Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-2h6c-j3gf-xp9r

больше 3 лет назад

IPFS go-bitfield vulnerable to DoS via malformed size arguments

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2h6c-9r57-fm42

около 4 лет назад

Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.

EPSS: Низкий
github логотип

GHSA-2h6c-6jr9-g2xg

около 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-2h69-pcrh-6qpw

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: net: macb: properly unregister fixed rate clocks The additional resources allocated with clk_register_fixed_rate() need to be released with clk_unregister_fixed_rate(), otherwise they are lost.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h68-mcf3-8qvh

около 4 лет назад

Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.

EPSS: Низкий
github логотип

GHSA-2h68-7p8g-777r

около 4 лет назад

cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.

EPSS: Высокий
github логотип

GHSA-2h68-4vmh-prhj

около 4 лет назад

A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2h67-7cm6-5mr3

около 4 лет назад

Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.

EPSS: Низкий
github логотип

GHSA-2h67-2jh9-2x74

около 4 лет назад

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsc” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2h66-xfr5-9c8f

около 3 лет назад

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password attack. Recommended fix: Upgrade to a supported product such as Alerton ACM.] Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. 

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2h66-v8cx-v4cx

около 4 лет назад

Cross-site scripting (XSS) vulnerability in modules/search/search.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the search parameter to search.html.

EPSS: Низкий
github логотип

GHSA-2h66-4jhv-36vf

4 месяца назад

A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h65-mqr6-9fm5

больше 1 года назад

The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd' parameters in all versions up to, and including, 1.17.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2h65-jhhf-3h5q

около 4 лет назад

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.36 and 5.0.14 allows remote attackers to affect availability via unknown vectors related to Core.

EPSS: Низкий
github логотип

GHSA-2h65-97g8-x647

4 месяца назад

SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2h65-8rvg-gmc7

больше 2 лет назад

In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01128524; Issue ID: MOLY01128524 (MSV-846).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h64-rqxh-72wj

больше 2 лет назад

Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in footer_info parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2h64-c999-c9r6

3 месяца назад

SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE

EPSS: Низкий
github логотип

GHSA-2h64-4pg7-rq8p

4 месяца назад

Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2h63-r9g4-jvhv

3 месяца назад

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h6c-j3gf-xp9r

IPFS go-bitfield vulnerable to DoS via malformed size arguments

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2h6c-9r57-fm42

Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2h6c-6jr9-g2xg

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

около 1 года назад
github логотип
GHSA-2h69-pcrh-6qpw

In the Linux kernel, the following vulnerability has been resolved: net: macb: properly unregister fixed rate clocks The additional resources allocated with clk_register_fixed_rate() need to be released with clk_unregister_fixed_rate(), otherwise they are lost.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2h68-mcf3-8qvh

Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2h68-7p8g-777r

cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.

74%
Высокий
около 4 лет назад
github логотип
GHSA-2h68-4vmh-prhj

A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2h67-7cm6-5mr3

Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2h67-2jh9-2x74

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsc” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2h66-xfr5-9c8f

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password attack. Recommended fix: Upgrade to a supported product such as Alerton ACM.] Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. 

CVSS3: 8.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-2h66-v8cx-v4cx

Cross-site scripting (XSS) vulnerability in modules/search/search.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the search parameter to search.html.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2h66-4jhv-36vf

A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2h65-mqr6-9fm5

The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd' parameters in all versions up to, and including, 1.17.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h65-jhhf-3h5q

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.36 and 5.0.14 allows remote attackers to affect availability via unknown vectors related to Core.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2h65-97g8-x647

SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.

CVSS3: 2.7
0%
Низкий
4 месяца назад
github логотип
GHSA-2h65-8rvg-gmc7

In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01128524; Issue ID: MOLY01128524 (MSV-846).

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2h64-rqxh-72wj

Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in footer_info parameter.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2h64-c999-c9r6

SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE

1%
Низкий
3 месяца назад
github логотип
GHSA-2h64-4pg7-rq8p

Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 8.8
4 месяца назад
github логотип
GHSA-2h63-r9g4-jvhv

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.

CVSS3: 7.5
1%
Низкий
3 месяца назад

Уязвимостей на страницу