Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xgfr-74fv-qv4q

29 дней назад

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be performed from remote. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xgfr-63pq-c6gp

больше 4 лет назад

The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgfq-m22c-vpjj

больше 4 лет назад

The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.

CVSS3: 2.7
EPSS: Средний
github логотип

GHSA-xgfq-5hc7-wrmc

больше 4 лет назад

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3667, and CVE-2015-3668.

EPSS: Низкий
github логотип

GHSA-xgfp-69mf-fpjr

9 месяцев назад

Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (high) impacts.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-xgfm-fjx6-62mj

больше 2 лет назад

readthedocs-sphinx-search vulnerable to cross-site scripting when including search results from malicious projects

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xgfm-992v-h2hr

около 1 года назад

Magento vulnerable to denial of service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgfj-m585-37q8

около 1 года назад

A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument aemailid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xgfh-xp86-3x5w

11 месяцев назад

A vulnerability has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected is the function findRolePage of the file findSingConfigPage.do. Such manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xgfh-v2r7-p787

больше 4 лет назад

TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgfh-qcrr-cpfq

около 4 лет назад

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgfh-jv6x-46xv

почти 2 года назад

An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgfh-h2p4-f7v7

больше 1 года назад

TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgfh-24vj-5m9m

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

EPSS: Низкий
github логотип

GHSA-xgff-53jx-q4j3

5 месяцев назад

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 4.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgff-48h7-pjqg

больше 4 лет назад

Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.

EPSS: Низкий
github логотип

GHSA-xgff-3pmh-2j23

больше 4 лет назад

Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgfc-fhgr-xpj4

больше 2 лет назад

WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/default/search.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgfc-f3gp-3mp4

больше 4 лет назад

SQL injection vulnerability in plugins/users/index.php in Galatolo WebManager 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-xgf9-j687-mjhj

15 дней назад

Memory Corruption when handling malformed request parameters in the fingerprint TA.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgfr-74fv-qv4q

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be performed from remote. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
0%
Низкий
29 дней назад
github логотип
GHSA-xgfr-63pq-c6gp

The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xgfq-m22c-vpjj

The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.

CVSS3: 2.7
15%
Средний
больше 4 лет назад
github логотип
GHSA-xgfq-5hc7-wrmc

QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3667, and CVE-2015-3668.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xgfp-69mf-fpjr

Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (high) impacts.

CVSS3: 7.9
0%
Низкий
9 месяцев назад
github логотип
GHSA-xgfm-fjx6-62mj

readthedocs-sphinx-search vulnerable to cross-site scripting when including search results from malicious projects

CVSS3: 6.3
больше 2 лет назад
github логотип
GHSA-xgfm-992v-h2hr

Magento vulnerable to denial of service

CVSS3: 7.5
1%
Низкий
около 1 года назад
github логотип
GHSA-xgfj-m585-37q8

A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument aemailid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xgfh-xp86-3x5w

A vulnerability has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected is the function findRolePage of the file findSingConfigPage.do. Such manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xgfh-v2r7-p787

TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xgfh-qcrr-cpfq

TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xgfh-jv6x-46xv

An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function

CVSS3: 7.5
2%
Низкий
почти 2 года назад
github логотип
GHSA-xgfh-h2p4-f7v7

TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xgfh-24vj-5m9m

Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgff-53jx-q4j3

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 4.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xgff-48h7-pjqg

Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgff-3pmh-2j23

Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xgfc-fhgr-xpj4

WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/default/search.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xgfc-f3gp-3mp4

SQL injection vulnerability in plugins/users/index.php in Galatolo WebManager 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgf9-j687-mjhj

Memory Corruption when handling malformed request parameters in the fingerprint TA.

CVSS3: 7.8
0%
Низкий
15 дней назад

Уязвимостей на страницу