Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xm48-7mjf-v22c

10 месяцев назад

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the UPDATE_VALUE parameter when updating the default time synchronization settings. When the default values displayed on the Time Server page are updated, the application issues an HTTP POST request to /cgi-bin/time.cgi, and the synchronization value is provided in the UPDATE_VALUE parameter. The value of this parameter is stored and later rendered in the web interface without proper sanitation or encoding, allowing injected scripts to execute in the context of other users who view the affected Time Server configuration page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xm47-42m3-whpm

больше 4 лет назад

Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF request.

EPSS: Средний
github логотип

GHSA-xm46-35x5-j3c7

около 4 лет назад

An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.

EPSS: Низкий
github логотип

GHSA-xm45-c62q-jmp8

24 дня назад

Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xm44-79f8-q8r7

около 2 лет назад

The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xm43-qc4p-9f7j

около 4 лет назад

An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.

EPSS: Низкий
github логотип

GHSA-xm43-3m56-w3wf

10 дней назад

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xm42-xfgp-mh86

7 месяцев назад

Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path by placing malicious executables in specific filesystem locations that will be executed with LocalSystem permissions during service startup.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xm42-x3fj-82gw

больше 4 лет назад

PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriver.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xm42-w58j-mp94

около 1 месяца назад

A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application.

EPSS: Низкий
github логотип

GHSA-xm42-v588-gp5m

около 4 лет назад

Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) newlang or (2) newtheme parameter.

EPSS: Низкий
github логотип

GHSA-xm42-j6p3-h49f

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Vertical Web Pricing Tables allows Reflected XSS. This issue affects CSS3 Vertical Web Pricing Tables: from n/a through 1.9.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xm3x-9cfw-jhx4

около 2 месяцев назад

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xm3x-7w4f-6pg6

около 4 лет назад

DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xm3x-787m-p66r

больше 4 лет назад

Cross-site Scripting in ShowDoc

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xm3x-5hpf-5369

почти 3 года назад

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

CVSS3: 7.2
EPSS: Высокий
github логотип

GHSA-xm3x-4ph3-3x9c

около 2 лет назад

friendsofsymfony/oauth2-php open redirection in oauth

EPSS: Низкий
github логотип

GHSA-xm3x-2cx4-fh5j

около 4 лет назад

In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155647761

EPSS: Низкий
github логотип

GHSA-xm3w-4959-2496

больше 4 лет назад

In ic_startRetrieveEntryValue of acropora/app/identity/ic.c, there is a possible bypass of defense-in-depth due to missing validation of the return value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195573629References: N/A

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xm3v-f6hx-79h4

больше 4 лет назад

The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse EAPoL-Key packets, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a malformed EAPoL-Key packet with a crafted "advertised length."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xm48-7mjf-v22c

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the UPDATE_VALUE parameter when updating the default time synchronization settings. When the default values displayed on the Time Server page are updated, the application issues an HTTP POST request to /cgi-bin/time.cgi, and the synchronization value is provided in the UPDATE_VALUE parameter. The value of this parameter is stored and later rendered in the web interface without proper sanitation or encoding, allowing injected scripts to execute in the context of other users who view the affected Time Server configuration page.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-xm47-42m3-whpm

Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF request.

37%
Средний
больше 4 лет назад
github логотип
GHSA-xm46-35x5-j3c7

An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xm45-c62q-jmp8

Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026.

CVSS3: 6.5
0%
Низкий
24 дня назад
github логотип
GHSA-xm44-79f8-q8r7

The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.

CVSS3: 7.2
3%
Низкий
около 2 лет назад
github логотип
GHSA-xm43-qc4p-9f7j

An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xm43-3m56-w3wf

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

CVSS3: 5.3
0%
Низкий
10 дней назад
github логотип
GHSA-xm42-xfgp-mh86

Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path by placing malicious executables in specific filesystem locations that will be executed with LocalSystem permissions during service startup.

CVSS3: 8.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-xm42-x3fj-82gw

PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriver.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xm42-w58j-mp94

A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application.

0%
Низкий
около 1 месяца назад
github логотип
GHSA-xm42-v588-gp5m

Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) newlang or (2) newtheme parameter.

7%
Низкий
около 4 лет назад
github логотип
GHSA-xm42-j6p3-h49f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 Vertical Web Pricing Tables allows Reflected XSS. This issue affects CSS3 Vertical Web Pricing Tables: from n/a through 1.9.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xm3x-9cfw-jhx4

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

CVSS3: 5.3
около 2 месяцев назад
github логотип
GHSA-xm3x-7w4f-6pg6

DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code.

CVSS3: 7.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-xm3x-787m-p66r

Cross-site Scripting in ShowDoc

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm3x-5hpf-5369

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

CVSS3: 7.2
90%
Высокий
почти 3 года назад
github логотип
GHSA-xm3x-4ph3-3x9c

friendsofsymfony/oauth2-php open redirection in oauth

около 2 лет назад
github логотип
GHSA-xm3x-2cx4-fh5j

In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155647761

0%
Низкий
около 4 лет назад
github логотип
GHSA-xm3w-4959-2496

In ic_startRetrieveEntryValue of acropora/app/identity/ic.c, there is a possible bypass of defense-in-depth due to missing validation of the return value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-195573629References: N/A

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xm3v-f6hx-79h4

The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse EAPoL-Key packets, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a malformed EAPoL-Key packet with a crafted "advertised length."

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу