Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2f4r-34m4-3w8q

около 1 года назад

Auth0 Wordpress plugin Vulnerable to Brute Force Authentication Tags of CookieStore Sessions

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2f4q-xh8v-r37w

около 1 года назад

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2f4q-m35h-pw25

около 4 лет назад

Buffer overflow in the server in OpenTTD 0.6.1 and earlier allows remote authenticated users to cause a denial of service (persistent game disruption) or possibly execute arbitrary code via vectors involving many long names for "companies and clients."

EPSS: Низкий
github логотип

GHSA-2f4q-fp76-vh93

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the vAlign property of a TimeField. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6482.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2f4q-74mc-vp6m

около 4 лет назад

RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.

EPSS: Низкий
github логотип

GHSA-2f4p-w49c-4q77

8 месяцев назад

An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2f4p-m737-x9wf

больше 3 лет назад

D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2f4p-j5v8-cq58

11 месяцев назад

The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_authors' shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2f4p-44cq-2pg5

около 4 лет назад

The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-2f4m-v4jj-hpx5

10 дней назад

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2f4m-q55c-v3xr

около 1 месяца назад

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2f4j-c232-x8x2

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-2f4j-64mc-h8m2

около 4 лет назад

The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects Firefox ESR < 52.3 and Firefox < 55.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2f4j-4fwc-f6fp

около 4 лет назад

An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

EPSS: Низкий
github логотип

GHSA-2f4h-rvr5-mcmc

около 4 лет назад

Open redirect vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2f4g-8m4c-65fm

почти 4 года назад

The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2f4g-6hfh-2v64

7 месяцев назад

VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security for PC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from incorrect permissions on a folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27147.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2f4f-h5m8-27v8

около 3 лет назад

A vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown code of the component ZIP Package Handler. The manipulation of the argument dir leads to information disclosure. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-231502 is the identifier assigned to this vulnerability.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2f4f-67fq-rw74

больше 3 лет назад

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMService component.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2f4c-vrjq-rcgv

5 месяцев назад

WeKnora has Broken Access Control - Cross-Tenant Data Exposure

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2f4r-34m4-3w8q

Auth0 Wordpress plugin Vulnerable to Brute Force Authentication Tags of CookieStore Sessions

CVSS3: 9.1
около 1 года назад
github логотип
GHSA-2f4q-xh8v-r37w

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-2f4q-m35h-pw25

Buffer overflow in the server in OpenTTD 0.6.1 and earlier allows remote authenticated users to cause a denial of service (persistent game disruption) or possibly execute arbitrary code via vectors involving many long names for "companies and clients."

5%
Низкий
около 4 лет назад
github логотип
GHSA-2f4q-fp76-vh93

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the vAlign property of a TimeField. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6482.

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2f4q-74mc-vp6m

RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2f4p-w49c-4q77

An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2f4p-m737-x9wf

D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2f4p-j5v8-cq58

The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_authors' shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-2f4p-44cq-2pg5

The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2f4m-v4jj-hpx5

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).

CVSS3: 7.7
0%
Низкий
10 дней назад
github логотип
GHSA-2f4m-q55c-v3xr

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2f4j-c232-x8x2

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

больше 1 года назад
github логотип
GHSA-2f4j-64mc-h8m2

The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects Firefox ESR < 52.3 and Firefox < 55.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2f4j-4fwc-f6fp

An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

4%
Низкий
около 4 лет назад
github логотип
GHSA-2f4h-rvr5-mcmc

Open redirect vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2f4g-8m4c-65fm

The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2f4g-6hfh-2v64

VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security for PC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from incorrect permissions on a folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27147.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-2f4f-h5m8-27v8

A vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown code of the component ZIP Package Handler. The manipulation of the argument dir leads to information disclosure. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-231502 is the identifier assigned to this vulnerability.

CVSS3: 3.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-2f4f-67fq-rw74

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMService component.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2f4c-vrjq-rcgv

WeKnora has Broken Access Control - Cross-Tenant Data Exposure

CVSS3: 7.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу