Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh58-cx6c-2h9h

больше 4 лет назад

Heap-based buffer overflow in the K7FWFilt.sys kernel mode driver (aka K7Firewall Packet Driver) before 14.0.1.16, as used in multiple K7 Computing products, allows local users to execute arbitrary code with kernel privileges via a crafted parameter in a DeviceIoControl API call.

EPSS: Низкий
github логотип

GHSA-xh57-2h8m-3798

около 2 лет назад

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh56-mjcr-q6vw

5 месяцев назад

Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh56-g7w6-x8rp

больше 4 лет назад

The view-source feature in Google Chrome before 16.0.912.63 allows remote attackers to spoof the URL bar via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xh56-fj78-hc8j

больше 4 лет назад

Untrusted search path vulnerability in TKY2JGD (TKY2JGD1379.EXE) ver. 1.3.79 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xh56-3xp6-p447

больше 4 лет назад

IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh56-3f5w-9h25

почти 8 лет назад

nodemailer-js is malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh56-3cv8-89c9

около 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Andrea Tarantini Menubar plugin <= 5.8.2 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xh56-37r6-8jjx

больше 4 лет назад

WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been fixed in 2.1.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh55-2fqp-p775

почти 5 лет назад

Command injection in mail agent settings

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh54-v5gh-jq8v

9 месяцев назад

The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it back in the page, leading to reflected cross-site scripting, which could be used against high-privilege users such as admins.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xh54-hh7j-wm53

больше 4 лет назад

ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.

EPSS: Низкий
github логотип

GHSA-xh54-7xjp-2239

больше 3 лет назад

An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xh53-wc36-2h2x

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo allows Cross Site Request Forgery. This issue affects Findgo: from n/a through 1.3.57.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh53-849p-cfvq

почти 2 года назад

D-Link DI-8400 16.07.26A1 is vulnerable to Command Injection via upgrade_filter_asp.

CVSS3: 8
EPSS: Средний
github логотип

GHSA-xh53-2m5x-5pw7

больше 4 лет назад

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xh52-rg2r-x4m5

почти 4 года назад

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh52-6wwc-2j2x

около 4 лет назад

Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.

EPSS: Низкий
github логотип

GHSA-xh52-5493-q8vx

около 1 года назад

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RP_checkFWByBBS of the file /goform/RP_checkFWByBBS. The manipulation of the argument type/ch/ssidhex/security/extch/pwd/mode/ip/nm/gw leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Средний
github логотип

GHSA-xh4x-ph6p-vmxh

больше 4 лет назад

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh58-cx6c-2h9h

Heap-based buffer overflow in the K7FWFilt.sys kernel mode driver (aka K7Firewall Packet Driver) before 14.0.1.16, as used in multiple K7 Computing products, allows local users to execute arbitrary code with kernel privileges via a crafted parameter in a DeviceIoControl API call.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh57-2h8m-3798

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-xh56-mjcr-q6vw

Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xh56-g7w6-x8rp

The view-source feature in Google Chrome before 16.0.912.63 allows remote attackers to spoof the URL bar via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh56-fj78-hc8j

Untrusted search path vulnerability in TKY2JGD (TKY2JGD1379.EXE) ver. 1.3.79 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh56-3xp6-p447

IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh56-3f5w-9h25

nodemailer-js is malware

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
github логотип
GHSA-xh56-3cv8-89c9

Cross-Site Request Forgery (CSRF) vulnerability in Andrea Tarantini Menubar plugin <= 5.8.2 versions.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-xh56-37r6-8jjx

WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been fixed in 2.1.1.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xh55-2fqp-p775

Command injection in mail agent settings

CVSS3: 8.8
2%
Низкий
почти 5 лет назад
github логотип
GHSA-xh54-v5gh-jq8v

The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it back in the page, leading to reflected cross-site scripting, which could be used against high-privilege users such as admins.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-xh54-hh7j-wm53

ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xh54-7xjp-2239

An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xh53-wc36-2h2x

Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo allows Cross Site Request Forgery. This issue affects Findgo: from n/a through 1.3.57.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xh53-849p-cfvq

D-Link DI-8400 16.07.26A1 is vulnerable to Command Injection via upgrade_filter_asp.

CVSS3: 8
14%
Средний
почти 2 года назад
github логотип
GHSA-xh53-2m5x-5pw7

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh52-rg2r-x4m5

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xh52-6wwc-2j2x

Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh52-5493-q8vx

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RP_checkFWByBBS of the file /goform/RP_checkFWByBBS. The manipulation of the argument type/ch/ssidhex/security/extch/pwd/mode/ip/nm/gw leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
21%
Средний
около 1 года назад
github логотип
GHSA-xh4x-ph6p-vmxh

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

CVSS3: 8.1
8%
Низкий
больше 4 лет назад

Уязвимостей на страницу