Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xq57-vcxr-jv32

больше 4 лет назад

hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

EPSS: Низкий
github логотип

GHSA-xq55-4x3m-2f97

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of NEF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11192.

EPSS: Низкий
github логотип

GHSA-xq54-x54m-vcpx

больше 1 года назад

Drupal core Denial of Service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq54-mqmx-3733

около 4 лет назад

SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq54-j4gh-pm4j

больше 4 лет назад

gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

EPSS: Низкий
github логотип

GHSA-xq54-fg9w-jw52

около 1 месяца назад

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xq54-79cv-mcq9

больше 4 лет назад

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq52-whfh-4w3m

около 4 лет назад

In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to code execution, denial of service, or escalation of privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xq52-rv6w-397c

больше 6 лет назад

Directive injection when using dynamic overrides with user input

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xq52-7mcc-4gqf

около 4 лет назад

An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.

EPSS: Низкий
github логотип

GHSA-xq4x-622m-q8fq

3 месяца назад

LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-xq4w-54fw-79jc

около 4 лет назад

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

EPSS: Низкий
github логотип

GHSA-xq4v-vrp9-vcf2

около 4 лет назад

Cross-site Scripting vulnerability in repository issue list in Gogs

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xq4v-f742-g2rw

больше 3 лет назад

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_sonos, at 0x9d01c1cc, the value for the `s_speaker` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xq4v-f5xw-jqg4

около 4 лет назад

Microsoft Excel 2002 SP3; Office 2004, 2008, and 2011 for Mac; and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Heap Overwrite Vulnerability."

EPSS: Средний
github логотип

GHSA-xq4v-69gf-r78f

больше 2 лет назад

In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq4v-6896-qq49

около 4 лет назад

WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xq4v-2p5j-7jj7

2 месяца назад

Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup' parameter to read arbitrary data from the database.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xq4r-xr6r-76qw

около 4 лет назад

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq4r-rq82-x9jj

около 2 месяцев назад

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq57-vcxr-jv32

hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-xq55-4x3m-2f97

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of NEF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11192.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xq54-x54m-vcpx

Drupal core Denial of Service

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq54-mqmx-3733

SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xq54-j4gh-pm4j

gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xq54-fg9w-jw52

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xq54-79cv-mcq9

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xq52-whfh-4w3m

In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to code execution, denial of service, or escalation of privileges.

CVSS3: 6.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-xq52-rv6w-397c

Directive injection when using dynamic overrides with user input

CVSS3: 4.4
2%
Низкий
больше 6 лет назад
github логотип
GHSA-xq52-7mcc-4gqf

An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq4x-622m-q8fq

LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution

CVSS3: 6.2
0%
Низкий
3 месяца назад
github логотип
GHSA-xq4w-54fw-79jc

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq4v-vrp9-vcf2

Cross-site Scripting vulnerability in repository issue list in Gogs

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq4v-f742-g2rw

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_sonos, at 0x9d01c1cc, the value for the `s_speaker` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xq4v-f5xw-jqg4

Microsoft Excel 2002 SP3; Office 2004, 2008, and 2011 for Mac; and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Heap Overwrite Vulnerability."

13%
Средний
около 4 лет назад
github логотип
GHSA-xq4v-69gf-r78f

In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq4v-6896-qq49

WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq4v-2p5j-7jj7

Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup' parameter to read arbitrary data from the database.

CVSS3: 8.2
0%
Низкий
2 месяца назад
github логотип
GHSA-xq4r-xr6r-76qw

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq4r-rq82-x9jj

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу