Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-27mv-5vpc-8g53

почти 3 года назад

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-27mr-8vvw-x4gr

больше 1 года назад

The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-27mq-645j-xwfx

около 4 лет назад

Non-secure SW can cause SDCC to generate secure bus accesses, which may expose RPM access in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27mm-rpgf-cvhw

около 3 лет назад

An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27mm-mp84-cq8h

около 4 лет назад

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.

EPSS: Низкий
github логотип

GHSA-27mm-gc33-cv78

9 месяцев назад

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27mm-4rvr-4q6h

около 2 лет назад

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to import courses.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-27mm-4p4v-5qpj

около 4 лет назад

D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27mh-mg4q-xvj9

около 4 лет назад

PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter.

EPSS: Низкий
github логотип

GHSA-27mh-3343-6hg5

около 4 лет назад

dhowden tag panic due to out-of-bounds read

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27mg-gqcr-w5x5

5 месяцев назад

Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27mf-h76r-wrj9

около 1 года назад

A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to modify protected parts of the file system.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27mf-ghqm-j3j8

больше 1 года назад

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-27mc-m39v-wccj

7 месяцев назад

The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. This is due to the `create_item_permissions_check()` function unconditionally returning true, which bypasses authentication and authorization validation. This makes it possible for unauthenticated attackers to create arbitrary metadata sections for any collection via the public REST API granted they can access the WordPress site.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27mc-9399-r9mx

9 месяцев назад

Drupal Access code allows Brute Force Attempts

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-27m8-q4mw-5g3g

около 4 лет назад

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-27m7-ffhq-jqrm

8 месяцев назад

MCP Watch has a Critical Command Injection in cloneRepo allows Remote Code Execution (RCE) via malicious URL

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27m7-5vm3-3prg

около 2 лет назад

The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service logic. Attackers can exploit the issue by forcing the AI service to leak the standard hard-coded system prompts and/or execute unwanted prompts. When engaging with EmailGPT by submitting a malicious prompt that requests harmful information, the system will respond by providing the requested data. This vulnerability can be exploited by any individual with access to the service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27m7-4v2p-j66r

около 4 лет назад

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27m5-g4hr-5cg5

около 4 лет назад

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27mv-5vpc-8g53

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.

CVSS3: 7.5
85%
Высокий
почти 3 года назад
github логотип
GHSA-27mr-8vvw-x4gr

The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action in all versions up to, and including, 1.0.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-27mq-645j-xwfx

Non-secure SW can cause SDCC to generate secure bus accesses, which may expose RPM access in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-27mm-rpgf-cvhw

An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 8.8
6%
Низкий
около 3 лет назад
github логотип
GHSA-27mm-mp84-cq8h

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.

4%
Низкий
около 4 лет назад
github логотип
GHSA-27mm-gc33-cv78

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-27mm-4rvr-4q6h

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to import courses.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-27mm-4p4v-5qpj

D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-27mh-mg4q-xvj9

PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-27mh-3343-6hg5

dhowden tag panic due to out-of-bounds read

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-27mg-gqcr-w5x5

Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-27mf-h76r-wrj9

A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to modify protected parts of the file system.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-27mf-ghqm-j3j8

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-27mc-m39v-wccj

The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. This is due to the `create_item_permissions_check()` function unconditionally returning true, which bypasses authentication and authorization validation. This makes it possible for unauthenticated attackers to create arbitrary metadata sections for any collection via the public REST API granted they can access the WordPress site.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-27mc-9399-r9mx

Drupal Access code allows Brute Force Attempts

CVSS3: 6.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-27m8-q4mw-5g3g

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

36%
Средний
около 4 лет назад
github логотип
GHSA-27m7-ffhq-jqrm

MCP Watch has a Critical Command Injection in cloneRepo allows Remote Code Execution (RCE) via malicious URL

CVSS3: 9.8
2%
Низкий
8 месяцев назад
github логотип
GHSA-27m7-5vm3-3prg

The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service logic. Attackers can exploit the issue by forcing the AI service to leak the standard hard-coded system prompts and/or execute unwanted prompts. When engaging with EmailGPT by submitting a malicious prompt that requests harmful information, the system will respond by providing the requested data. This vulnerability can be exploited by any individual with access to the service.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-27m7-4v2p-j66r

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-27m5-g4hr-5cg5

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."

22%
Средний
около 4 лет назад

Уязвимостей на страницу