Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-2chj-cxxf-fqh6

8 месяцев назад

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2chj-59j8-h2vv

около 4 лет назад

Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attackers to execute arbitrary code via a long first argument to the CreateStill method.

EPSS: Средний
github логотип

GHSA-2chj-3cfx-vf64

около 4 лет назад

The _bfd_vms_slurp_egsd function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an arbitrary memory read via a crafted vms alpha file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2chh-r2hc-8q2g

около 1 года назад

Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-2chh-qcxj-m24m

около 4 лет назад

Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2chh-fcwm-p667

4 месяца назад

Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2chh-8jf9-q8fm

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-2chg-mq5v-5gqp

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berg Informatik Stripe Donation allows Stored XSS.This issue affects Stripe Donation: from n/a through 1.2.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2chg-86hq-7w38

больше 3 лет назад

btcd mishandles witness size checking

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2chg-78hj-c2w2

3 месяца назад

A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_organisation of the file superagi/controllers/project.py. The manipulation results in authorization bypass. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2chf-w4v5-vmmg

больше 3 лет назад

Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2ch9-gmhf-h625

около 2 лет назад

CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2ch9-6m9h-xx7v

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eZee Technosys eZee Online Hotel Booking Engine allows Stored XSS. This issue affects eZee Online Hotel Booking Engine: from n/a through 1.0.0.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2ch8-gj76-vc82

больше 1 года назад

The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 3.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2ch8-f849-pjg3

около 4 лет назад

Eugene Pankov Ajenti Cross-site scripting Vulnerabilities

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2ch8-2mw7-grmm

3 месяца назад

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, and Firefox ESR 115.35.2.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2ch7-pmg7-vv3j

около 4 лет назад

An elevation of privilege vulnerability exists when the Windows InstallService improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows InstallService Elevation of Privilege Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2ch7-9rhx-4c28

5 месяцев назад

Missing Authorization vulnerability in Wisernotify team WiserReview Product Reviews for WooCommerce wiser-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserReview Product Reviews for WooCommerce: from n/a through <= 2.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2ch6-x3g4-7759

5 месяцев назад

OpenClaw's commands.allowFrom sender authorization accepted conversation identifiers via ctx.From

EPSS: Низкий
github логотип

GHSA-2ch6-m8wh-67f2

больше 2 лет назад

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2chj-cxxf-fqh6

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2chj-59j8-h2vv

Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attackers to execute arbitrary code via a long first argument to the CreateStill method.

11%
Средний
около 4 лет назад
github логотип
GHSA-2chj-3cfx-vf64

The _bfd_vms_slurp_egsd function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an arbitrary memory read via a crafted vms alpha file.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2chh-r2hc-8q2g

Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.

CVSS3: 4.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2chh-qcxj-m24m

Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVSS3: 9.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-2chh-fcwm-p667

Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2chh-8jf9-q8fm

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

больше 1 года назад
github логотип
GHSA-2chg-mq5v-5gqp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berg Informatik Stripe Donation allows Stored XSS.This issue affects Stripe Donation: from n/a through 1.2.5.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2chg-86hq-7w38

btcd mishandles witness size checking

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2chg-78hj-c2w2

A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_organisation of the file superagi/controllers/project.py. The manipulation results in authorization bypass. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2chf-w4v5-vmmg

Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2ch9-gmhf-h625

CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.

CVSS3: 5.9
1%
Низкий
около 2 лет назад
github логотип
GHSA-2ch9-6m9h-xx7v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eZee Technosys eZee Online Hotel Booking Engine allows Stored XSS. This issue affects eZee Online Hotel Booking Engine: from n/a through 1.0.0.

CVSS3: 5.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-2ch8-gj76-vc82

The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 3.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-2ch8-f849-pjg3

Eugene Pankov Ajenti Cross-site scripting Vulnerabilities

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2ch8-2mw7-grmm

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, and Firefox ESR 115.35.2.

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-2ch7-pmg7-vv3j

An elevation of privilege vulnerability exists when the Windows InstallService improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows InstallService Elevation of Privilege Vulnerability'.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2ch7-9rhx-4c28

Missing Authorization vulnerability in Wisernotify team WiserReview Product Reviews for WooCommerce wiser-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserReview Product Reviews for WooCommerce: from n/a through <= 2.9.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2ch6-x3g4-7759

OpenClaw's commands.allowFrom sender authorization accepted conversation identifiers via ctx.From

5 месяцев назад
github логотип
GHSA-2ch6-m8wh-67f2

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу