Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhc3-g335-68h3

больше 4 лет назад

Array index error in Microsoft Word 2007 SP3, Word 2010 SP2, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Invalid Index Remote Code Execution Vulnerability."

EPSS: Средний
github логотип

GHSA-xhc3-5pgf-p576

около 4 лет назад

subrion CMS Cross Site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhc2-6qjv-5jpp

5 месяцев назад

A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xhc2-42cx-x3vm

больше 4 лет назад

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

EPSS: Низкий
github логотип

GHSA-xh9x-w92m-2jwh

больше 4 лет назад

Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entry processed by metaGetServerList and allow remote metaservers to execute arbitrary code via a long server entry processed by metaGetServerList; (2) allow attackers to have an unknown impact by exceeding the configured number of metaservers; and allow remote attackers to corrupt memory via a SP_CLIENTSTAT packet with certain values of (3) unum or (4) snum, different vulnerabilities than CVE-2003-0933.

EPSS: Низкий
github логотип

GHSA-xh9x-3wgg-3wwg

больше 4 лет назад

NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler's Man-in-the-Middle signature.

EPSS: Низкий
github логотип

GHSA-xh9r-fpvc-x582

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

EPSS: Низкий
github логотип

GHSA-xh9r-6fmf-q43q

почти 3 года назад

The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh9q-q8cm-cwp3

больше 2 лет назад

CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh9q-jvq8-p253

около 3 лет назад

In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xh9q-385r-j657

почти 3 года назад

A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the ESR console. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to elevate their privileges to root and read, write, or delete arbitrary files from the underlying operating system of the affected device. Note: The ESR is not enabled by default and must be licensed. To verify the status of the ESR in the Admin GUI, choose Administration > Settings > Protocols > IPSec.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xh9p-x5hc-hgcp

10 месяцев назад

Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing unauthorized command execution or disclosure of sensitive information.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh9p-p9h3-4958

больше 4 лет назад

Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the num parameter in (a) phonemessage.asp, (2) the catcode parameter in (b) faqDsp.asp, and the (3) Username and (4) Password fields in (c) login.asp.

EPSS: Низкий
github логотип

GHSA-xh9p-h3qw-7x43

больше 4 лет назад

The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.

EPSS: Средний
github логотип

GHSA-xh9m-w5fp-7v4f

почти 3 года назад

In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xh9j-mpc9-2m9p

5 месяцев назад

Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xh9j-gpmv-5c2v

15 дней назад

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as arbitrary file deletion, sensitive data retrieval, or remote code execution. This is an incomplete fix of the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7's earlier object-injection advisories.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-xh9j-cgw9-fq25

больше 4 лет назад

The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbitrary files via a crafted URL.

EPSS: Низкий
github логотип

GHSA-xh9j-9cgx-45h4

около 4 лет назад

Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen.

EPSS: Низкий
github логотип

GHSA-xh9h-92wg-cf4c

около 3 лет назад

In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhc3-g335-68h3

Array index error in Microsoft Word 2007 SP3, Word 2010 SP2, and Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Invalid Index Remote Code Execution Vulnerability."

12%
Средний
больше 4 лет назад
github логотип
GHSA-xhc3-5pgf-p576

subrion CMS Cross Site Scripting (XSS) vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xhc2-6qjv-5jpp

A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

CVSS3: 3.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xhc2-42cx-x3vm

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2015-1924, CVE-2015-1925, CVE-2015-1929, CVE-2015-1930, CVE-2015-1948, CVE-2015-1953, CVE-2015-1962, CVE-2015-1963, CVE-2015-1964, and CVE-2015-1965.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xh9x-w92m-2jwh

Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entry processed by metaGetServerList and allow remote metaservers to execute arbitrary code via a long server entry processed by metaGetServerList; (2) allow attackers to have an unknown impact by exceeding the configured number of metaservers; and allow remote attackers to corrupt memory via a SP_CLIENTSTAT packet with certain values of (3) unum or (4) snum, different vulnerabilities than CVE-2003-0933.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xh9x-3wgg-3wwg

NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler's Man-in-the-Middle signature.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xh9r-fpvc-x582

Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh9r-6fmf-q43q

The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xh9q-q8cm-cwp3

CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xh9q-jvq8-p253

In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xh9q-385r-j657

A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the ESR console. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to elevate their privileges to root and read, write, or delete arbitrary files from the underlying operating system of the affected device. Note: The ESR is not enabled by default and must be licensed. To verify the status of the ESR in the Admin GUI, choose Administration > Settings > Protocols > IPSec.

CVSS3: 6
0%
Низкий
почти 3 года назад
github логотип
GHSA-xh9p-x5hc-hgcp

Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing unauthorized command execution or disclosure of sensitive information.

CVSS3: 8.8
2%
Низкий
10 месяцев назад
github логотип
GHSA-xh9p-p9h3-4958

Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the num parameter in (a) phonemessage.asp, (2) the catcode parameter in (b) faqDsp.asp, and the (3) Username and (4) Password fields in (c) login.asp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh9p-h3qw-7x43

The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.

37%
Средний
больше 4 лет назад
github логотип
GHSA-xh9m-w5fp-7v4f

In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-xh9j-mpc9-2m9p

Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

CVSS3: 5.9
5 месяцев назад
github логотип
GHSA-xh9j-gpmv-5c2v

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as arbitrary file deletion, sensitive data retrieval, or remote code execution. This is an incomplete fix of the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7's earlier object-injection advisories.

CVSS3: 6.6
0%
Низкий
15 дней назад
github логотип
GHSA-xh9j-cgw9-fq25

The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbitrary files via a crafted URL.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh9j-9cgx-45h4

Navigate CMS 2.9 allows XSS via the Alias or Real URL field of the "Web Sites > Create > Aliases > Add" screen.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh9h-92wg-cf4c

In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу