Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-36cf-mq32-6x43

больше 2 лет назад

Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36cf-7v9x-v5q6

больше 4 лет назад

drivers/video/msm/mdss/mdss_debug.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 30874196 and Qualcomm internal bug CR 1001224.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36cf-5wv3-q7jj

больше 4 лет назад

SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.

EPSS: Низкий
github логотип

GHSA-36cf-5gj8-xhqw

больше 4 лет назад

WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.

EPSS: Низкий
github логотип

GHSA-36cc-rhpv-jrxc

около 1 месяца назад

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36cc-q99j-cg4r

больше 2 лет назад

Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36c9-hhx6-w4hh

около 3 лет назад

Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36c8-x5g7-w9x4

больше 2 лет назад

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36c8-9mvw-xr8h

больше 2 лет назад

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36c8-8hrq-7r5x

7 месяцев назад

The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's .htaccess file with arbitrary content, which can lead to arbitrary file read on the server under certain configurations.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36c8-63rj-g7xv

около 3 лет назад

Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36c8-4759-wcjr

больше 3 лет назад

CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are able to inject arbitrary arguments into a system command, which can be used to read files from, and write files to, the sipXcom server. This can also be leveraged to gain remote command execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36c7-mfh8-886h

6 месяцев назад

Missing Authorization vulnerability in MWP Development Diet Calorie Calculator diet-calorie-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Diet Calorie Calculator: from n/a through <= 1.1.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36c7-h45p-9hch

около 2 лет назад

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-36c7-4qpg-3rf4

больше 4 лет назад

Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

EPSS: Низкий
github логотип

GHSA-36c7-4899-gvc2

больше 4 лет назад

SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode.

EPSS: Низкий
github логотип

GHSA-36c6-hq98-86j5

больше 4 лет назад

The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-36c5-5h9q-3jvp

больше 4 лет назад

On Prima Systems FlexAir devices through 2.4.9api3, an authenticated user can upload Python (.py) scripts and execute arbitrary code with root privileges.

EPSS: Средний
github логотип

GHSA-36c5-27vw-wf76

7 месяцев назад

In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-36c4-vh5m-q4h5

почти 4 года назад

A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /hrm/employeeadd.php. The manipulation of the argument empid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214775.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36cf-mq32-6x43

Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36cf-7v9x-v5q6

drivers/video/msm/mdss/mdss_debug.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 30874196 and Qualcomm internal bug CR 1001224.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-36cf-5wv3-q7jj

SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36cf-5gj8-xhqw

WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-36cc-rhpv-jrxc

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-36cc-q99j-cg4r

Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-36c9-hhx6-w4hh

Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-36c8-x5g7-w9x4

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-36c8-9mvw-xr8h

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36c8-8hrq-7r5x

The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's .htaccess file with arbitrary content, which can lead to arbitrary file read on the server under certain configurations.

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-36c8-63rj-g7xv

Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-36c8-4759-wcjr

CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are able to inject arbitrary arguments into a system command, which can be used to read files from, and write files to, the sipXcom server. This can also be leveraged to gain remote command execution.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-36c7-mfh8-886h

Missing Authorization vulnerability in MWP Development Diet Calorie Calculator diet-calorie-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Diet Calorie Calculator: from n/a through <= 1.1.1.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-36c7-h45p-9hch

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.

CVSS3: 7.6
1%
Низкий
около 2 лет назад
github логотип
GHSA-36c7-4qpg-3rf4

Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-36c7-4899-gvc2

SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36c6-hq98-86j5

The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.

CVSS3: 3.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36c5-5h9q-3jvp

On Prima Systems FlexAir devices through 2.4.9api3, an authenticated user can upload Python (.py) scripts and execute arbitrary code with root privileges.

12%
Средний
больше 4 лет назад
github логотип
GHSA-36c5-27vw-wf76

In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-36c4-vh5m-q4h5

A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /hrm/employeeadd.php. The manipulation of the argument empid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214775.

CVSS3: 7.2
1%
Низкий
почти 4 года назад

Уязвимостей на страницу