Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2jp3-fvm5-pq7w

около 4 лет назад

niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2jp3-2vfh-535w

больше 1 года назад

Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS allows Privilege Escalation.This issue affects WPLMS: from n/a through 1.9.9.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jp3-2923-9h52

3 месяца назад

Apache ActiveMQ Vulnerable to Cross-site Scripting

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2jp2-fm6f-4vgc

больше 4 лет назад

SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

EPSS: Низкий
github логотип

GHSA-2jp2-c8rx-5w8j

больше 4 лет назад

Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.

EPSS: Средний
github логотип

GHSA-2jp2-4gcw-39mv

больше 1 года назад

Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2jp2-2mm5-5h78

2 месяца назад

A flaw has been found in Edimax BR-6675nD 1.12. Affected by this issue is the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Executing a manipulation of the argument pptpUserName can lead to buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jmx-42pw-22v9

около 2 месяцев назад

Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2jmw-7gh4-3h48

около 4 лет назад

In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-2jmv-xwch-pcqf

10 месяцев назад

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2jmv-v5xf-w928

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Beautique beautique allows PHP Local File Inclusion.This issue affects Beautique: from n/a through <= 1.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2jmv-v2x6-mmv8

около 4 лет назад

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.

EPSS: Низкий
github логотип

GHSA-2jmv-57qj-jwg6

около 4 лет назад

Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season bans and SR losses for other users) by leaving a competitive match at a specific time during the initial loading of that match.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2jmv-336w-9f9w

около 4 лет назад

The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2jmr-h5mm-35ff

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.

EPSS: Низкий
github логотип

GHSA-2jmq-v535-vr5r

больше 1 года назад

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. This affects an unknown part of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2jmq-pwpx-v2pq

8 месяцев назад

Akamai Guardicore Platform Agent before 52.1.1 allows an unprivileged user to fully elevate privileges to SYSTEM. This affects versions before 50.15.0, 51.12.0, and 52.1.1.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2jmq-6fx4-r49q

11 месяцев назад

EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its HTTP interface. When processing a GET request to list.html, the server fails to properly validate the length of the path parameter. Supplying an excessively long value causes a buffer overflow on the stack, potentially corrupting control flow structures. The vulnerability is exposed through the embedded web server and does not require authentication due to default anonymous access. The issue was resolved in version 1.7.0.12, after which the product was renamed to UplusFtp.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jmj-6ff4-3p3w

около 4 лет назад

The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target device is configured giving permission for the gateway device to act on its behalf. This means an authenticated device of a certain tenant, notably also a non-gateway device acting like a gateway, may receive command & control messages targeted at a different device of the same tenant without corresponding permissions getting checked.

EPSS: Низкий
github логотип

GHSA-2jmg-wxp9-5qfc

почти 3 года назад

All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jp3-fvm5-pq7w

niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks.

CVSS3: 7.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jp3-2vfh-535w

Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS allows Privilege Escalation.This issue affects WPLMS: from n/a through 1.9.9.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2jp3-2923-9h52

Apache ActiveMQ Vulnerable to Cross-site Scripting

CVSS3: 6.5
1%
Низкий
3 месяца назад
github логотип
GHSA-2jp2-fm6f-4vgc

SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2jp2-c8rx-5w8j

Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.

20%
Средний
больше 4 лет назад
github логотип
GHSA-2jp2-4gcw-39mv

Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jp2-2mm5-5h78

A flaw has been found in Edimax BR-6675nD 1.12. Affected by this issue is the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Executing a manipulation of the argument pptpUserName can lead to buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
2 месяца назад
github логотип
GHSA-2jmx-42pw-22v9

Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2jmw-7gh4-3h48

In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.

CVSS3: 8.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jmv-xwch-pcqf

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

CVSS3: 8.2
1%
Низкий
10 месяцев назад
github логотип
GHSA-2jmv-v5xf-w928

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Beautique beautique allows PHP Local File Inclusion.This issue affects Beautique: from n/a through <= 1.5.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-2jmv-v2x6-mmv8

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.

8%
Низкий
около 4 лет назад
github логотип
GHSA-2jmv-57qj-jwg6

Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season bans and SR losses for other users) by leaving a competitive match at a specific time during the initial loading of that match.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jmv-336w-9f9w

The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2jmr-h5mm-35ff

Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2jmq-v535-vr5r

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. This affects an unknown part of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2jmq-pwpx-v2pq

Akamai Guardicore Platform Agent before 52.1.1 allows an unprivileged user to fully elevate privileges to SYSTEM. This affects versions before 50.15.0, 51.12.0, and 52.1.1.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2jmq-6fx4-r49q

EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its HTTP interface. When processing a GET request to list.html, the server fails to properly validate the length of the path parameter. Supplying an excessively long value causes a buffer overflow on the stack, potentially corrupting control flow structures. The vulnerability is exposed through the embedded web server and does not require authentication due to default anonymous access. The issue was resolved in version 1.7.0.12, after which the product was renamed to UplusFtp.

CVSS3: 9.8
2%
Низкий
11 месяцев назад
github логотип
GHSA-2jmj-6ff4-3p3w

The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device. The missing check involves verifying that the command target device is configured giving permission for the gateway device to act on its behalf. This means an authenticated device of a certain tenant, notably also a non-gateway device acting like a gateway, may receive command & control messages targeted at a different device of the same tenant without corresponding permissions getting checked.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2jmg-wxp9-5qfc

All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.

CVSS3: 8.1
1%
Низкий
почти 3 года назад

Уязвимостей на страницу