Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-xqxm-2rpm-3889

больше 4 лет назад

Comment reply notifications sent to incorrect users

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xqxj-x89x-6rq4

больше 2 лет назад

Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xqxh-xcx3-fff7

около 1 года назад

Improper Control of Generation of Code ('Code Injection') vulnerability in ABB ASPECT.This issue affects ASPECT: before <3.08.04-s01.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xqxh-qgrp-wxhr

около 2 месяцев назад

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xqxh-p7r4-xgw7

больше 4 лет назад

UR+ (Universal Robots+) is a platform of hardware and software component sellers, for Universal Robots robots. When installing any of these components in the robots (e.g. in the UR10), no integrity checks are performed. Moreover, the SDK for making such components can be easily obtained from Universal Robots. An attacker could exploit this flaw by crafting a custom component with the SDK, performing Person-In-The-Middle attacks (PITM) and shipping the maliciously-crafted component on demand.

EPSS: Низкий
github логотип

GHSA-xqxh-cq77-r6qh

почти 5 лет назад

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-xqxh-7x7w-p8r9

больше 4 лет назад

A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xqxh-7jrj-2mvm

больше 4 лет назад

In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025789.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqxg-hxfm-4q7f

больше 4 лет назад

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.

EPSS: Средний
github логотип

GHSA-xqxg-8497-rcpx

около 4 лет назад

The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqxf-w779-5jrr

больше 4 лет назад

An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xqxf-q4xj-jxh3

4 месяца назад

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqxf-jjq4-grw6

больше 4 лет назад

Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

EPSS: Низкий
github логотип

GHSA-xqxc-xrjc-68wf

больше 4 лет назад

F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xqxc-x9r4-3vjh

около 2 месяцев назад

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xqxc-x6p3-w683

больше 1 года назад

Deno run with --allow-read and --deny-read flags results in allowed

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xqxc-r4xh-rx35

больше 4 лет назад

zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

EPSS: Средний
github логотип

GHSA-xqxc-72vf-v8f5

8 месяцев назад

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Wi...

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xqxc-686p-m2m3

почти 3 года назад

The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xqx8-64m4-pqcg

больше 4 лет назад

DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqxm-2rpm-3889

Comment reply notifications sent to incorrect users

CVSS3: 3.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqxj-x89x-6rq4

Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqxh-xcx3-fff7

Improper Control of Generation of Code ('Code Injection') vulnerability in ABB ASPECT.This issue affects ASPECT: before <3.08.04-s01.

CVSS3: 7
1%
Низкий
около 1 года назад
github логотип
GHSA-xqxh-qgrp-wxhr

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xqxh-p7r4-xgw7

UR+ (Universal Robots+) is a platform of hardware and software component sellers, for Universal Robots robots. When installing any of these components in the robots (e.g. in the UR10), no integrity checks are performed. Moreover, the SDK for making such components can be easily obtained from Universal Robots. An attacker could exploit this flaw by crafting a custom component with the SDK, performing Person-In-The-Middle attacks (PITM) and shipping the maliciously-crafted component on demand.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqxh-cq77-r6qh

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

CVSS3: 7.5
97%
Критический
почти 5 лет назад
github логотип
GHSA-xqxh-7x7w-p8r9

A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqxh-7jrj-2mvm

In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025789.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqxg-hxfm-4q7f

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.

14%
Средний
больше 4 лет назад
github логотип
GHSA-xqxg-8497-rcpx

The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xqxf-w779-5jrr

An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xqxf-q4xj-jxh3

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xqxf-jjq4-grw6

Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqxc-xrjc-68wf

F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xqxc-x9r4-3vjh

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

CVSS3: 9.9
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-xqxc-x6p3-w683

Deno run with --allow-read and --deny-read flags results in allowed

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqxc-r4xh-rx35

zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

12%
Средний
больше 4 лет назад
github логотип
GHSA-xqxc-72vf-v8f5

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Wi...

CVSS3: 6.4
1%
Низкий
8 месяцев назад
github логотип
GHSA-xqxc-686p-m2m3

The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xqx8-64m4-pqcg

DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу