. A successful exploit could cause the system to crash.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mqx-pp9v-pgr6

Use-after-free vulnerability in the GPU process in Google Chrome before 10.0.648.205 allows remote attackers to execute arbitrary code via unknown vectors.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2mqw-xvh5-rv38

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embedai/chats/send_message".

CVSS3: 5.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2mqw-rq5m-8hc8

Snowflake.Data has weak temporary files permissions

CVSS3: 5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2mqw-gxvv-6qrc

E6878-370 versions 10.0.3.1(H557SP27C233),10.0.3.1(H563SP21C233) and E6878-870 versions 10.0.3.1(H557SP27C233),10.0.3.1(H563SP11C233) have a denial of service vulnerability. The system does not properly check some events, an attacker could launch the events continually, successful exploit could cause reboot of the process.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2mqv-mwvq-mv8h

Cross-Site Request Forgery (CSRF) vulnerability in jazzigor price-calc allows Stored XSS. This issue affects price-calc: from n/a through 0.6.3.

CVSS3: 7.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу