Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh8q-x6hw-jhv5

около 2 месяцев назад

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xh8q-wvvw-q9w3

около 4 лет назад

Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve server-side denial of service. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

EPSS: Низкий
github логотип

GHSA-xh8q-q4r3-6x29

больше 4 лет назад

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

EPSS: Низкий
github логотип

GHSA-xh8q-jh7v-55g2

около 1 года назад

A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Lua Admin Console. The manipulation leads to execution with unnecessary privileges. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 7.4.4 is able to address this issue. It is recommended to upgrade the affected component. The vendor explains: "[W]e do not consider it as a security vulnerability, because the system admin in WingFTP has full permissions [...], but you can suggest the user run WingFTP service as Normal User rather than SYSTEM/Root, it will be safer."

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-xh8q-gjf3-g988

больше 4 лет назад

SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than CVE-2009-2567.

EPSS: Низкий
github логотип

GHSA-xh8p-p48j-92w6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.

EPSS: Низкий
github логотип

GHSA-xh8p-8v2c-5w7v

больше 1 года назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail allows Retrieve Embedded Sensitive Data. This issue affects weMail: from n/a through 1.14.13.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xh8m-w9h2-4fc7

3 месяца назад

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled cookie value without proper sanitization, allowing directory traversal and bypass of authentication.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh8m-9gqq-4g7c

больше 4 лет назад

D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-880L A* before v1.20B02Beta devices allow authenticated remote command execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh8j-pqxf-hqm9

больше 4 лет назад

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows remote attackers to cause a denial of service (CPU consumption) via a crafted RSA public key.

EPSS: Низкий
github логотип

GHSA-xh8j-8x8h-3f2m

около 4 лет назад

OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts.

EPSS: Низкий
github логотип

GHSA-xh8h-mfrv-w6wh

8 месяцев назад

SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to potentially execute arbitrary code and crash the application.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh8h-4qpj-8wx6

около 3 лет назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously crafted AppleScript binary may result in unexpected app termination or disclosure of process memory.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xh8g-j88w-6v59

почти 6 лет назад

Malicious Package in cionstring

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xh8f-vjvr-825x

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in highwarden Super Store Finder allows Cross-Site Scripting (XSS).This issue affects Super Store Finder: from n/a through 6.9.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xh8f-g2qw-gcm7

3 месяца назад

MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xh8f-45cf-2xqc

почти 3 года назад

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh8c-gmc9-9v6x

больше 3 лет назад

Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xh89-vmqr-6c3j

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.

EPSS: Низкий
github логотип

GHSA-xh89-f5vr-hmhw

почти 2 года назад

Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh8q-x6hw-jhv5

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xh8q-wvvw-q9w3

Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve server-side denial of service. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh8q-q4r3-6x29

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xh8q-jh7v-55g2

A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Lua Admin Console. The manipulation leads to execution with unnecessary privileges. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 7.4.4 is able to address this issue. It is recommended to upgrade the affected component. The vendor explains: "[W]e do not consider it as a security vulnerability, because the system admin in WingFTP has full permissions [...], but you can suggest the user run WingFTP service as Normal User rather than SYSTEM/Root, it will be safer."

CVSS3: 6.6
1%
Низкий
около 1 года назад
github логотип
GHSA-xh8q-gjf3-g988

SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than CVE-2009-2567.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh8p-p48j-92w6

Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh8p-8v2c-5w7v

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail allows Retrieve Embedded Sensitive Data. This issue affects weMail: from n/a through 1.14.13.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh8m-w9h2-4fc7

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled cookie value without proper sanitization, allowing directory traversal and bypass of authentication.

CVSS3: 9.8
1%
Низкий
3 месяца назад
github логотип
GHSA-xh8m-9gqq-4g7c

D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-880L A* before v1.20B02Beta devices allow authenticated remote command execution.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xh8j-pqxf-hqm9

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows remote attackers to cause a denial of service (CPU consumption) via a crafted RSA public key.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xh8j-8x8h-3f2m

OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh8h-mfrv-w6wh

SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to potentially execute arbitrary code and crash the application.

CVSS3: 9.8
1%
Низкий
8 месяцев назад
github логотип
GHSA-xh8h-4qpj-8wx6

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously crafted AppleScript binary may result in unexpected app termination or disclosure of process memory.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xh8g-j88w-6v59

Malicious Package in cionstring

CVSS3: 9.1
почти 6 лет назад
github логотип
GHSA-xh8f-vjvr-825x

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in highwarden Super Store Finder allows Cross-Site Scripting (XSS).This issue affects Super Store Finder: from n/a through 6.9.7.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xh8f-g2qw-gcm7

MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint

CVSS3: 4.9
8%
Низкий
3 месяца назад
github логотип
GHSA-xh8f-45cf-2xqc

In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xh8c-gmc9-9v6x

Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.

CVSS3: 8.8
32%
Средний
больше 3 лет назад
github логотип
GHSA-xh89-vmqr-6c3j

Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh89-f5vr-hmhw

Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.

CVSS3: 9.8
1%
Низкий
почти 2 года назад

Уязвимостей на страницу