Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xpx7-5x44-3fqq

около 4 лет назад

IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xpx7-27p8-r55q

больше 4 лет назад

IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.

EPSS: Низкий
github логотип

GHSA-xpx6-hwxg-rj79

около 4 лет назад

The Master Mix (aka com.nobexinc.wls_24832536.rc) application 3.3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xpx5-8gpf-9924

9 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpx4-57h5-9v98

9 месяцев назад

A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct save_path and save files. This allows remote attackers to perform arbitrary file writes outside the intended directory by sending crafted POST requests with malicious traversal sequences to /share/file/ upload endpoint, which does not require any authorization.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpx2-vc3f-pg29

около 4 лет назад

SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.

EPSS: Низкий
github логотип

GHSA-xpww-g9jx-hp8r

около 4 лет назад

Miscomputed sha2 results when using AVX2 backend

EPSS: Низкий
github логотип

GHSA-xpww-f6pm-cfhq

3 месяца назад

dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xpwv-rp39-7pr7

около 4 лет назад

Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpwv-gcc7-5gwp

больше 2 лет назад

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpwv-75x9-38q4

больше 2 лет назад

Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpwr-42qv-5j22

больше 4 лет назад

Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown impact and remote authenticated attack vectors related to sys.dbms_scheduler, aka Vuln# DB19.

EPSS: Низкий
github логотип

GHSA-xpwq-w665-cf7c

больше 4 лет назад

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."

EPSS: Средний
github логотип

GHSA-xpwq-r3f8-686w

4 месяца назад

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpwq-h27p-5wg9

почти 4 года назад

FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpwq-6mfc-rr7g

около 4 лет назад

Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xpwp-rq3x-x6v7

почти 8 лет назад

Critical severity vulnerability that affects recurly-api-client

EPSS: Низкий
github логотип

GHSA-xpwp-hgm6-qgh5

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html.

EPSS: Низкий
github логотип

GHSA-xpwm-vrv5-5mgm

почти 2 года назад

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xpwm-m5cr-whm7

около 4 лет назад

A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897394.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpx7-5x44-3fqq

IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xpx7-27p8-r55q

IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpx6-hwxg-rj79

The Master Mix (aka com.nobexinc.wls_24832536.rc) application 3.3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xpx5-8gpf-9924

Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17.

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xpx4-57h5-9v98

A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct save_path and save files. This allows remote attackers to perform arbitrary file writes outside the intended directory by sending crafted POST requests with malicious traversal sequences to /share/file/ upload endpoint, which does not require any authorization.

CVSS3: 7.5
1%
Низкий
9 месяцев назад
github логотип
GHSA-xpx2-vc3f-pg29

SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xpww-g9jx-hp8r

Miscomputed sha2 results when using AVX2 backend

около 4 лет назад
github логотип
GHSA-xpww-f6pm-cfhq

dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xpwv-rp39-7pr7

Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpwv-gcc7-5gwp

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpwv-75x9-38q4

Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpwr-42qv-5j22

Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown impact and remote authenticated attack vectors related to sys.dbms_scheduler, aka Vuln# DB19.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xpwq-w665-cf7c

Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."

21%
Средний
больше 4 лет назад
github логотип
GHSA-xpwq-r3f8-686w

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xpwq-h27p-5wg9

FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function.

CVSS3: 8.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-xpwq-6mfc-rr7g

Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpwp-rq3x-x6v7

Critical severity vulnerability that affects recurly-api-client

3%
Низкий
почти 8 лет назад
github логотип
GHSA-xpwp-hgm6-qgh5

Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpwm-vrv5-5mgm

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.

CVSS3: 8.6
1%
Низкий
почти 2 года назад
github логотип
GHSA-xpwm-m5cr-whm7

A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897394.

CVSS3: 7.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу