Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-xr2h-wg3w-vrcr

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xr2h-v539-xc2h

3 дня назад

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management Interface. The manipulation of the argument name/author leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xr2g-wg2c-hrx6

больше 4 лет назад

Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr2g-57fm-4f25

4 месяца назад

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr2f-69jg-7g6f

почти 2 года назад

Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xr2c-mwcx-4xmj

больше 4 лет назад

Buffer overflow in NIS+, in Sun's rpc.nisd program.

EPSS: Низкий
github логотип

GHSA-xr2c-mghr-gmr2

около 4 лет назад

Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xr2c-6hv6-xcw7

около 2 месяцев назад

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

EPSS: Низкий
github логотип

GHSA-xr2c-5w89-63pv

больше 4 лет назад

Poetry before v1.1.9 contains Untrusted Search Path

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr2c-56qc-4ffh

больше 4 лет назад

A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions)

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xr2c-4prw-6479

больше 4 лет назад

PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xr29-6gg3-jq8m

больше 4 лет назад

SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.

EPSS: Низкий
github логотип

GHSA-xr29-4f97-vhvq

7 месяцев назад

A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xr28-hrcf-5jw6

около 2 лет назад

Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xr28-f4wv-gfp3

больше 4 лет назад

An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr27-wwfr-j97v

больше 4 лет назад

CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr27-v8wc-87cr

больше 4 лет назад

An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr26-qphw-jcg8

больше 3 лет назад

Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xr25-qx3m-g53h

6 дней назад

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xr25-hvc7-fcxm

больше 4 лет назад

HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr2h-wg3w-vrcr

Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2h-v539-xc2h

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management Interface. The manipulation of the argument name/author leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
3 дня назад
github логотип
GHSA-xr2g-wg2c-hrx6

Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2g-57fm-4f25

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xr2f-69jg-7g6f

Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr2c-mwcx-4xmj

Buffer overflow in NIS+, in Sun's rpc.nisd program.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2c-mghr-gmr2

Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection

CVSS3: 6.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xr2c-6hv6-xcw7

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

около 2 месяцев назад
github логотип
GHSA-xr2c-5w89-63pv

Poetry before v1.1.9 contains Untrusted Search Path

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2c-56qc-4ffh

A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions)

CVSS3: 7.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2c-4prw-6479

PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.

CVSS3: 8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr29-6gg3-jq8m

SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr29-4f97-vhvq

A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xr28-hrcf-5jw6

Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xr28-f4wv-gfp3

An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr27-wwfr-j97v

CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr27-v8wc-87cr

An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xr26-qphw-jcg8

Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xr25-qx3m-g53h

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve sensitive sandbox internals.

CVSS3: 5.3
0%
Низкий
6 дней назад
github логотип
GHSA-xr25-hvc7-fcxm

HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу