Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35xv-2qm4-86w9

11 месяцев назад

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418954; Issue ID: MSV-3569.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35xr-qxrc-6m3x

больше 4 лет назад

SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.

EPSS: Низкий
github логотип

GHSA-35xr-m7j2-qj4j

больше 2 лет назад

Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35xr-6qpp-jxg6

больше 4 лет назад

Unspecified vulnerability in the Siebel Call Center component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via vectors related to Email - COMM Server Components.

EPSS: Низкий
github логотип

GHSA-35xr-5vwf-cx56

больше 4 лет назад

An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0763.

EPSS: Низкий
github логотип

GHSA-35xr-2w3x-9wvx

25 дней назад

Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35xq-xxqc-xxh9

больше 4 лет назад

The wp-rollback plugin before 1.2.3 for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35xq-xfhr-qv9p

больше 2 лет назад

The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on the plugin's AJAX actions.. This makes it possible for unauthenticated attackers to create and duplicate posts, retrieve post content, and modify post taxonomy among other things via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35xq-75pf-rjwj

больше 4 лет назад

An issue has been discovered in Bento4 1.5.1-624. AP4_Mp4AudioDsiParser::ReadBits in Codecs/Ap4Mp4AudioInfo.cpp has a heap-based buffer over-read.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35xq-5wph-pxqw

почти 5 лет назад

In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-35xp-mwcf-j33g

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not return negative stream id for array [WHY] resource_stream_to_stream_idx returns an array index and it return -1 when not found; however, -1 is not a valid array index number. [HOW] When this happens, call ASSERT(), and return a zero instead. This fixes an OVERRUN and an NEGATIVE_RETURNS issues reported by Coverity.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35xp-mfx8-r234

больше 4 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35xm-qvjg-8m42

6 месяцев назад

dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-35xm-2rw8-rrv8

около 4 лет назад

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35xg-8w82-5395

больше 4 лет назад

BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35xg-724r-fcfx

около 2 лет назад

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35xf-8pcf-3f8p

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.

EPSS: Низкий
github логотип

GHSA-35xf-7pfr-g5f5

больше 2 лет назад

Zoho ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to this vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-35xc-5p56-vcx8

больше 4 лет назад

config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter.

EPSS: Низкий
github логотип

GHSA-35xc-3xx3-rqcw

больше 4 лет назад

An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35xv-2qm4-86w9

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418954; Issue ID: MSV-3569.

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-35xr-qxrc-6m3x

SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35xr-m7j2-qj4j

Adobe Experience Manager versions 6.5.19 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35xr-6qpp-jxg6

Unspecified vulnerability in the Siebel Call Center component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via vectors related to Email - COMM Server Components.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35xr-5vwf-cx56

An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0763.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35xr-2w3x-9wvx

Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 7.5
0%
Низкий
25 дней назад
github логотип
GHSA-35xq-xxqc-xxh9

The wp-rollback plugin before 1.2.3 for WordPress has XSS.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35xq-xfhr-qv9p

The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on the plugin's AJAX actions.. This makes it possible for unauthenticated attackers to create and duplicate posts, retrieve post content, and modify post taxonomy among other things via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35xq-75pf-rjwj

An issue has been discovered in Bento4 1.5.1-624. AP4_Mp4AudioDsiParser::ReadBits in Codecs/Ap4Mp4AudioInfo.cpp has a heap-based buffer over-read.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35xq-5wph-pxqw

In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel

CVSS3: 4.4
0%
Низкий
почти 5 лет назад
github логотип
GHSA-35xp-mwcf-j33g

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not return negative stream id for array [WHY] resource_stream_to_stream_idx returns an array index and it return -1 when not found; however, -1 is not a valid array index number. [HOW] When this happens, call ASSERT(), and return a zero instead. This fixes an OVERRUN and an NEGATIVE_RETURNS issues reported by Coverity.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-35xp-mfx8-r234

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-35xm-qvjg-8m42

dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration

CVSS3: 8.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-35xm-2rw8-rrv8

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-35xg-8w82-5395

BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-35xg-724r-fcfx

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-35xf-8pcf-3f8p

Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35xf-7pfr-g5f5

Zoho ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to this vulnerability.

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35xc-5p56-vcx8

config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-35xc-3xx3-rqcw

An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу