Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhf5-2xwr-3gp9

больше 4 лет назад

The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-screen - ensuring only those who can view it are streaming.All Epson projectors supporting the "EasyMP" software are vulnerable to a brute-force vulnerability, allowing any attacker on the network to remotely control and stream to the vulnerable device

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhf4-qqf8-2pw6

больше 1 года назад

Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xhf4-8pfh-6cmf

почти 3 года назад

A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xhf4-832v-7xcr

11 дней назад

rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xhf3-pp4q-gxh5

около 2 лет назад

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xhf2-76w5-8cfq

около 4 лет назад

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating as the remote support user and submitting malicious input to a specific command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system (OS) with root privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xhf2-5c6w-86fx

около 1 года назад

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL trhough the id_concesion parameter in /<Client>FacturaE/VerFacturaPDF.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhcw-78wg-7hj8

около 4 лет назад

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=user/manage_user&id=.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhcw-5f8j-45f2

около 4 лет назад

Azure DevOps Server Spoofing Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhcv-5x87-p5v6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in sample-forms/simple-contact-form-with-preview/simple-contact-form-with-preview.html in MitriDAT eMail Form Processor Pro allows remote attackers to inject arbitrary web script or HTML via the base_path parameter, possibly related to (1) formprocessorpro.php in the PHP version of the product, and (2) formprocessorpro.pl in the Perl version of the product.

EPSS: Низкий
github логотип

GHSA-xhcv-4cg2-46v5

больше 1 года назад

The TP-Link Tapo C500 V1 and V2 are a pan-and-tilt outdoor Wi-Fi security cameras designed for comprehensive surveillance. This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device.

EPSS: Низкий
github логотип

GHSA-xhcq-fv7x-grr2

больше 7 лет назад

Critical severity vulnerability that affects org.apache.solr:solr-core

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-xhcq-9mcp-rrvr

6 месяцев назад

GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICNS files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28530.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhcp-wrwf-p86r

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xhcp-hwcp-p5wq

больше 4 лет назад

There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xhcp-54vp-9q62

больше 1 года назад

Missing Authorization vulnerability in dgamoni LocateAndFilter allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects LocateAndFilter: from n/a through 1.6.16.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xhcm-8344-w8gw

около 4 лет назад

In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.

EPSS: Низкий
github логотип

GHSA-xhcj-9vv5-9686

больше 2 лет назад

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhcj-87mg-4cx4

около 4 лет назад

A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerability is due to inadequate parsing mechanisms for specific email body components. An attacker could exploit this vulnerability by sending a malicious email containing a high number of shortened URLs through an affected device. A successful exploit could allow the attacker to consume processing resources, causing a DoS condition on an affected device. To successfully exploit this vulnerability, certain conditions beyond the control of the attacker must occur.

EPSS: Низкий
github логотип

GHSA-xhch-ppc4-w2v4

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a before 2.10.8.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhf5-2xwr-3gp9

The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-screen - ensuring only those who can view it are streaming.All Epson projectors supporting the "EasyMP" software are vulnerable to a brute-force vulnerability, allowing any attacker on the network to remotely control and stream to the vulnerable device

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xhf4-qqf8-2pw6

Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xhf4-8pfh-6cmf

A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-xhf4-832v-7xcr

rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory

CVSS3: 5.9
0%
Низкий
11 дней назад
github логотип
GHSA-xhf3-pp4q-gxh5

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

CVSS3: 7.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-xhf2-76w5-8cfq

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating as the remote support user and submitting malicious input to a specific command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system (OS) with root privileges.

CVSS3: 6.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-xhf2-5c6w-86fx

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL trhough the id_concesion parameter in /<Client>FacturaE/VerFacturaPDF.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xhcw-78wg-7hj8

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=user/manage_user&id=.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xhcw-5f8j-45f2

Azure DevOps Server Spoofing Vulnerability

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xhcv-5x87-p5v6

Cross-site scripting (XSS) vulnerability in sample-forms/simple-contact-form-with-preview/simple-contact-form-with-preview.html in MitriDAT eMail Form Processor Pro allows remote attackers to inject arbitrary web script or HTML via the base_path parameter, possibly related to (1) formprocessorpro.php in the PHP version of the product, and (2) formprocessorpro.pl in the Perl version of the product.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhcv-4cg2-46v5

The TP-Link Tapo C500 V1 and V2 are a pan-and-tilt outdoor Wi-Fi security cameras designed for comprehensive surveillance. This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device.

0%
Низкий
больше 1 года назад
github логотип
GHSA-xhcq-fv7x-grr2

Critical severity vulnerability that affects org.apache.solr:solr-core

CVSS3: 9.8
78%
Высокий
больше 7 лет назад
github логотип
GHSA-xhcq-9mcp-rrvr

GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICNS files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28530.

CVSS3: 7.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-xhcp-wrwf-p86r

Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xhcp-hwcp-p5wq

There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.

CVSS3: 7.2
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xhcp-54vp-9q62

Missing Authorization vulnerability in dgamoni LocateAndFilter allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects LocateAndFilter: from n/a through 1.6.16.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xhcm-8344-w8gw

In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xhcj-9vv5-9686

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xhcj-87mg-4cx4

A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerability is due to inadequate parsing mechanisms for specific email body components. An attacker could exploit this vulnerability by sending a malicious email containing a high number of shortened URLs through an affected device. A successful exploit could allow the attacker to consume processing resources, causing a DoS condition on an affected device. To successfully exploit this vulnerability, certain conditions beyond the control of the attacker must occur.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xhch-ppc4-w2v4

Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a before 2.10.8.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу