Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xgpp-xqc8-gr5w

больше 4 лет назад

SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands via the password parameter.

EPSS: Низкий
github логотип

GHSA-xgpp-v9mr-6fg2

около 2 месяцев назад

The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without authentication via the plugin's frontend routing system. The _filename parameter is accepted with RAW filter (no sanitization), and the helper function makePathFile() only normalizes directory separator characters without stripping path traversal sequences (../). When combined with the _path_type=2 parameter, which sets the base directory to the plugin's site folder, an attacker can supply a _filename value containing ../ sequences to traverse outside the plugin directory and call PHP's unlink() on arbitrary files — including wp-config.php, wp-config-backup.php, or other critical server files accessible to the web server process. This makes it possible for unauthenticated at...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xgpm-xf5g-45m5

9 месяцев назад

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xgpm-q3mq-46rq

больше 2 лет назад

PrestaShop some attribute not escaped in Validate::isCleanHTML method

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xgpm-hq77-53g9

больше 4 лет назад

Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5132.

EPSS: Средний
github логотип

GHSA-xgpm-76vc-4m4p

больше 4 лет назад

The mintToken function of a smart contract implementation for CM, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgpm-2v6j-vx8q

4 месяца назад

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xgpj-r9f2-8ghw

больше 4 лет назад

mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### temporary file, probably a related issue to CVE-2005-2995.

EPSS: Низкий
github логотип

GHSA-xgpj-c6vr-4w93

почти 3 года назад

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-xgph-v3ch-chmg

около 4 лет назад

Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgph-j3rr-ghx9

больше 3 лет назад

3D Builder Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21780, CVE-2023-21781, CVE-2023-21782, CVE-2023-21783, CVE-2023-21784, CVE-2023-21785, CVE-2023-21786, CVE-2023-21787, CVE-2023-21789, CVE-2023-21790, CVE-2023-21791, CVE-2023-21792, CVE-2023-21793.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgph-64jm-fq69

больше 2 лет назад

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgpg-w5r9-97qh

10 месяцев назад

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a Denial of Service when an attacker sends malformed MM packets to the target.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgpg-34fv-3xwr

почти 2 года назад

In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgpf-xc53-xgr5

больше 4 лет назад

The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (type confusion and application crash) via crafted serialized _cookies data, related to the SoapClient::__call method in ext/soap/soap.c.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xgpf-p52j-pf7m

больше 5 лет назад

XSS in CreateQueuedJobTask

EPSS: Низкий
github логотип

GHSA-xgpf-25jc-xvgf

19 дней назад

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xgpc-r53m-pqc6

2 месяца назад

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-xgpc-r328-jcfc

больше 3 лет назад

Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgpc-q899-67p8

больше 1 года назад

Fleet doesn’t validate a server’s certificate when connecting through SSH

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgpp-xqc8-gr5w

SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands via the password parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgpp-v9mr-6fg2

The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without authentication via the plugin's frontend routing system. The _filename parameter is accepted with RAW filter (no sanitization), and the helper function makePathFile() only normalizes directory separator characters without stripping path traversal sequences (../). When combined with the _path_type=2 parameter, which sets the base directory to the plugin's site folder, an attacker can supply a _filename value containing ../ sequences to traverse outside the plugin directory and call PHP's unlink() on arbitrary files — including wp-config.php, wp-config-backup.php, or other critical server files accessible to the web server process. This makes it possible for unauthenticated at...

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xgpm-xf5g-45m5

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xgpm-q3mq-46rq

PrestaShop some attribute not escaped in Validate::isCleanHTML method

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xgpm-hq77-53g9

Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5131 and CVE-2015-5132.

51%
Средний
больше 4 лет назад
github логотип
GHSA-xgpm-76vc-4m4p

The mintToken function of a smart contract implementation for CM, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgpm-2v6j-vx8q

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

CVSS3: 6.7
1%
Низкий
4 месяца назад
github логотип
GHSA-xgpj-r9f2-8ghw

mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### temporary file, probably a related issue to CVE-2005-2995.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xgpj-c6vr-4w93

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.

CVSS3: 5.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-xgph-v3ch-chmg

Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xgph-j3rr-ghx9

3D Builder Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21780, CVE-2023-21781, CVE-2023-21782, CVE-2023-21783, CVE-2023-21784, CVE-2023-21785, CVE-2023-21786, CVE-2023-21787, CVE-2023-21789, CVE-2023-21790, CVE-2023-21791, CVE-2023-21792, CVE-2023-21793.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xgph-64jm-fq69

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xgpg-w5r9-97qh

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a Denial of Service when an attacker sends malformed MM packets to the target.

CVSS3: 7.5
1%
Низкий
10 месяцев назад
github логотип
GHSA-xgpg-34fv-3xwr

In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xgpf-xc53-xgr5

The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (type confusion and application crash) via crafted serialized _cookies data, related to the SoapClient::__call method in ext/soap/soap.c.

CVSS3: 7.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xgpf-p52j-pf7m

XSS in CreateQueuedJobTask

1%
Низкий
больше 5 лет назад
github логотип
GHSA-xgpf-25jc-xvgf

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 9.6
0%
Низкий
19 дней назад
github логотип
GHSA-xgpc-r53m-pqc6

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.

CVSS3: 9
0%
Низкий
2 месяца назад
github логотип
GHSA-xgpc-r328-jcfc

Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xgpc-q899-67p8

Fleet doesn’t validate a server’s certificate when connecting through SSH

CVSS3: 6.3
больше 1 года назад

Уязвимостей на страницу