Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-3mj6-hq84-85g9

больше 2 лет назад

Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3mj6-3crj-6pcw

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3mj5-5ph7-ggjq

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter.

EPSS: Низкий
github логотип

GHSA-3mj4-w4vq-39pp

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3mj4-2258-cj4p

больше 4 лет назад

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root.

EPSS: Низкий
github логотип

GHSA-3mj3-396v-7f8p

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3mj2-f6g2-rqg9

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9640, SDM630, MSM8976, MSM8937, SDM845, MSM8976, and MSM8952, when running module or kernel code with improper access control allowing writing to arbitrary regions of memory, the user may utilize this vector to alter module executable code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mj2-6x39-pq7w

больше 4 лет назад

Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream in a PDF file.

EPSS: Низкий
github логотип

GHSA-3mhx-94rj-7j37

больше 4 лет назад

An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3mhx-4cwj-8prc

больше 4 лет назад

The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mhw-mxm8-w9rh

больше 4 лет назад

Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.

EPSS: Низкий
github логотип

GHSA-3mhw-f79r-crmm

больше 2 лет назад

An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mhv-6x8q-5v9p

почти 2 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor allows Upload a Web Shell to a Web Server.This issue affects Custom Icons for Elementor: from n/a through 0.3.3.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3mhr-hwm3-pcr6

6 месяцев назад

Missing Authorization vulnerability in lvaudore The Moneytizer the-moneytizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Moneytizer: from n/a through <= 10.0.10.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mhr-frr8-qmc6

больше 4 лет назад

A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. Cisco Bug IDs: CSCvh49388.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3mhr-8gcj-264p

больше 4 лет назад

Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.

EPSS: Низкий
github логотип

GHSA-3mhq-vj94-wvcw

больше 4 лет назад

The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mhq-jqrv-fc88

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page) has already progressed towards the end of allocation. It is incorrect to perform __free_pages(page, order) using this pointer as we would free any arbitrary pages. Fix this by stop modifying the page pointer.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mhq-gg8j-mxrw

больше 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mhq-7jvc-97g7

28 дней назад

The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the administrator moderation workflow.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mj6-hq84-85g9

Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mj6-3crj-6pcw

Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3mj5-5ph7-ggjq

Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj4-w4vq-39pp

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.

CVSS3: 3.1
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj4-2258-cj4p

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj3-396v-7f8p

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj2-f6g2-rqg9

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9640, SDM630, MSM8976, MSM8937, SDM845, MSM8976, and MSM8952, when running module or kernel code with improper access control allowing writing to arbitrary regions of memory, the user may utilize this vector to alter module executable code.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mj2-6x39-pq7w

Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream in a PDF file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhx-94rj-7j37

An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhx-4cwj-8prc

The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhw-mxm8-w9rh

Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhw-f79r-crmm

An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mhv-6x8q-5v9p

Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor allows Upload a Web Shell to a Web Server.This issue affects Custom Icons for Elementor: from n/a through 0.3.3.

CVSS3: 6.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3mhr-hwm3-pcr6

Missing Authorization vulnerability in lvaudore The Moneytizer the-moneytizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Moneytizer: from n/a through <= 10.0.10.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3mhr-frr8-qmc6

A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass configured policies. The vulnerability is due to incorrect management of the configured interface names and VPN parameters when dynamic CLI configuration changes are performed. An attacker could exploit this vulnerability by sending packets through an interface on the targeted device. A successful exploit could allow the attacker to bypass configured VPN policies. Cisco Bug IDs: CSCvh49388.

CVSS3: 5.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhr-8gcj-264p

Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhq-vj94-wvcw

The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mhq-jqrv-fc88

In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page) has already progressed towards the end of allocation. It is incorrect to perform __free_pages(page, order) using this pointer as we would free any arbitrary pages. Fix this by stop modifying the page pointer.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mhq-gg8j-mxrw

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3mhq-7jvc-97g7

The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the administrator moderation workflow.

CVSS3: 5.3
0%
Низкий
28 дней назад

Уязвимостей на страницу