Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhjg-5g5x-rccw

около 3 лет назад

Untrusted search path in the installer for Zoom Rooms before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xhjf-xjwg-rm34

больше 2 лет назад

In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that runs at the root level. This is fixed in ER605(UN)_v2_2.2.4 Build 020240119.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-xhjf-mf8w-q63p

около 4 лет назад

An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.

EPSS: Низкий
github логотип

GHSA-xhjf-fjp3-34r9

больше 3 лет назад

A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the component URL Parameter Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224016.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhjc-f747-7pqf

около 4 лет назад

Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4091.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhjc-54vq-qjm9

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhjc-3h89-4qhf

9 месяцев назад

The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficient API key validation using loose equality comparison. This makes it possible for unauthenticated attackers to retrieve personally identifiable information (PII), including usernames and email addresses of users with various approval statuses via the Zapier REST API endpoints, by exploiting PHP type juggling with the api_key parameter set to "0" on sites where the Zapier API key has not been configured.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xhj9-wqh5-g6hq

8 месяцев назад

An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later QuTS hero h5.3.1.3250 build 20250912 and later

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhj8-r9jm-ff9x

больше 2 лет назад

An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhj8-6h38-6m6j

около 3 лет назад

A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. Affected is an unknown function of the file /admin/del_service.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235242 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xhj8-35xv-vj3p

около 4 лет назад

Use after free in WebAudio in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-xhj8-26hf-x47j

больше 1 года назад

Missing Authorization vulnerability in jidaikobo Dashi allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dashi: from n/a through 3.1.8.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xhj7-pf22-5x9w

почти 3 года назад

Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhj7-jr45-5w8r

больше 4 лет назад

Apache OpenMeetings updates user password in insecure manner

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhj6-r3m9-cx4x

больше 4 лет назад

A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address. This is due to that the server implicitly trusts the Host header, and fails to validate or escape it properly. An attacker can use this input to redirect target users to a malicious domain/web page. This would result in expanding the potential to further attacks and malicious actions.

EPSS: Низкий
github логотип

GHSA-xhj6-6rx2-q3f4

около 4 лет назад

The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case of misconfigured servers with Directory listing enabled, accessing it is trivial.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhj5-rvcv-cccg

около 4 лет назад

ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xhj4-vrgc-hr34

4 месяца назад

actix-http has HTTP/1.1 CL.TE Request Smuggling

EPSS: Низкий
github логотип

GHSA-xhj4-g6w8-2xjw

4 месяца назад

go-zserio has Unbounded Memory Allocation for All Platforms

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhj4-5383-37r2

около 3 лет назад

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhjg-5g5x-rccw

Untrusted search path in the installer for Zoom Rooms before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVSS3: 8.2
0%
Низкий
около 3 лет назад
github логотип
GHSA-xhjf-xjwg-rm34

In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that runs at the root level. This is fixed in ER605(UN)_v2_2.2.4 Build 020240119.

CVSS3: 10
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xhjf-mf8w-q63p

An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.

9%
Низкий
около 4 лет назад
github логотип
GHSA-xhjf-fjp3-34r9

A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the component URL Parameter Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224016.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xhjc-f747-7pqf

Heap-based buffer overflow in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4091.

CVSS3: 9.8
10%
Низкий
около 4 лет назад
github логотип
GHSA-xhjc-54vq-qjm9

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xhjc-3h89-4qhf

The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficient API key validation using loose equality comparison. This makes it possible for unauthenticated attackers to retrieve personally identifiable information (PII), including usernames and email addresses of users with various approval statuses via the Zapier REST API endpoints, by exploiting PHP type juggling with the api_key parameter set to "0" on sites where the Zapier API key has not been configured.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xhj9-wqh5-g6hq

An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later QuTS hero h5.3.1.3250 build 20250912 and later

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xhj8-r9jm-ff9x

An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xhj8-6h38-6m6j

A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. Affected is an unknown function of the file /admin/del_service.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235242 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-xhj8-35xv-vj3p

Use after free in WebAudio in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhj8-26hf-x47j

Missing Authorization vulnerability in jidaikobo Dashi allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dashi: from n/a through 3.1.8.

CVSS3: 5.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xhj7-pf22-5x9w

Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.

CVSS3: 7.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xhj7-jr45-5w8r

Apache OpenMeetings updates user password in insecure manner

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xhj6-r3m9-cx4x

A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address. This is due to that the server implicitly trusts the Host header, and fails to validate or escape it properly. An attacker can use this input to redirect target users to a malicious domain/web page. This would result in expanding the potential to further attacks and malicious actions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhj6-6rx2-q3f4

The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case of misconfigured servers with Directory listing enabled, accessing it is trivial.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xhj5-rvcv-cccg

ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.

CVSS3: 6
0%
Низкий
около 4 лет назад
github логотип
GHSA-xhj4-vrgc-hr34

actix-http has HTTP/1.1 CL.TE Request Smuggling

4 месяца назад
github логотип
GHSA-xhj4-g6w8-2xjw

go-zserio has Unbounded Memory Allocation for All Platforms

CVSS3: 9.8
4 месяца назад
github логотип
GHSA-xhj4-5383-37r2

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.

CVSS3: 5.9
1%
Низкий
около 3 лет назад

Уязвимостей на страницу