Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-27x8-wr44-c4fx

больше 3 лет назад

Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27x8-pgpq-2xp5

около 4 лет назад

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128460.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-27x5-rrvg-fcg5

около 4 лет назад

Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-27x5-h3jg-f385

около 2 лет назад

Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation.This issue affects Mia-Med Health Aplication: before 1.0.14.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27x5-gpc9-m62h

около 4 лет назад

Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-27x5-f9wp-cp4p

около 4 лет назад

The OHBM 20th Annual Meeting (aka com.coreapps.android.followme.ohbm2014) application 6.0.9.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-27x5-2866-42xg

больше 1 года назад

Rejected reason: reserved but not needed

EPSS: Низкий
github логотип

GHSA-27x4-j476-jp5f

около 4 лет назад

Setuptools vulnerable to Man-in-the-middle attacks

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-27x4-6mg5-w2gm

около 4 лет назад

Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.2.0 and 11.1.2.1 allows remote attackers to affect confidentiality via unknown vectors related to Identity Console.

EPSS: Низкий
github логотип

GHSA-27x4-2pj4-vg94

около 4 лет назад

Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.

EPSS: Средний
github логотип

GHSA-27x3-xfp4-2fq2

почти 4 года назад

In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-203229608

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-27x3-9gfr-28mw

больше 3 лет назад

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd sn_grp, at 0x9d017658, the value for the `gcmd` key is copied using `strcpy` to the buffer at `$sp+0x270`.This buffer is 16 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-27x2-vxwh-x9pv

больше 4 лет назад

The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27x2-77hh-wh7h

около 2 лет назад

A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to modify certain files, allowing the attacker to cause any command to execute with root privileges leading to privilege escalation ultimately compromising the system.  This issue affects Junos OS Evolved:  * All versions prior to 21.2R3-S8-EVO,  * 21.4 versions prior to  21.4R3-S6-EVO,  * 22.1 versions prior to 22.1R3-S5-EVO,  * 22.2 versions prior to 22.2R3-S3-EVO,  * 22.3 versions prior to 22.3R3-S3-EVO,  * 22.4 versions prior to 22.4R3-EVO,  * 23.2 versions prior to 23.2R2-EVO.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-27x2-2gh4-2gpv

11 месяцев назад

Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, a function that requires authentication may be accessed by a remote unauthenticated attacker.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27wx-w49m-rrj8

больше 1 года назад

Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-27wx-pvwm-cfh2

около 2 месяцев назад

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or view. When editing objects, the sharing group validation was performed against the wrong request data structure after object fields had been merged to the top level, causing the check to be bypassed. In addition, attributes embedded in objects were not individually validated for authorized sharing group use. An attacker could craft a request with distribution set to 4 and an arbitrary sharing_group_id, potentially disclosing the existence or name of otherwise non-visible sharing groups and improperly modifying the distribution metadata of objects or contained attributes.

EPSS: Низкий
github логотип

GHSA-27ww-v7p7-f3mc

8 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-27ww-388c-hfhf

больше 1 года назад

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-27wv-g8h4-3qr9

больше 1 года назад

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27x8-wr44-c4fx

Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27x8-pgpq-2xp5

IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128460.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-27x5-rrvg-fcg5

Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c.

CVSS3: 7.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-27x5-h3jg-f385

Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation.This issue affects Mia-Med Health Aplication: before 1.0.14.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-27x5-gpc9-m62h

Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

16%
Средний
около 4 лет назад
github логотип
GHSA-27x5-f9wp-cp4p

The OHBM 20th Annual Meeting (aka com.coreapps.android.followme.ohbm2014) application 6.0.9.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-27x5-2866-42xg

Rejected reason: reserved but not needed

больше 1 года назад
github логотип
GHSA-27x4-j476-jp5f

Setuptools vulnerable to Man-in-the-middle attacks

CVSS3: 8.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-27x4-6mg5-w2gm

Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.2.0 and 11.1.2.1 allows remote attackers to affect confidentiality via unknown vectors related to Identity Console.

2%
Низкий
около 4 лет назад
github логотип
GHSA-27x4-2pj4-vg94

Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.

16%
Средний
около 4 лет назад
github логотип
GHSA-27x3-xfp4-2fq2

In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-203229608

CVSS3: 3.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-27x3-9gfr-28mw

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd sn_grp, at 0x9d017658, the value for the `gcmd` key is copied using `strcpy` to the buffer at `$sp+0x270`.This buffer is 16 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27x2-vxwh-x9pv

The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-27x2-77hh-wh7h

A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to modify certain files, allowing the attacker to cause any command to execute with root privileges leading to privilege escalation ultimately compromising the system.  This issue affects Junos OS Evolved:  * All versions prior to 21.2R3-S8-EVO,  * 21.4 versions prior to  21.4R3-S6-EVO,  * 22.1 versions prior to 22.1R3-S5-EVO,  * 22.2 versions prior to 22.2R3-S3-EVO,  * 22.3 versions prior to 22.3R3-S3-EVO,  * 22.4 versions prior to 22.4R3-EVO,  * 23.2 versions prior to 23.2R2-EVO.

CVSS3: 7.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-27x2-2gh4-2gpv

Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, a function that requires authentication may be accessed by a remote unauthenticated attacker.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-27wx-w49m-rrj8

Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-27wx-pvwm-cfh2

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or view. When editing objects, the sharing group validation was performed against the wrong request data structure after object fields had been merged to the top level, causing the check to be bypassed. In addition, attributes embedded in objects were not individually validated for authorized sharing group use. An attacker could craft a request with distribution set to 4 and an arbitrary sharing_group_id, potentially disclosing the existence or name of otherwise non-visible sharing groups and improperly modifying the distribution metadata of objects or contained attributes.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-27ww-v7p7-f3mc

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

8 месяцев назад
github логотип
GHSA-27ww-388c-hfhf

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function.

CVSS3: 7.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-27wv-g8h4-3qr9

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.

CVSS3: 3.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу