Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35vv-8xvm-74jp

больше 4 лет назад

Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35vr-x655-89wj

почти 3 года назад

A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-35vq-jv5m-667c

больше 4 лет назад

The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204.

EPSS: Низкий
github логотип

GHSA-35vq-2ggj-6fwg

больше 4 лет назад

security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

EPSS: Низкий
github логотип

GHSA-35vp-x4m3-rrq9

6 месяцев назад

A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field of a comment. An attacker can inject arbitrary JavaScript code using a <script> element. The injected payload is stored in the database and subsequently rendered in the Administration panel's "Comments" section when administrators review submitted comments. Importantly, the malicious script is not reflected in the public-facing comments interface, but only within the backend administration view. Alternatively, users of Administrator, Moderator, Manager roles can also directly input crafted payloads into existing comments. This makes the vulnerability a persistent XSS issue targeting administrative users. This affects /core/admin/comments.php, while CVE-2022-24585 affects /core/admin/comment.php, a uniquely distinct vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35vm-xh8x-vfc2

больше 4 лет назад

Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.

EPSS: Средний
github логотип

GHSA-35vm-p7h9-q944

больше 4 лет назад

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files via a direct request to a URL, aka Bug ID CSCum46495.

EPSS: Низкий
github логотип

GHSA-35vj-pjgj-gmmg

больше 4 лет назад

Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.

EPSS: Низкий
github логотип

GHSA-35vj-j37m-2rfx

больше 1 года назад

Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-35vj-82w2-vv85

больше 4 лет назад

Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

EPSS: Низкий
github логотип

GHSA-35vj-78r5-pwj5

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-35vg-mphp-6q6c

больше 4 лет назад

Multiple buffer overflows in the web interface on the D-Link DI-524 router allow remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact via (1) a long username or (2) an HTTP header with a large name and an empty value.

EPSS: Низкий
github логотип

GHSA-35vf-vw9f-q3cr

5 месяцев назад

Duplicate Advisory: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35vc-w93w-75c2

больше 5 лет назад

JWT leak via Open Redirect in Programmatic access

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-35vc-3vm2-6c46

почти 4 года назад

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35v9-p68v-wpm7

больше 4 лет назад

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35v9-p644-6gff

9 месяцев назад

Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.12.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35v9-jfrh-47jx

больше 4 лет назад

Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-35v9-54h8-hx2c

больше 4 лет назад

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant from a more serious issue such as directory traversal.

EPSS: Низкий
github логотип

GHSA-35v9-42cw-vgg3

больше 4 лет назад

proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35vv-8xvm-74jp

Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35vr-x655-89wj

A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to the application in plaint text. This log file contains the password hashes coded with AES-CBC-128 bits algorithm, which can be decrypted with a .NET function, obtaining the username's password in plain text.

CVSS3: 8.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-35vq-jv5m-667c

The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35vq-2ggj-6fwg

security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35vp-x4m3-rrq9

A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field of a comment. An attacker can inject arbitrary JavaScript code using a <script> element. The injected payload is stored in the database and subsequently rendered in the Administration panel's "Comments" section when administrators review submitted comments. Importantly, the malicious script is not reflected in the public-facing comments interface, but only within the backend administration view. Alternatively, users of Administrator, Moderator, Manager roles can also directly input crafted payloads into existing comments. This makes the vulnerability a persistent XSS issue targeting administrative users. This affects /core/admin/comments.php, while CVE-2022-24585 affects /core/admin/comment.php, a uniquely distinct vulnerability.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-35vm-xh8x-vfc2

Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.

13%
Средний
больше 4 лет назад
github логотип
GHSA-35vm-p7h9-q944

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files via a direct request to a URL, aka Bug ID CSCum46495.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35vj-pjgj-gmmg

Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35vj-j37m-2rfx

Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.

CVSS3: 6.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-35vj-82w2-vv85

Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-35vj-78r5-pwj5

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35vg-mphp-6q6c

Multiple buffer overflows in the web interface on the D-Link DI-524 router allow remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact via (1) a long username or (2) an HTTP header with a large name and an empty value.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35vf-vw9f-q3cr

Duplicate Advisory: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens

CVSS3: 7.8
5 месяцев назад
github логотип
GHSA-35vc-w93w-75c2

JWT leak via Open Redirect in Programmatic access

CVSS3: 6.3
1%
Низкий
больше 5 лет назад
github логотип
GHSA-35vc-3vm2-6c46

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. It was possible for an unauthorised user to create issues in a project.

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-35v9-p68v-wpm7

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35v9-p644-6gff

Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.12.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-35v9-jfrh-47jx

Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-35v9-54h8-hx2c

modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant from a more serious issue such as directory traversal.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35v9-42cw-vgg3

proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу