Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjq5-7h7q-37wc

больше 4 лет назад

CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.

EPSS: Низкий
github логотип

GHSA-xjq4-w8f6-7xc7

2 месяца назад

Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xjq4-2q47-63c2

больше 4 лет назад

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjq3-p9vw-4qrf

больше 1 года назад

Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function, causing an arbitrary command execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjq3-33j2-xcwm

больше 1 года назад

Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xjq2-x47m-hqr8

больше 4 лет назад

The uploads module in vTiger CRM 4.2 and earlier allows remote attackers to upload arbitrary files, such as PHP files, via the add2db action.

EPSS: Низкий
github логотип

GHSA-xjpw-qmp3-4x22

больше 1 года назад

A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that exceeds the buffer size.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xjpw-mc8f-p786

больше 4 лет назад

The ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows remote attackers to cause a denial of service (infinite loop) via a crafted HDR file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xjpw-hx47-rccv

больше 2 лет назад

PaddlePaddle floating point exception in paddle.nanmedian

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xjpv-4c4j-wwp8

больше 1 года назад

An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjpv-48qr-cg8g

около 4 лет назад

The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.

EPSS: Низкий
github логотип

GHSA-xjpv-2h98-wpc7

больше 4 лет назад

Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjpr-5xvx-vr58

больше 4 лет назад

OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse package. This has security implications in cases where untrusted users can trigger CallOPKG calls, and these users can enter an arbitrary URL in an input field, even though that input field was only intended for a package name. This threat model may be relevant in the latest versions of third-party products that bundle OpenWebif, i.e., set-top box products. The issue of Trojan horse packages does NOT have security implications in cases where the attacker has full OpenWebif access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xjpq-q5j9-jvwc

больше 4 лет назад

at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.

EPSS: Низкий
github логотип

GHSA-xjpq-hgc7-6jvh

около 4 лет назад

The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation where a temporary table has been created, even though this cached data is intended only for situations where a temporary table has not been created, which might allow remote attackers to obtain sensitive information via a search.

EPSS: Низкий
github логотип

GHSA-xjpq-582q-q6mh

около 4 лет назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1407.

EPSS: Средний
github логотип

GHSA-xjpp-q586-9whh

около 4 лет назад

An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjpm-crjx-x784

5 месяцев назад

A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xjpm-62p5-jw4j

2 месяца назад

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xjpj-vg2h-c82v

около 4 лет назад

SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjq5-7h7q-37wc

CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjq4-w8f6-7xc7

Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.3
0%
Низкий
2 месяца назад
github логотип
GHSA-xjq4-2q47-63c2

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
7%
Низкий
больше 4 лет назад
github логотип
GHSA-xjq3-p9vw-4qrf

Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function, causing an arbitrary command execution.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xjq3-33j2-xcwm

Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjq2-x47m-hqr8

The uploads module in vTiger CRM 4.2 and earlier allows remote attackers to upload arbitrary files, such as PHP files, via the add2db action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjpw-qmp3-4x22

A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that exceeds the buffer size.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjpw-mc8f-p786

The ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows remote attackers to cause a denial of service (infinite loop) via a crafted HDR file.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjpw-hx47-rccv

PaddlePaddle floating point exception in paddle.nanmedian

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xjpv-4c4j-wwp8

An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xjpv-48qr-cg8g

The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xjpv-2h98-wpc7

Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjpr-5xvx-vr58

OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse package. This has security implications in cases where untrusted users can trigger CallOPKG calls, and these users can enter an arbitrary URL in an input field, even though that input field was only intended for a package name. This threat model may be relevant in the latest versions of third-party products that bundle OpenWebif, i.e., set-top box products. The issue of Trojan horse packages does NOT have security implications in cases where the attacker has full OpenWebif access.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjpq-q5j9-jvwc

at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xjpq-hgc7-6jvh

The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation where a temporary table has been created, even though this cached data is intended only for situations where a temporary table has not been created, which might allow remote attackers to obtain sensitive information via a search.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjpq-582q-q6mh

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1407.

13%
Средний
около 4 лет назад
github логотип
GHSA-xjpp-q586-9whh

An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjpm-crjx-x784

A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xjpm-62p5-jw4j

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-xjpj-vg2h-c82v

SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу