Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xjgf-c9ph-cxh2

больше 1 года назад

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockSmtpSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xjgc-mvgw-p5qh

около 4 лет назад

A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xjg9-9f7c-cx46

больше 4 лет назад

In numerous functions of libFDK, there are possible out of bounds writes due to incorrect bounds checks. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112662184

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjg9-924r-39mj

около 4 лет назад

Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-42305.

CVSS3: 6.5
EPSS: Критический
github логотип

GHSA-xjg9-7m45-xm66

около 4 лет назад

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xjg8-5473-5pjp

около 4 лет назад

A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot. This vulnerability is due to insufficient input validation checks while processing boot options. An attacker could exploit this vulnerability by modifying device boot options to execute attacker-provided code. A successful exploit may allow an attacker to bypass the Secure Boot process and execute malicious code on an affected device with root-level privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xjg7-f767-r5hv

около 4 лет назад

A local attacker may be able to view Now Playing information from the lock screen. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6. A privacy issue in Now Playing was addressed with improved permissions.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xjg6-x934-rxf8

больше 4 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Performance Schema). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xjg6-g789-r34w

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xjg6-5v39-v7fc

3 месяца назад

Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion

EPSS: Низкий
github логотип

GHSA-xjg5-j24f-8p55

больше 3 лет назад

The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjg4-r4q3-x4xx

больше 4 лет назад

Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 use AES-128 with ECB mode to encrypt voice traffic between the device and remote server, allowing a malicious user to map encrypted traffic to a particular AES key index and gaining further access to eavesdrop on privacy-sensitive voice communication of a child and their Dino device.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xjg4-m7jw-8486

3 месяца назад

Use after free in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xjg4-fwj3-xr89

около 2 лет назад

An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xjg4-367c-227h

больше 1 года назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in appgenixinfotech Firebase OTP Authentication allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through 1.0.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjg3-c793-7v2j

больше 1 года назад

An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjg3-6r75-jcx6

больше 4 лет назад

SQL injection vulnerability in kategori.asp in Muratsoft Haber Portal 3.6 allows remote attackers to execute arbitrary SQL commands via the kat parameter.

EPSS: Низкий
github логотип

GHSA-xjg2-7c9h-gr9w

почти 4 года назад

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/up_booking.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xjg2-2h73-wcm3

больше 4 лет назад

OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xjfx-xwf6-5c7w

больше 4 лет назад

ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjgf-c9ph-cxh2

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockSmtpSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xjgc-mvgw-p5qh

A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjg9-9f7c-cx46

In numerous functions of libFDK, there are possible out of bounds writes due to incorrect bounds checks. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112662184

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjg9-924r-39mj

Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-42305.

CVSS3: 6.5
94%
Критический
около 4 лет назад
github логотип
GHSA-xjg9-7m45-xm66

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
26%
Средний
около 4 лет назад
github логотип
GHSA-xjg8-5473-5pjp

A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot. This vulnerability is due to insufficient input validation checks while processing boot options. An attacker could exploit this vulnerability by modifying device boot options to execute attacker-provided code. A successful exploit may allow an attacker to bypass the Secure Boot process and execute malicious code on an affected device with root-level privileges.

CVSS3: 6.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjg7-f767-r5hv

A local attacker may be able to view Now Playing information from the lock screen. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6. A privacy issue in Now Playing was addressed with improved permissions.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xjg6-x934-rxf8

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Performance Schema). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xjg6-g789-r34w

Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjg6-5v39-v7fc

Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion

0%
Низкий
3 месяца назад
github логотип
GHSA-xjg5-j24f-8p55

The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-xjg4-r4q3-x4xx

Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 use AES-128 with ECB mode to encrypt voice traffic between the device and remote server, allowing a malicious user to map encrypted traffic to a particular AES key index and gaining further access to eavesdrop on privacy-sensitive voice communication of a child and their Dino device.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjg4-m7jw-8486

Use after free in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xjg4-fwj3-xr89

An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xjg4-367c-227h

Authentication Bypass Using an Alternate Path or Channel vulnerability in appgenixinfotech Firebase OTP Authentication allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through 1.0.1.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xjg3-c793-7v2j

An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xjg3-6r75-jcx6

SQL injection vulnerability in kategori.asp in Muratsoft Haber Portal 3.6 allows remote attackers to execute arbitrary SQL commands via the kat parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjg2-7c9h-gr9w

Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/up_booking.php.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-xjg2-2h73-wcm3

OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xjfx-xwf6-5c7w

ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.

5%
Низкий
больше 4 лет назад

Уязвимостей на страницу