Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-29vc-jwh6-m84c

12 месяцев назад

A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/server/web/api/controller/data/source/DataSourceController.java of the component JDBC Connection Handler. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-29v9-x79c-6xjf

7 месяцев назад

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-29v9-mcvr-88rv

около 4 лет назад

A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-29v9-m8r8-v85x

около 4 лет назад

An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29v9-frvh-c426

3 месяца назад

monetr: Server-side request forgery in Lunch Flow link creation and refresh

EPSS: Низкий
github логотип

GHSA-29v9-2fpx-j5g9

больше 5 лет назад

CSV Injection vulnerability with exported contact lists in Mautic

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29v8-q543-pf5w

28 дней назад

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-29v8-gqqm-8c25

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Stored XSS. This issue affects Quick Event Calendar: from n/a through 1.4.9.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-29v7-3v4c-gf38

почти 5 лет назад

Data races in parc

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-29v6-j9p2-6qxc

около 4 лет назад

The packet-storing feature on Cisco 9900 phones with firmware 9.3(2) does not properly support the RTP protocol, which allows remote attackers to cause a denial of service (device hang) by sending malformed RTP packets after a call is answered, aka Bug ID CSCur39976.

EPSS: Низкий
github логотип

GHSA-29v6-6hr2-37cw

5 месяцев назад

Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affects YITH WooCommerce Compare: from n/a through <= 3.6.0.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-29v5-v73g-x3cp

около 4 лет назад

Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).

EPSS: Низкий
github логотип

GHSA-29v4-89fg-g7q9

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Prevent jump to NULL add_sidecar callback In create_sdw_dailink() check that sof_end->codec_info->add_sidecar is not NULL before calling it. The original code assumed that if include_sidecar is true, the codec on that link has an add_sidecar callback. But there could be other codecs on the same link that do not have an add_sidecar callback.

EPSS: Низкий
github логотип

GHSA-29v4-3v34-f922

около 4 лет назад

libZetta.rs through 0.1.2 has an integer overflow in the zpool parser (for error stats) that leads to a panic.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29v4-2xqc-8q79

около 4 лет назад

Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that specifies a large report size for an LED report.

EPSS: Низкий
github логотип

GHSA-29v3-r4gm-9j2f

около 4 лет назад

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 (July 2020).

EPSS: Низкий
github логотип

GHSA-29v3-g4cx-hr4v

больше 4 лет назад

RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.

EPSS: Низкий
github логотип

GHSA-29v2-2jwv-8mvr

около 4 лет назад

The LLTD Mapper in Microsoft Windows Vista allows remote attackers to spoof hosts, and nonexistent bridge relationships, into the network topology map by using a MAC address that differs from the MAC address provided in the Real Source field of the LLTD BASE header of a HELLO packet, aka the "Spoof on Bridge" attack.

EPSS: Средний
github логотип

GHSA-29rx-mvcf-24fj

около 4 лет назад

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2019).

EPSS: Низкий
github логотип

GHSA-29rx-6x28-gmg7

около 4 лет назад

Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29vc-jwh6-m84c

A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/server/web/api/controller/data/source/DataSourceController.java of the component JDBC Connection Handler. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-29v9-x79c-6xjf

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
1%
Низкий
7 месяцев назад
github логотип
GHSA-29v9-mcvr-88rv

A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-29v9-m8r8-v85x

An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-29v9-frvh-c426

monetr: Server-side request forgery in Lunch Flow link creation and refresh

0%
Низкий
3 месяца назад
github логотип
GHSA-29v9-2fpx-j5g9

CSV Injection vulnerability with exported contact lists in Mautic

CVSS3: 9.8
2%
Низкий
больше 5 лет назад
github логотип
GHSA-29v8-q543-pf5w

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
1%
Низкий
28 дней назад
github логотип
GHSA-29v8-gqqm-8c25

Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Stored XSS. This issue affects Quick Event Calendar: from n/a through 1.4.9.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-29v7-3v4c-gf38

Data races in parc

CVSS3: 8.1
1%
Низкий
почти 5 лет назад
github логотип
GHSA-29v6-j9p2-6qxc

The packet-storing feature on Cisco 9900 phones with firmware 9.3(2) does not properly support the RTP protocol, which allows remote attackers to cause a denial of service (device hang) by sending malformed RTP packets after a call is answered, aka Bug ID CSCur39976.

3%
Низкий
около 4 лет назад
github логотип
GHSA-29v6-6hr2-37cw

Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affects YITH WooCommerce Compare: from n/a through <= 3.6.0.

CVSS3: 7.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-29v5-v73g-x3cp

Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).

2%
Низкий
около 4 лет назад
github логотип
GHSA-29v4-89fg-g7q9

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Prevent jump to NULL add_sidecar callback In create_sdw_dailink() check that sof_end->codec_info->add_sidecar is not NULL before calling it. The original code assumed that if include_sidecar is true, the codec on that link has an add_sidecar callback. But there could be other codecs on the same link that do not have an add_sidecar callback.

0%
Низкий
9 месяцев назад
github логотип
GHSA-29v4-3v34-f922

libZetta.rs through 0.1.2 has an integer overflow in the zpool parser (for error stats) that leads to a panic.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-29v4-2xqc-8q79

Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that specifies a large report size for an LED report.

0%
Низкий
около 4 лет назад
github логотип
GHSA-29v3-r4gm-9j2f

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 (July 2020).

0%
Низкий
около 4 лет назад
github логотип
GHSA-29v3-g4cx-hr4v

RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-29v2-2jwv-8mvr

The LLTD Mapper in Microsoft Windows Vista allows remote attackers to spoof hosts, and nonexistent bridge relationships, into the network topology map by using a MAC address that differs from the MAC address provided in the Real Source field of the LLTD BASE header of a HELLO packet, aka the "Spoof on Bridge" attack.

11%
Средний
около 4 лет назад
github логотип
GHSA-29rx-mvcf-24fj

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2019).

0%
Низкий
около 4 лет назад
github логотип
GHSA-29rx-6x28-gmg7

Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command.

6%
Низкий
около 4 лет назад

Уязвимостей на страницу