Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-xp8m-46mm-88p5

около 4 лет назад

VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to execute code on the host. Note: IPv6 mode for VMNAT is not enabled by default.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xp8j-r9x7-6rrv

около 4 лет назад

Buffer overflow in the CL_vsprintf function in Takumi Yamada DX Library before 3.16 allows remote attackers to execute arbitrary code via a crafted string.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp8h-v68p-5fwx

5 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Coinpress coinpress allows PHP Local File Inclusion.This issue affects Coinpress: from n/a through <= 1.0.14.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xp8h-mw33-82v7

больше 4 лет назад

vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.

EPSS: Низкий
github логотип

GHSA-xp8h-gc5h-wmff

7 месяцев назад

D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attacker within RF range can transmit continuous interference to block sensor transmissions, resulting in missed alarms and loss of security monitoring. The device lacks jamming detection or mitigations, creating a denial-of-service condition that may lead to undetected intrusions or failure to trigger safety alerts.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp8h-g29p-cq44

около 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Memcached to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp8h-82pc-f6jm

около 2 месяцев назад

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xp8g-v54p-hrcx

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter.

EPSS: Низкий
github логотип

GHSA-xp8g-32qh-mv28

11 месяцев назад

Decap CMS Cross Site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp8f-x545-6j5r

больше 4 лет назад

SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_page action to index.php.

EPSS: Низкий
github логотип

GHSA-xp8f-rxxq-p5wv

больше 1 года назад

The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which may make remote code execution possible assuming the files can be written to by the web server.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xp8f-77p3-p5rv

около 2 лет назад

Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xp8f-6f2w-prw8

около 4 лет назад

The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to cli.html.

EPSS: Низкий
github логотип

GHSA-xp8c-wvr5-8f8x

почти 3 года назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xp8c-vfh9-64v5

почти 3 года назад

There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-xp89-8fq3-96gv

больше 4 лет назад

SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xp89-62wf-p429

больше 4 лет назад

Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to conduct cross-site scripting (XSS) attacks.

EPSS: Низкий
github логотип

GHSA-xp88-vp78-mqm7

больше 1 года назад

Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xp88-ch9m-fp9x

больше 3 лет назад

An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / Admin / System Params] page, and the [Home / Design / Basekey Configuration] page.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xp88-c69g-qmrh

около 4 лет назад

phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp8m-46mm-88p5

VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to execute code on the host. Note: IPv6 mode for VMNAT is not enabled by default.

CVSS3: 7
0%
Низкий
около 4 лет назад
github логотип
GHSA-xp8j-r9x7-6rrv

Buffer overflow in the CL_vsprintf function in Takumi Yamada DX Library before 3.16 allows remote attackers to execute arbitrary code via a crafted string.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xp8h-v68p-5fwx

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Coinpress coinpress allows PHP Local File Inclusion.This issue affects Coinpress: from n/a through <= 1.0.14.

CVSS3: 8.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-xp8h-mw33-82v7

vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xp8h-gc5h-wmff

D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attacker within RF range can transmit continuous interference to block sensor transmissions, resulting in missed alarms and loss of security monitoring. The device lacks jamming detection or mitigations, creating a denial-of-service condition that may lead to undetected intrusions or failure to trigger safety alerts.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xp8h-g29p-cq44

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Memcached to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xp8h-82pc-f6jm

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xp8g-v54p-hrcx

Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xp8g-32qh-mv28

Decap CMS Cross Site Scripting (XSS) vulnerability

CVSS3: 6.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-xp8f-x545-6j5r

SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_page action to index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xp8f-rxxq-p5wv

The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which may make remote code execution possible assuming the files can be written to by the web server.

CVSS3: 7.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-xp8f-77p3-p5rv

Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xp8f-6f2w-prw8

The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to cli.html.

10%
Низкий
около 4 лет назад
github логотип
GHSA-xp8c-wvr5-8f8x

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xp8c-vfh9-64v5

There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.

CVSS3: 10
1%
Низкий
почти 3 года назад
github логотип
GHSA-xp89-8fq3-96gv

SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xp89-62wf-p429

Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to conduct cross-site scripting (XSS) attacks.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xp88-vp78-mqm7

Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp88-ch9m-fp9x

An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / Admin / System Params] page, and the [Home / Design / Basekey Configuration] page.

CVSS3: 6.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xp88-c69g-qmrh

phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.

CVSS3: 9.8
1%
Низкий
около 4 лет назад

Уязвимостей на страницу