Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-xprw-xvvm-vqmv

около 4 лет назад

Improper Access Control in Apache Derby

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xprw-r8hx-4rqm

больше 1 года назад

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager allows Object Injection. This issue affects Booking and Rental Manager: from n/a through 2.2.6.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xprw-mh67-9xf5

6 месяцев назад

Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xprv-wvh7-qqqx

почти 4 года назад

Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xprv-fqx6-cfrr

около 4 лет назад

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords.

EPSS: Низкий
github логотип

GHSA-xprv-cc7m-2c6q

7 месяцев назад

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xprr-mw6x-6m8m

больше 2 лет назад

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. For the free version, this is limited to administrators. The pro version is also vulnerable and exploitable by administrators, but also offers the functionality to lower level users (as low as subscribers) if enabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xprr-fxcx-qr72

около 4 лет назад

A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system. A successful exploit would consist of an attacker persuading an authorized user to follow a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user.

EPSS: Низкий
github логотип

GHSA-xprr-92x5-gfg6

больше 1 года назад

Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xprr-83m2-vv8v

больше 4 лет назад

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

EPSS: Низкий
github логотип

GHSA-xprq-x9hf-4xcp

около 4 лет назад

The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.

EPSS: Низкий
github логотип

GHSA-xprq-wxmv-vch9

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: efi: runtime: avoid EFIv2 runtime services on Apple x86 machines Aditya reports [0] that his recent MacbookPro crashes in the firmware when using the variable services at runtime. The culprit appears to be a call to QueryVariableInfo(), which we did not use to call on Apple x86 machines in the past as they only upgraded from EFI v1.10 to EFI v2.40 firmware fairly recently, and QueryVariableInfo() (along with UpdateCapsule() et al) was added in EFI v2.00. The only runtime service introduced in EFI v2.00 that we actually use in Linux is QueryVariableInfo(), as the capsule based ones are optional, generally not used at runtime (all the LVFS/fwupd firmware update infrastructure uses helper EFI programs that invoke capsule update at boot time, not runtime), and not implemented by Apple machines in the first place. QueryVariableInfo() is used to 'safely' set variables, i.e., only when there is enough space. This preven...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xprq-8xww-262w

около 4 лет назад

SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xprq-5rwr-7h56

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of administrators via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xprq-37ch-7r6g

больше 4 лет назад

SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the jobid parameter.

EPSS: Низкий
github логотип

GHSA-xprp-8rc7-rgvq

около 4 лет назад

Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Siebel UI Framework.

EPSS: Низкий
github логотип

GHSA-xprp-4qjc-gqwc

около 4 лет назад

Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xprm-wp2v-g9g4

около 4 лет назад

Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstrated by discovering database credentials.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xprj-wrvh-8ppj

около 2 лет назад

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 10
EPSS: Средний
github логотип

GHSA-xprj-64cf-h29h

около 4 лет назад

NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers via the traceroute handler.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xprw-xvvm-vqmv

Improper Access Control in Apache Derby

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xprw-r8hx-4rqm

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager allows Object Injection. This issue affects Booking and Rental Manager: from n/a through 2.2.6.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xprw-mh67-9xf5

Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xprv-wvh7-qqqx

Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-xprv-fqx6-cfrr

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xprv-cc7m-2c6q

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xprr-mw6x-6m8m

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. For the free version, this is limited to administrators. The pro version is also vulnerable and exploitable by administrators, but also offers the functionality to lower level users (as low as subscribers) if enabled.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xprr-fxcx-qr72

A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a CSRF attack against a vulnerable system. A successful exploit would consist of an attacker persuading an authorized user to follow a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xprr-92x5-gfg6

Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xprr-83m2-vv8v

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xprq-x9hf-4xcp

The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xprq-wxmv-vch9

In the Linux kernel, the following vulnerability has been resolved: efi: runtime: avoid EFIv2 runtime services on Apple x86 machines Aditya reports [0] that his recent MacbookPro crashes in the firmware when using the variable services at runtime. The culprit appears to be a call to QueryVariableInfo(), which we did not use to call on Apple x86 machines in the past as they only upgraded from EFI v1.10 to EFI v2.40 firmware fairly recently, and QueryVariableInfo() (along with UpdateCapsule() et al) was added in EFI v2.00. The only runtime service introduced in EFI v2.00 that we actually use in Linux is QueryVariableInfo(), as the capsule based ones are optional, generally not used at runtime (all the LVFS/fwupd firmware update infrastructure uses helper EFI programs that invoke capsule update at boot time, not runtime), and not implemented by Apple machines in the first place. QueryVariableInfo() is used to 'safely' set variables, i.e., only when there is enough space. This preven...

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xprq-8xww-262w

SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xprq-5rwr-7h56

Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of administrators via unspecified vectors.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xprq-37ch-7r6g

SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the jobid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xprp-8rc7-rgvq

Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Siebel UI Framework.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xprp-4qjc-gqwc

Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xprm-wp2v-g9g4

Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstrated by discovering database credentials.

CVSS3: 9.8
11%
Средний
около 4 лет назад
github логотип
GHSA-xprj-wrvh-8ppj

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 10
53%
Средний
около 2 лет назад
github логотип
GHSA-xprj-64cf-h29h

NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers via the traceroute handler.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу