Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-385j-v37x-w8hf

около 1 года назад

In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-385j-3gwh-pjgr

больше 3 лет назад

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-385j-3cf6-7qjj

больше 2 лет назад

D-Link DAP-2622 DDP Set SSID List RADIUS Server Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20100.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-385h-fw9f-cf6x

около 14 часов назад

MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly mapped to the wildcard permission ('*') in the ACLComponent, making it accessible to any authenticated user regardless of their assigned permissions. All analogous report-modification actions correctly required the perm_add permission, while read-only actions such as downloadAsPDF appropriately used the wildcard.  An authenticated user without the perm_add permission could invoke the replaceSuggestionInReport endpoint to alter report suggestion data, violating the intended authorization model.  This constitutes an improper authorization weakness that could lead to unauthorized modification of event report content, potentially corrupting shared threat intelligence data or injecting misleading information into reports relied upon by other analysts and automated consumers.

EPSS: Низкий
github логотип

GHSA-385g-h8q2-rpj7

2 месяца назад

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the payload is stored in term meta rather than post content, the WordPress unfiltered_html capability exception does not apply, meaning Shop Manager-level users — who normally lack unfiltered_html — can fully exploit this vulnerability.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-385g-f3h5-22xh

7 месяцев назад

Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-385g-388p-m6hv

больше 4 лет назад

A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by submitting custom JavaScript to affected web applications. A successful exploit could allow the attacker to rewrite web page content, access sensitive information stored in the applications, and alter data by submitting forms.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-385f-vgq7-8hhx

почти 4 года назад

Moodle No groups filtering in H5P activity attempts report

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-385f-mwvx-qwq5

3 месяца назад

Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-385f-2j86-w7g5

около 4 лет назад

In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-234440688

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-385c-m8p7-qvr3

больше 4 лет назад

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3858-cvv4-qvj7

почти 5 лет назад

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

EPSS: Низкий
github логотип

GHSA-3858-58w9-wpcg

больше 4 лет назад

Jenkins OpenId Connect Authentication Plugin showed plain text client secret in configuration form

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3857-xm38-jmq2

больше 4 лет назад

Incorrect Authorization in Jenkins Core

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3857-jq6x-m933

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidpaulsson byBrick Accordion allows Stored XSS. This issue affects byBrick Accordion: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3857-6763-x46q

больше 4 лет назад

Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.

EPSS: Низкий
github логотип

GHSA-3856-cjch-9cv8

почти 3 года назад

In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3856-3vxq-m6fc

4 месяца назад

Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3855-w94p-4hp9

больше 4 лет назад

A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The possibility of exploiting this vulnerability is limited and can only take place during the installation phase of ESET products. Furthermore, exploitation can only succeed when Self-Defense is disabled. Affected products are: ESET NOD32 Antivirus, ESET Internet Security, ESET Smart Security, ESET Smart Security Premium versions 13.2 and lower; ESET Endpoint Antivirus, ESET Endpoint Security, ESET NOD32 Antivirus Business Edition, ESET Smart Security Business Edition versions 7.3 and lower; ESET File Security for Microsoft Windows Server, ESET Mail Security for Microsoft Exchange Server, ESET Mail Security for IBM Domino, ESET Security for Kerio, ESET Security for Microsoft SharePoint Server versions 7.2 and lower.

EPSS: Низкий
github логотип

GHSA-3855-mpq3-qh22

больше 4 лет назад

Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device crash) via (1) "abnormal" MGCP messages, aka CSCsd81407; and (2) a large facsimile packet, aka CSCej20505.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-385j-v37x-w8hf

In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-385j-3gwh-pjgr

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
49%
Средний
больше 3 лет назад
github логотип
GHSA-385j-3cf6-7qjj

D-Link DAP-2622 DDP Set SSID List RADIUS Server Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20100.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-385h-fw9f-cf6x

MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly mapped to the wildcard permission ('*') in the ACLComponent, making it accessible to any authenticated user regardless of their assigned permissions. All analogous report-modification actions correctly required the perm_add permission, while read-only actions such as downloadAsPDF appropriately used the wildcard.  An authenticated user without the perm_add permission could invoke the replaceSuggestionInReport endpoint to alter report suggestion data, violating the intended authorization model.  This constitutes an improper authorization weakness that could lead to unauthorized modification of event report content, potentially corrupting shared threat intelligence data or injecting misleading information into reports relied upon by other analysts and automated consumers.

около 14 часов назад
github логотип
GHSA-385g-h8q2-rpj7

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the payload is stored in term meta rather than post content, the WordPress unfiltered_html capability exception does not apply, meaning Shop Manager-level users — who normally lack unfiltered_html — can fully exploit this vulnerability.

CVSS3: 4.4
0%
Низкий
2 месяца назад
github логотип
GHSA-385g-f3h5-22xh

Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-385g-388p-m6hv

A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by submitting custom JavaScript to affected web applications. A successful exploit could allow the attacker to rewrite web page content, access sensitive information stored in the applications, and alter data by submitting forms.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-385f-vgq7-8hhx

Moodle No groups filtering in H5P activity attempts report

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-385f-mwvx-qwq5

Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.

CVSS3: 6.6
0%
Низкий
3 месяца назад
github логотип
GHSA-385f-2j86-w7g5

In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-234440688

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-385c-m8p7-qvr3

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3858-cvv4-qvj7

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

7%
Низкий
почти 5 лет назад
github логотип
GHSA-3858-58w9-wpcg

Jenkins OpenId Connect Authentication Plugin showed plain text client secret in configuration form

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3857-xm38-jmq2

Incorrect Authorization in Jenkins Core

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3857-jq6x-m933

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidpaulsson byBrick Accordion allows Stored XSS. This issue affects byBrick Accordion: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3857-6763-x46q

Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3856-cjch-9cv8

In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3856-3vxq-m6fc

Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-3855-w94p-4hp9

A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The possibility of exploiting this vulnerability is limited and can only take place during the installation phase of ESET products. Furthermore, exploitation can only succeed when Self-Defense is disabled. Affected products are: ESET NOD32 Antivirus, ESET Internet Security, ESET Smart Security, ESET Smart Security Premium versions 13.2 and lower; ESET Endpoint Antivirus, ESET Endpoint Security, ESET NOD32 Antivirus Business Edition, ESET Smart Security Business Edition versions 7.3 and lower; ESET File Security for Microsoft Windows Server, ESET Mail Security for Microsoft Exchange Server, ESET Mail Security for IBM Domino, ESET Security for Kerio, ESET Security for Microsoft SharePoint Server versions 7.2 and lower.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3855-mpq3-qh22

Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device crash) via (1) "abnormal" MGCP messages, aka CSCsd81407; and (2) a large facsimile packet, aka CSCej20505.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу