Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjj6-f689-gwr9

больше 3 лет назад

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjj6-3w9q-h5xv

около 4 лет назад

Improper access control in subsystem for BlueZ before version 5.53 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xjj5-rj2r-8v2w

около 4 лет назад

A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjj5-mp7v-39hq

больше 2 лет назад

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xjj5-69gv-xxqg

больше 4 лет назад

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.

EPSS: Низкий
github логотип

GHSA-xjj4-w934-3vj9

больше 4 лет назад

Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.

EPSS: Низкий
github логотип

GHSA-xjj4-qhcp-574p

около 3 лет назад

A vulnerability classified as critical was found in SourceCodester Online Exam System 1.0. This vulnerability affects unknown code of the file /kelasdosen/data. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-229276.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xjj4-8mx7-wf4q

почти 2 года назад

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects systems with BGP traceoptions enabled and requires a BGP session to be already established.  Systems without BGP traceoptions enabled are not affected by this issue. This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability. This issue affects: Junos OS:  * All versions before 21.2R3-S8,  * from 21.4 before 21.4R3-S8,  * from 22.2 before 22.2R3-S4,  * from 22.3 before 22.3R3-S4, * from 22.4 before 22.4R3-S3,  * from 23.2 before 23.2R2-S1,  * from 23.4 before 23.4R2;  Junos OS Ev...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjj4-3gwf-mwqh

почти 2 года назад

The issue was addressed with improved checks. This issue is fixed in tvOS 17.6, visionOS 1.3, Safari 17.6, watchOS 10.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xjj2-r3pr-m35h

больше 4 лет назад

Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xjhx-x9fp-x5mx

около 2 лет назад

Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This issue affects WordPress Manutenção: from n/a through 1.0.6.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xjhx-h6x5-g77v

около 4 лет назад

The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuu51839.

EPSS: Низкий
github логотип

GHSA-xjhx-fvc5-fv5p

около 4 лет назад

Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.

EPSS: Низкий
github логотип

GHSA-xjhw-gq27-xgjr

больше 1 года назад

Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjhw-7765-363q

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apptivo Apptivo Business Site CRM plugin <= 3.0.12 versions.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xjhw-6jx7-jr2f

больше 4 лет назад

Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjhv-v822-pf94

6 месяцев назад

Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

EPSS: Низкий
github логотип

GHSA-xjhv-pp2r-6f82

3 месяца назад

BoxLite has a Timeout Bypass Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjhv-p3fv-x24r

больше 2 лет назад

In Reactor Netty HTTP Server a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjhv-m7vj-8xjp

больше 4 лет назад

Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjj6-f689-gwr9

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xjj6-3w9q-h5xv

Improper access control in subsystem for BlueZ before version 5.53 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access.

CVSS3: 7.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjj5-rj2r-8v2w

A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjj5-mp7v-39hq

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xjj5-69gv-xxqg

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-xjj4-w934-3vj9

Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xjj4-qhcp-574p

A vulnerability classified as critical was found in SourceCodester Online Exam System 1.0. This vulnerability affects unknown code of the file /kelasdosen/data. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-229276.

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-xjj4-8mx7-wf4q

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition. This issue only affects systems with BGP traceoptions enabled and requires a BGP session to be already established.  Systems without BGP traceoptions enabled are not affected by this issue. This issue affects iBGP and eBGP, and both IPv4 and IPv6 are affected by this vulnerability. This issue affects: Junos OS:  * All versions before 21.2R3-S8,  * from 21.4 before 21.4R3-S8,  * from 22.2 before 22.2R3-S4,  * from 22.3 before 22.3R3-S4, * from 22.4 before 22.4R3-S3,  * from 23.2 before 23.2R2-S1,  * from 23.4 before 23.4R2;  Junos OS Ev...

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xjj4-3gwf-mwqh

The issue was addressed with improved checks. This issue is fixed in tvOS 17.6, visionOS 1.3, Safari 17.6, watchOS 10.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xjj2-r3pr-m35h

Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjhx-x9fp-x5mx

Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This issue affects WordPress Manutenção: from n/a through 1.0.6.

CVSS3: 3.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xjhx-h6x5-g77v

The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuu51839.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xjhx-fvc5-fv5p

Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xjhw-gq27-xgjr

Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xjhw-7765-363q

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apptivo Apptivo Business Site CRM plugin <= 3.0.12 versions.

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xjhw-6jx7-jr2f

Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjhv-v822-pf94

Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

0%
Низкий
6 месяцев назад
github логотип
GHSA-xjhv-pp2r-6f82

BoxLite has a Timeout Bypass Vulnerability

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xjhv-p3fv-x24r

In Reactor Netty HTTP Server a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xjhv-m7vj-8xjp

Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll.

6%
Низкий
больше 4 лет назад

Уязвимостей на страницу