Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-37jr-8vrf-hwhp

около 3 лет назад

Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-37jr-2q49-7p4m

больше 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-37jq-2j66-w398

больше 4 лет назад

Apple TV before 6.1 does not properly restrict logging, which allows local users to obtain sensitive information by reading log data.

EPSS: Низкий
github логотип

GHSA-37jp-3q9w-phcm

2 месяца назад

A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37jm-qcw2-gcqg

3 месяца назад

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-37jm-q7wj-f2wc

почти 2 года назад

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37jm-8h4h-w52w

около 4 лет назад

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/manage_item.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37jj-wp7g-7wj4

около 5 лет назад

Read of uninitialized memory in cdr

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37jj-q8h7-hv43

почти 2 года назад

The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode in version 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-37jj-p98x-q9ff

больше 2 лет назад

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37jj-mf3j-h43w

больше 4 лет назад

Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.

EPSS: Низкий
github логотип

GHSA-37jj-fmf6-4mf7

8 месяцев назад

Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'Facebook' parameter in '/loggrodemo/jbrain/ConsultaTerceros' endpoint.

EPSS: Низкий
github логотип

GHSA-37jj-7j96-mcqv

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37jj-54rg-xjcm

около 3 лет назад

An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-37jg-qm7m-782r

больше 4 лет назад

Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbitrarily without logging in.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37jg-g7cq-cj49

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sabuj Kundu CBX Map for Google Map & OpenStreetMap allows DOM-Based XSS. This issue affects CBX Map for Google Map & OpenStreetMap: from n/a through 1.1.12.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37jg-8f5h-cqw4

больше 4 лет назад

services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not validate EFFECT_CMD_SET_PARAM and EFFECT_CMD_SET_PARAM_DEFERRED commands, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 30204301.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37jg-73cm-52cp

больше 4 лет назад

The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.

EPSS: Низкий
github логотип

GHSA-37jg-28mm-ghhp

больше 4 лет назад

Unspecified vulnerability in the PL/SQL component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality via unknown vectors.

EPSS: Низкий
github логотип

GHSA-37jf-ph38-h4vx

6 месяцев назад

Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fusion Builder: from n/a through < 3.15.0.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37jr-8vrf-hwhp

Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.

CVSS3: 8.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-37jr-2q49-7p4m

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-37jq-2j66-w398

Apple TV before 6.1 does not properly restrict logging, which allows local users to obtain sensitive information by reading log data.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-37jp-3q9w-phcm

A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-37jm-qcw2-gcqg

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
0%
Низкий
3 месяца назад
github логотип
GHSA-37jm-q7wj-f2wc

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-37jm-8h4h-w52w

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/manage_item.php.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-37jj-wp7g-7wj4

Read of uninitialized memory in cdr

CVSS3: 9.8
2%
Низкий
около 5 лет назад
github логотип
GHSA-37jj-q8h7-hv43

The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode in version 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-37jj-p98x-q9ff

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-37jj-mf3j-h43w

Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-37jj-fmf6-4mf7

Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'Facebook' parameter in '/loggrodemo/jbrain/ConsultaTerceros' endpoint.

0%
Низкий
8 месяцев назад
github логотип
GHSA-37jj-7j96-mcqv

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-37jj-54rg-xjcm

An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-37jg-qm7m-782r

Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parameters to delete articles arbitrarily without logging in.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37jg-g7cq-cj49

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sabuj Kundu CBX Map for Google Map & OpenStreetMap allows DOM-Based XSS. This issue affects CBX Map for Google Map & OpenStreetMap: from n/a through 1.1.12.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-37jg-8f5h-cqw4

services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not validate EFFECT_CMD_SET_PARAM and EFFECT_CMD_SET_PARAM_DEFERRED commands, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 30204301.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-37jg-73cm-52cp

The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-37jg-28mm-ghhp

Unspecified vulnerability in the PL/SQL component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37jf-ph38-h4vx

Missing Authorization vulnerability in ThemeFusion Fusion Builder fusion-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fusion Builder: from n/a through < 3.15.0.

CVSS3: 6.3
0%
Низкий
6 месяцев назад

Уязвимостей на страницу