Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xgwr-j735-3wg4

9 дней назад

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xgwr-cg3h-pjvj

4 месяца назад

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBind results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgwq-r73w-qq4g

3 месяца назад

A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument EncrypType/wl_Pass is directly passed by the attacker/so we can control the EncrypType/wl_Pass results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xgwp-wf98-3xhc

около 4 лет назад

Unauthenticated redirection to a malicious website

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgwp-88wx-4cww

около 4 лет назад

The wp-database-backup plugin before 4.3.3 for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgwm-rhgp-jr5w

около 4 лет назад

BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.

EPSS: Низкий
github логотип

GHSA-xgwm-9vr8-389w

около 4 лет назад

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-28313, CVE-2021-28321.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgwj-qm2p-hcpc

больше 4 лет назад

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.

EPSS: Низкий
github логотип

GHSA-xgwj-fj27-7g4m

3 дня назад

In the Linux kernel, the following vulnerability has been resolved: hwmon: adm1275: Prevent reading uninitialized stack While adding support for the ROHM BD127X0 hot-swap controllers, sashiko reported an error in device-name comparison, which can lead to reading uninitialized stack memory. Quoting Sashiko: This is a pre-existing issue, but I noticed that just before this block in adm1275_probe(), there might be an out-of-bounds stack read: ret = i2c_smbus_read_block_data(client, PMBUS_MFR_MODEL, block_buffer); if (ret < 0) { ... } for (mid = adm1275_id; mid->name[0]; mid++) { if (!strncasecmp(mid->name, block_buffer, strlen(mid->name))) break; } Since i2c_smbus_read_block_data() reads up to 32 bytes into the uninitialized stack array block_buffer without appending a null terminator, strncasecmp() could read past the valid bytes returned in ret. For example, if the device returns a shorter string like "adm12", checking it against...

EPSS: Низкий
github логотип

GHSA-xgwj-62j7-h8hh

больше 4 лет назад

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

CVSS3: 8.6
EPSS: Средний
github логотип

GHSA-xgwh-cgv9-783v

около 2 лет назад

Ghost allows CSV Injection during member CSV export

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgwh-9xmj-ghm4

около 4 лет назад

An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgwg-wqmg-vwwp

больше 4 лет назад

Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.

EPSS: Низкий
github логотип

GHSA-xgwg-m42c-8q62

5 месяцев назад

Duplicate Advisory: OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xgwf-26wj-q43v

около 4 лет назад

Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is executed.

EPSS: Низкий
github логотип

GHSA-xgwc-rmqj-wxqr

больше 4 лет назад

A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied. The vulnerability is due to the incorrect handling of SSL-encrypted traffic when Decrypt for End-User Notification is disabled in the configuration. An attacker could exploit this vulnerability by sending a SSL connection through the affected device. A successful exploit could allow the attacker to bypass a configured drop policy to block specific SSL connections. Releases 10.1.x and 10.5.x are affected.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xgw9-335v-h35w

12 месяцев назад

The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ni_woocpr_action() function in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xgw8-wc8h-j56g

около 2 лет назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-xgw8-47vc-hmfh

около 4 лет назад

All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. This information was only presented in the menus when authenticated, and the pages that loaded this information were also protected. However, all files that contained the configuration parameters were accessible. These files contained sensitive information, such as users, community strings, and other passwords configured in the printer.

EPSS: Низкий
github логотип

GHSA-xgw7-5955-3jv7

больше 4 лет назад

Unspecified vulnerability in the (1) Sun Convergence 1 and (2) Sun Java Communications Suite 7 components in Oracle Sun Products Suite 1.0 and 7.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Webmail.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgwr-j735-3wg4

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component.

CVSS3: 5.3
0%
Низкий
9 дней назад
github логотип
GHSA-xgwr-cg3h-pjvj

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBind results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xgwq-r73w-qq4g

A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument EncrypType/wl_Pass is directly passed by the attacker/so we can control the EncrypType/wl_Pass results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.

CVSS3: 6.3
5%
Низкий
3 месяца назад
github логотип
GHSA-xgwp-wf98-3xhc

Unauthenticated redirection to a malicious website

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-xgwp-88wx-4cww

The wp-database-backup plugin before 4.3.3 for WordPress has XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xgwm-rhgp-jr5w

BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xgwm-9vr8-389w

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-28313, CVE-2021-28321.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xgwj-qm2p-hcpc

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xgwj-fj27-7g4m

In the Linux kernel, the following vulnerability has been resolved: hwmon: adm1275: Prevent reading uninitialized stack While adding support for the ROHM BD127X0 hot-swap controllers, sashiko reported an error in device-name comparison, which can lead to reading uninitialized stack memory. Quoting Sashiko: This is a pre-existing issue, but I noticed that just before this block in adm1275_probe(), there might be an out-of-bounds stack read: ret = i2c_smbus_read_block_data(client, PMBUS_MFR_MODEL, block_buffer); if (ret < 0) { ... } for (mid = adm1275_id; mid->name[0]; mid++) { if (!strncasecmp(mid->name, block_buffer, strlen(mid->name))) break; } Since i2c_smbus_read_block_data() reads up to 32 bytes into the uninitialized stack array block_buffer without appending a null terminator, strncasecmp() could read past the valid bytes returned in ret. For example, if the device returns a shorter string like "adm12", checking it against...

0%
Низкий
3 дня назад
github логотип
GHSA-xgwj-62j7-h8hh

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

CVSS3: 8.6
36%
Средний
больше 4 лет назад
github логотип
GHSA-xgwh-cgv9-783v

Ghost allows CSV Injection during member CSV export

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xgwh-9xmj-ghm4

An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xgwg-wqmg-vwwp

Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgwg-m42c-8q62

Duplicate Advisory: OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers

CVSS3: 5.4
5 месяцев назад
github логотип
GHSA-xgwf-26wj-q43v

Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is executed.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xgwc-rmqj-wxqr

A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied. The vulnerability is due to the incorrect handling of SSL-encrypted traffic when Decrypt for End-User Notification is disabled in the configuration. An attacker could exploit this vulnerability by sending a SSL connection through the affected device. A successful exploit could allow the attacker to bypass a configured drop policy to block specific SSL connections. Releases 10.1.x and 10.5.x are affected.

CVSS3: 5.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgw9-335v-h35w

The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ni_woocpr_action() function in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-xgw8-wc8h-j56g

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 2 лет назад
github логотип
GHSA-xgw8-47vc-hmfh

All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. This information was only presented in the menus when authenticated, and the pages that loaded this information were also protected. However, all files that contained the configuration parameters were accessible. These files contained sensitive information, such as users, community strings, and other passwords configured in the printer.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xgw7-5955-3jv7

Unspecified vulnerability in the (1) Sun Convergence 1 and (2) Sun Java Communications Suite 7 components in Oracle Sun Products Suite 1.0 and 7.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Webmail.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу