Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjjh-4gfx-3jfp

почти 2 года назад

A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjjg-vmw6-c2p9

почти 7 лет назад

Open Redirect in httpie

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xjjg-fcrx-3pm6

больше 4 лет назад

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xjjg-5fvp-6fv2

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Real Estate WordPress Theme: from n/a before 2.8.3.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xjjf-f7j2-766f

около 4 лет назад

Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjjc-xf36-3jp9

около 2 лет назад

Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjjc-j4cj-mpm6

больше 4 лет назад

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 31116.

EPSS: Низкий
github логотип

GHSA-xjjc-hxq8-fxj5

29 дней назад

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xjjc-g7ww-xfq5

10 месяцев назад

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user accounts are created.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjjc-g3r4-r6xr

около 4 лет назад

The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.

EPSS: Низкий
github логотип

GHSA-xjjc-8jjh-rwv3

больше 4 лет назад

Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xjj9-gqgq-pccf

около 4 лет назад

Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xjj9-3q77-6c55

около 4 лет назад

A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-xjj9-2w6f-jg55

5 месяцев назад

Duplicate Advisory: OpenClaw safeBins file-existence oracle information disclosure

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xjj8-r7cf-g6w9

больше 4 лет назад

In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function wma_roam_synch_event_handler, vdev_id is received from firmware and used to access an array without validation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjj7-h4hj-89mh

около 4 лет назад

The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in a "virsh vol-upload" command.

EPSS: Низкий
github логотип

GHSA-xjj7-5xwp-h6p7

около 3 лет назад

IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executable file in the path of the affected service. IBM X-Force ID: 249194.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xjj7-3ggm-8mm7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xjj7-3469-hmrm

около 4 лет назад

SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts leading to Reflected Cross-Site Scripting (XSS) vulnerability.

EPSS: Низкий
github логотип

GHSA-xjj6-hgq2-689x

около 4 лет назад

OpsRamp Gateway 3.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjjh-4gfx-3jfp

A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xjjg-vmw6-c2p9

Open Redirect in httpie

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
github логотип
GHSA-xjjg-fcrx-3pm6

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjjg-5fvp-6fv2

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Real Estate WordPress Theme: from n/a before 2.8.3.

CVSS3: 8.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xjjf-f7j2-766f

Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjjc-xf36-3jp9

Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xjjc-j4cj-mpm6

The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 31116.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xjjc-hxq8-fxj5

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can exploit mismatched environment configurations to persist or execute actions that exceed the caller's approved permissions.

CVSS3: 8.8
0%
Низкий
29 дней назад
github логотип
GHSA-xjjc-g7ww-xfq5

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user accounts are created.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xjjc-g3r4-r6xr

The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjjc-8jjh-rwv3

Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xjj9-gqgq-pccf

Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xjj9-3q77-6c55

A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.

CVSS3: 7.2
24%
Средний
около 4 лет назад
github логотип
GHSA-xjj9-2w6f-jg55

Duplicate Advisory: OpenClaw safeBins file-existence oracle information disclosure

CVSS3: 3.3
5 месяцев назад
github логотип
GHSA-xjj8-r7cf-g6w9

In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function wma_roam_synch_event_handler, vdev_id is received from firmware and used to access an array without validation.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xjj7-h4hj-89mh

The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in a "virsh vol-upload" command.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xjj7-5xwp-h6p7

IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executable file in the path of the affected service. IBM X-Force ID: 249194.

CVSS3: 8.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-xjj7-3ggm-8mm7

Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xjj7-3469-hmrm

SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts leading to Reflected Cross-Site Scripting (XSS) vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjj6-hgq2-689x

OpsRamp Gateway 3.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server.

3%
Низкий
около 4 лет назад

Уязвимостей на страницу