Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-22qq-pvp9-wmv5

больше 4 лет назад

Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID bound to the watch can bypass permission verification to perform specific operations and modify some data on the watch.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-22qq-gmgr-6mw9

больше 4 лет назад

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22qq-g5f9-r82v

больше 4 лет назад

Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.

EPSS: Низкий
github логотип

GHSA-22qq-3xwm-r5x4

больше 1 года назад

CometBFT allows a malicious peer to make node stuck in blocksync

EPSS: Низкий
github логотип

GHSA-22qm-pq7c-f85x

больше 4 лет назад

Lack of check in length before using memcpy in WLAN function can lead to OOB access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCS605, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM630, SDM660, SDX20, SDX24, SXR1130

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22qj-wxjp-fcc7

больше 4 лет назад

There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the system to restart.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22qj-f25c-22mc

больше 1 года назад

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22qj-922v-qrj6

больше 4 лет назад

SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-22qj-8xm8-83m5

больше 2 лет назад

The Easy Social Feed WordPress plugin before 6.5.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22qj-6c22-mwj2

больше 1 года назад

NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-22qh-gmm8-6w63

больше 4 лет назад

Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22qh-5xm8-3xfw

почти 5 лет назад

The vulnerability function is enabled when the streamer service related to the AfreecaTV communicated through web socket using 21201 port. A stack-based buffer overflow leading to remote code execution was discovered in strcpy() operate by "FanTicket" field. It is because of stored data without validation of length.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22qh-55gx-68jh

больше 4 лет назад

Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

EPSS: Низкий
github логотип

GHSA-22qg-42rj-w8x8

больше 2 лет назад

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22qf-w2wm-5686

больше 4 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the encryption of firmware update images. The issue results from the use of an inappropriate encryption algorithm. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9649.

EPSS: Низкий
github логотип

GHSA-22qf-62f9-pj62

больше 2 лет назад

As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22q9-m8j5-x7xg

почти 2 года назад

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22q9-hqm5-mhmc

почти 6 лет назад

Cross-Site Scripting in swagger-ui

EPSS: Низкий
github логотип

GHSA-22q9-7cmf-jjxp

больше 4 лет назад

The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.

EPSS: Низкий
github логотип

GHSA-22q8-rwx9-62gg

больше 2 лет назад

A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22qq-pvp9-wmv5

Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID bound to the watch can bypass permission verification to perform specific operations and modify some data on the watch.

CVSS3: 4.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-22qq-gmgr-6mw9

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-22qq-g5f9-r82v

Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-22qq-3xwm-r5x4

CometBFT allows a malicious peer to make node stuck in blocksync

0%
Низкий
больше 1 года назад
github логотип
GHSA-22qm-pq7c-f85x

Lack of check in length before using memcpy in WLAN function can lead to OOB access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCS605, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM630, SDM660, SDX20, SDX24, SXR1130

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22qj-wxjp-fcc7

There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the system to restart.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22qj-f25c-22mc

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-22qj-922v-qrj6

SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 6.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22qj-8xm8-83m5

The Easy Social Feed WordPress plugin before 6.5.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22qj-6c22-mwj2

NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-22qh-gmm8-6w63

Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-22qh-5xm8-3xfw

The vulnerability function is enabled when the streamer service related to the AfreecaTV communicated through web socket using 21201 port. A stack-based buffer overflow leading to remote code execution was discovered in strcpy() operate by "FanTicket" field. It is because of stored data without validation of length.

CVSS3: 8.8
1%
Низкий
почти 5 лет назад
github логотип
GHSA-22qh-55gx-68jh

Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-22qg-42rj-w8x8

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-22qf-w2wm-5686

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the encryption of firmware update images. The issue results from the use of an inappropriate encryption algorithm. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9649.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22qf-62f9-pj62

As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22q9-m8j5-x7xg

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-22q9-hqm5-mhmc

Cross-Site Scripting in swagger-ui

почти 6 лет назад
github логотип
GHSA-22q9-7cmf-jjxp

The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-22q8-rwx9-62gg

A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability.

CVSS3: 3.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу