Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-22q5-57p4-rxcv

больше 4 лет назад

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22q4-f5r6-3xqw

больше 2 лет назад

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

CVSS3: 7.3
EPSS: Высокий
github логотип

GHSA-22q4-5758-44qv

больше 4 лет назад

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.

EPSS: Низкий
github логотип

GHSA-22q3-mmfp-g262

больше 4 лет назад

Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.

EPSS: Низкий
github логотип

GHSA-22q3-4v32-4m7c

около 2 лет назад

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-22q3-4g3j-wq87

10 месяцев назад

A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-22q2-ww3p-hj7f

8 месяцев назад

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22q2-gf4f-hvw6

около 1 года назад

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.

EPSS: Низкий
github логотип

GHSA-22px-9px7-pc64

больше 4 лет назад

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

EPSS: Низкий
github логотип

GHSA-22pw-2xmq-86xg

больше 4 лет назад

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.

EPSS: Низкий
github логотип

GHSA-22pv-7v9j-hqxp

больше 4 лет назад

Symfony Host Header Injection vulnerability in the HttpFoundation component

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22pv-795j-9r7p

больше 3 лет назад

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22pv-5hq3-v243

28 дней назад

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22pr-vjq7-4qcg

больше 4 лет назад

The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-22pr-mvmh-vgg5

больше 4 лет назад

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22pp-q7jc-mc64

больше 4 лет назад

PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.

EPSS: Низкий
github логотип

GHSA-22pp-gfq3-734r

больше 4 лет назад

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-22pm-jxcw-xcx5

больше 4 лет назад

There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition. Successful exploit could cause information disclosure.

EPSS: Низкий
github логотип

GHSA-22pm-3j5r-cgw3

около 3 лет назад

The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.1 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-22ph-w354-vrgv

около 4 лет назад

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22q5-57p4-rxcv

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-22q4-f5r6-3xqw

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

CVSS3: 7.3
88%
Высокий
больше 2 лет назад
github логотип
GHSA-22q4-5758-44qv

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-22q3-mmfp-g262

Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-22q3-4v32-4m7c

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.

CVSS3: 4.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-22q3-4g3j-wq87

A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.

CVSS3: 5.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-22q2-ww3p-hj7f

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

CVSS3: 6.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-22q2-gf4f-hvw6

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause command injection in BLMon that is executed in the operating system console when in a SSH session.

0%
Низкий
около 1 года назад
github логотип
GHSA-22px-9px7-pc64

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22pw-2xmq-86xg

Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-22pv-7v9j-hqxp

Symfony Host Header Injection vulnerability in the HttpFoundation component

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-22pv-795j-9r7p

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22pv-5hq3-v243

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.

CVSS3: 7.5
0%
Низкий
28 дней назад
github логотип
GHSA-22pr-vjq7-4qcg

The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-22pr-mvmh-vgg5

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1503, CVE-2020-1583.

CVSS3: 5.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-22pp-q7jc-mc64

PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-22pp-gfq3-734r

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

CVSS3: 8.8
49%
Средний
больше 4 лет назад
github логотип
GHSA-22pm-jxcw-xcx5

There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition. Successful exploit could cause information disclosure.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-22pm-3j5r-cgw3

The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.1 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 7.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-22ph-w354-vrgv

Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.

CVSS3: 6.1
1%
Низкий
около 4 лет назад

Уязвимостей на страницу