Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-26h2-jmcv-j5g4

около 4 лет назад

In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Out of Bounds Write vulnerability because of not validating input values from IOCtl 0x83000058, a related issue to CVE-2017-17112.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26h2-7ff9-7pj5

около 4 лет назад

CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlier is prone to a stack-based buffer overflow, which allows a remote attacker to achieve code execution or denial of service by sending a crafted payload to the listening server.

EPSS: Низкий
github логотип

GHSA-26gw-crpw-vhg7

около 4 лет назад

The Aptallik Testi (aka com.wAptallikTesti) application 4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-26gw-4gmp-qgf3

около 4 лет назад

In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-26gv-x98q-gqcw

11 месяцев назад

A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the component HTTP Header Handler. The manipulation of the argument Host results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26gv-chv5-g7q6

больше 1 года назад

An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26gr-cvq3-qxgf

около 5 лет назад

Improper Authentication in Apache Shiro

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-26gr-c7rc-wwqj

около 4 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

EPSS: Низкий
github логотип

GHSA-26gq-p25f-99cp

8 дней назад

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

EPSS: Низкий
github логотип

GHSA-26gq-p245-cq98

больше 4 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26gq-grmh-6xm6

6 месяцев назад

Gogs vulnerable to Stored XSS via Mermaid diagrams

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-26gp-9jcj-gh27

больше 4 лет назад

When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application

EPSS: Низкий
github логотип

GHSA-26gm-rrp5-38p4

3 месяца назад

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-26gm-rmpq-m43w

5 месяцев назад

EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send GET requests to the files directory to download database files like db.sq3 containing application data and credentials.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26gm-93rw-cchf

4 месяца назад

Open WebUI has unauthorized deletion of knowledge files

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26gj-v5x8-mq2v

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-26gj-j48h-429f

около 4 лет назад

Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController servlet in jviews-framework-all.jar does not require explicit configuration of servlets that can be called.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26gj-hvfr-rqwg

больше 4 лет назад

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service.

EPSS: Низкий
github логотип

GHSA-26gj-f778-xvm7

около 4 лет назад

Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.

EPSS: Низкий
github логотип

GHSA-26gh-v8rm-xxgj

5 дней назад

The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26h2-jmcv-j5g4

In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Out of Bounds Write vulnerability because of not validating input values from IOCtl 0x83000058, a related issue to CVE-2017-17112.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-26h2-7ff9-7pj5

CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlier is prone to a stack-based buffer overflow, which allows a remote attacker to achieve code execution or denial of service by sending a crafted payload to the listening server.

3%
Низкий
около 4 лет назад
github логотип
GHSA-26gw-crpw-vhg7

The Aptallik Testi (aka com.wAptallikTesti) application 4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-26gw-4gmp-qgf3

In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-26gv-x98q-gqcw

A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the component HTTP Header Handler. The manipulation of the argument Host results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-26gv-chv5-g7q6

An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-26gr-cvq3-qxgf

Improper Authentication in Apache Shiro

CVSS3: 9.8
23%
Средний
около 5 лет назад
github логотип
GHSA-26gr-c7rc-wwqj

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

2%
Низкий
около 4 лет назад
github логотип
GHSA-26gq-p25f-99cp

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

8 дней назад
github логотип
GHSA-26gq-p245-cq98

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-26gq-grmh-6xm6

Gogs vulnerable to Stored XSS via Mermaid diagrams

CVSS3: 7.3
6 месяцев назад
github логотип
GHSA-26gp-9jcj-gh27

When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application

1%
Низкий
больше 4 лет назад
github логотип
GHSA-26gm-rrp5-38p4

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
3 месяца назад
github логотип
GHSA-26gm-rmpq-m43w

EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send GET requests to the files directory to download database files like db.sq3 containing application data and credentials.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-26gm-93rw-cchf

Open WebUI has unauthorized deletion of knowledge files

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-26gj-v5x8-mq2v

Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-26gj-j48h-429f

Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController servlet in jviews-framework-all.jar does not require explicit configuration of servlets that can be called.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-26gj-hvfr-rqwg

There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-26gj-f778-xvm7

Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4152, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.

8%
Низкий
около 4 лет назад
github логотип
GHSA-26gh-v8rm-xxgj

The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.

CVSS3: 7.1
0%
Низкий
5 дней назад

Уязвимостей на страницу