Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-xfx2-prg5-jq3g

6 месяцев назад

INSATutorat has an authorization bypass vulnerability in its /api/admin/* endpoints

EPSS: Низкий
github логотип

GHSA-xfwx-x943-x38c

10 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart SEO smartSEO allows SQL Injection.This issue affects smart SEO: from n/a through <= 4.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xfwx-g8wm-38q3

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit....

EPSS: Низкий
github логотип

GHSA-xfwx-792p-42fx

почти 4 года назад

Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xfwx-2q8g-38ph

около 1 года назад

A vulnerability was determined in Netis WF2419 1.2.29433. This vulnerability affects unknown code of the file /index.htm of the component Wireless Settings Page. This manipulation of the argument SSID with the input <img/src/onerror=prompt(8)> causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-xfww-6hgp-m5c5

около 4 лет назад

A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request.

EPSS: Низкий
github логотип

GHSA-xfww-5m83-7972

около 4 лет назад

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112610994

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xfwv-95wj-h3jj

больше 3 лет назад

This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xfwr-rc6r-49xf

больше 4 лет назад

IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM X-Force ID: 127406.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xfwq-mh5v-7fg5

больше 3 лет назад

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xfwq-gq62-2hc2

больше 4 лет назад

sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xfwp-f8wr-x3j8

больше 4 лет назад

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xfwp-87xx-cqvf

около 4 лет назад

The Samsung J6 Android device with a build fingerprint of samsung/j6ltexx/j6lte:8.0.0/R16NW/J600FNXXU3ASC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.

EPSS: Низкий
github логотип

GHSA-xfwm-9jhj-mjg4

около 3 лет назад

In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xfwm-3cfp-v279

больше 4 лет назад

tss 0.8.1 allows local users to read arbitrary files via the -a parameter, which is processed while tss is running with privileges.

EPSS: Низкий
github логотип

GHSA-xfwj-2f34-32f5

больше 4 лет назад

Jenkins Groovy Plugin sandbox bypass vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xfwh-gc4w-mg75

больше 4 лет назад

Opera before 9.61 does not properly block scripts during preview of a news feed, which allows remote attackers to create arbitrary new feed subscriptions and read the contents of arbitrary feeds.

EPSS: Низкий
github логотип

GHSA-xfwh-3cg2-6hcv

больше 4 лет назад

An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xfwg-78fh-5fcq

больше 4 лет назад

ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/resolv.conf.tmp temporary file.

EPSS: Низкий
github логотип

GHSA-xfwf-x9cr-g95x

около 4 лет назад

GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xfx2-prg5-jq3g

INSATutorat has an authorization bypass vulnerability in its /api/admin/* endpoints

6 месяцев назад
github логотип
GHSA-xfwx-x943-x38c

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart SEO smartSEO allows SQL Injection.This issue affects smart SEO: from n/a through <= 4.0.

CVSS3: 8.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xfwx-g8wm-38q3

Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit....

9%
Низкий
больше 4 лет назад
github логотип
GHSA-xfwx-792p-42fx

Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xfwx-2q8g-38ph

A vulnerability was determined in Netis WF2419 1.2.29433. This vulnerability affects unknown code of the file /index.htm of the component Wireless Settings Page. This manipulation of the argument SSID with the input <img/src/onerror=prompt(8)> causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
около 1 года назад
github логотип
GHSA-xfww-6hgp-m5c5

A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xfww-5m83-7972

In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112610994

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xfwv-95wj-h3jj

This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xfwr-rc6r-49xf

IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM X-Force ID: 127406.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xfwq-mh5v-7fg5

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xfwq-gq62-2hc2

sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xfwp-f8wr-x3j8

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.

CVSS3: 7.5
10%
Средний
больше 4 лет назад
github логотип
GHSA-xfwp-87xx-cqvf

The Samsung J6 Android device with a build fingerprint of samsung/j6ltexx/j6lte:8.0.0/R16NW/J600FNXXU3ASC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xfwm-9jhj-mjg4

In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xfwm-3cfp-v279

tss 0.8.1 allows local users to read arbitrary files via the -a parameter, which is processed while tss is running with privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xfwj-2f34-32f5

Jenkins Groovy Plugin sandbox bypass vulnerability

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xfwh-gc4w-mg75

Opera before 9.61 does not properly block scripts during preview of a news feed, which allows remote attackers to create arbitrary new feed subscriptions and read the contents of arbitrary feeds.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xfwh-3cg2-6hcv

An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xfwg-78fh-5fcq

ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/resolv.conf.tmp temporary file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xfwf-x9cr-g95x

GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу