Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-xpr2-2m5m-75jw

около 4 лет назад

The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended workstation, which makes it easier for attackers to steal Bitcoin via hook code that runs at a later time when the wallet password has been entered, a different vulnerability than CVE-2018-1000022.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpqx-4wj8-ww45

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Responsive allows DOM-Based XSS. This issue affects Aparat Responsive: from n/a through 1.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpqw-fqpw-35fc

почти 6 лет назад

Directory Traversal in wangguojing123

EPSS: Низкий
github логотип

GHSA-xpqw-6gx7-v673

5 месяцев назад

SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpqw-3mmq-rpcv

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified administrative modules in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allow remote attackers to hijack the authentication of administrators via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xpqv-f82r-327v

около 2 лет назад

Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpqv-37cp-9vj2

больше 4 лет назад

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.

EPSS: Низкий
github логотип

GHSA-xpqq-823p-hvxr

3 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Super Assistent amazonsimpleadmin allows Stored XSS.This issue affects Affiliate Super Assistent: from n/a through <= 1.10.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xpqq-583w-8g73

больше 3 лет назад

VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xpqq-5557-v5jm

почти 2 года назад

Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpqm-wm3m-f34h

7 месяцев назад

pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpqm-h22m-6vxm

около 4 лет назад

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Средний
github логотип

GHSA-xpqm-g5q7-2r7x

больше 1 года назад

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpqm-66vq-xgp8

больше 2 лет назад

Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21437.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpqj-27x8-277f

около 4 лет назад

NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

EPSS: Низкий
github логотип

GHSA-xpqh-grpw-4xmg

4 месяца назад

Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xpqh-2w77-cvcv

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NULL when memory allocation fails. Currently, imx_card_probe() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpqg-5hj3-ggmh

около 2 месяцев назад

Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or Content-Disposition: attachment. This allows an attacker to publish an extension with a malicious SVG icon and achieve stored cross-site scripting (XSS) when a user navigates directly to the icon URL. On deployments using local storage, script execution occurs within the Open VSX application origin, enabling session hijacking, authentication token theft, and unauthorized extension publishing. On deployments backed by external storage (such as open-vsx.org with an S3-backed CDN), execution is confined to the storage origin, reducing impact but still permitting phishing attacks and credential harvesting through attacker-crafted pages.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-xpqf-h5q4-9r99

около 4 лет назад

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xpqc-2xj6-mrm4

больше 3 лет назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpr2-2m5m-75jw

The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended workstation, which makes it easier for attackers to steal Bitcoin via hook code that runs at a later time when the wallet password has been entered, a different vulnerability than CVE-2018-1000022.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xpqx-4wj8-ww45

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Responsive allows DOM-Based XSS. This issue affects Aparat Responsive: from n/a through 1.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpqw-fqpw-35fc

Directory Traversal in wangguojing123

2%
Низкий
почти 6 лет назад
github логотип
GHSA-xpqw-6gx7-v673

SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)

CVSS3: 7.5
1%
Низкий
5 месяцев назад
github логотип
GHSA-xpqw-3mmq-rpcv

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified administrative modules in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allow remote attackers to hijack the authentication of administrators via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xpqv-f82r-327v

Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xpqv-37cp-9vj2

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xpqq-823p-hvxr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Super Assistent amazonsimpleadmin allows Stored XSS.This issue affects Affiliate Super Assistent: from n/a through <= 1.10.1.

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xpqq-583w-8g73

VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.

CVSS3: 8.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xpqq-5557-v5jm

Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xpqm-wm3m-f34h

pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xpqm-h22m-6vxm

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

65%
Средний
около 4 лет назад
github логотип
GHSA-xpqm-g5q7-2r7x

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xpqm-66vq-xgp8

Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21437.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpqj-27x8-277f

NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xpqh-grpw-4xmg

Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xpqh-2w77-cvcv

In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NULL when memory allocation fails. Currently, imx_card_probe() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpqg-5hj3-ggmh

Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or Content-Disposition: attachment. This allows an attacker to publish an extension with a malicious SVG icon and achieve stored cross-site scripting (XSS) when a user navigates directly to the icon URL. On deployments using local storage, script execution occurs within the Open VSX application origin, enabling session hijacking, authentication token theft, and unauthorized extension publishing. On deployments backed by external storage (such as open-vsx.org with an S3-backed CDN), execution is confined to the storage origin, reducing impact but still permitting phishing attacks and credential harvesting through attacker-crafted pages.

CVSS3: 4.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xpqf-h5q4-9r99

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

CVSS3: 7.2
3%
Низкий
около 4 лет назад
github логотип
GHSA-xpqc-2xj6-mrm4

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу