Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xj2q-cpcq-554c

6 месяцев назад

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the ID parameter. Attackers can craft requests to the /manage/ips/appid/ endpoint with script payloads in the ID parameter to execute arbitrary JavaScript in victim browsers.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xj2p-gvrg-v6wm

около 4 лет назад

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The SiNVR 3 Central Control Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. A remote attacker with network access to the CCS server could exploit this vulnerability to read the CCS users database, including the passwords of all users in obfuscated cleartext.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj2p-4gc4-hvf5

около 3 лет назад

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xj2m-wgjq-qpmc

почти 3 года назад

PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xj2j-8x6x-4m9r

около 4 лет назад

Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7647.

EPSS: Средний
github логотип

GHSA-xj2h-mwjp-6j9v

больше 4 лет назад

SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-xj2g-mmx3-fq3p

больше 2 лет назад

File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to obtain sensitive information via the uploadfile.php component.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xj2g-cv86-vc2c

около 2 лет назад

DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account. The affected products and versions are as follows: CENTUM CS 3000 R3.08.10 to R3.09.50 CENTUM VP R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.11.10.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xj2f-r9jm-5w6p

больше 4 лет назад

An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xj2c-g5xp-4p47

около 2 месяцев назад

Duplicate Advisory: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xj2c-76v8-mh2r

больше 4 лет назад

Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.

EPSS: Низкий
github логотип

GHSA-xj29-gfww-j67g

больше 3 лет назад

Jenkins JaCoCo Plugin vulnerable to Stored Cross-site Scripting

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xj28-8c9f-6cgg

почти 4 года назад

The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xj28-57qv-77hc

больше 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xj27-f2rc-xf55

11 месяцев назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-13967. Reason: This record is a reservation duplicate of CVE-2024-13967. Notes: All CVE users should reference CVE-2024-13967 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

EPSS: Низкий
github логотип

GHSA-xj26-qh36-fcxp

больше 3 лет назад

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj26-gx3h-x793

больше 1 года назад

Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xj25-753j-wgp9

3 месяца назад

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder

EPSS: Низкий
github логотип

GHSA-xj25-4829-7rv5

около 4 лет назад

Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=user/manage_user&id=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xj24-hv97-964g

почти 4 года назад

IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xj2q-cpcq-554c

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the ID parameter. Attackers can craft requests to the /manage/ips/appid/ endpoint with script payloads in the ID parameter to execute arbitrary JavaScript in victim browsers.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-xj2p-gvrg-v6wm

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The SiNVR 3 Central Control Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. A remote attacker with network access to the CCS server could exploit this vulnerability to read the CCS users database, including the passwords of all users in obfuscated cleartext.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xj2p-4gc4-hvf5

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xj2m-wgjq-qpmc

PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xj2j-8x6x-4m9r

Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7647.

30%
Средний
около 4 лет назад
github логотип
GHSA-xj2h-mwjp-6j9v

SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj2g-mmx3-fq3p

File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to obtain sensitive information via the uploadfile.php component.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xj2g-cv86-vc2c

DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account. The affected products and versions are as follows: CENTUM CS 3000 R3.08.10 to R3.09.50 CENTUM VP R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.11.10.

CVSS3: 8.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xj2f-r9jm-5w6p

An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.

CVSS3: 4.3
5%
Низкий
больше 4 лет назад
github логотип
GHSA-xj2c-g5xp-4p47

Duplicate Advisory: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

CVSS3: 4.3
около 2 месяцев назад
github логотип
GHSA-xj2c-76v8-mh2r

Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj29-gfww-j67g

Jenkins JaCoCo Plugin vulnerable to Stored Cross-site Scripting

CVSS3: 8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xj28-8c9f-6cgg

The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xj28-57qv-77hc

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xj27-f2rc-xf55

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-13967. Reason: This record is a reservation duplicate of CVE-2024-13967. Notes: All CVE users should reference CVE-2024-13967 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

11 месяцев назад
github логотип
GHSA-xj26-qh36-fcxp

In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xj26-gx3h-x793

Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

CVSS3: 9.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xj25-753j-wgp9

Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder

0%
Низкий
3 месяца назад
github логотип
GHSA-xj25-4829-7rv5

Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=user/manage_user&id=.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-xj24-hv97-964g

IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.

CVSS3: 9.8
5%
Низкий
почти 4 года назад

Уязвимостей на страницу