Exploit Database
153,618 exploits tracked across all sources.
Telegram 4.8.11 - Authentication Bypass via Runtime Manipulation
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS 6.4
Telegram 4.8.11 - Authentication Bypass via FingerprintManager Callback
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS 6.8
Visiology Flipbox < 2.7.0 - Path Traversal via Filename Parameter
Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.
CVSS 7.5
SolarWinds Database Performance Analyzer 11.1.468 and 12.0.3074 - Stored Cross-Site Scripting
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
CVSS 5.4
Moxa EDR-810 V4.2 build 18041013 - OS Command Injection via caname Parameter
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.
CVSS 8.8
SWIFT Alliance Web Platform 7.1.23 - Log Injection
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjBlnvocationException error log information containing null@java:comp/env/ error messages.
CVSS 7.5
craftedweb < 2013-09-24 - Cross-Site Scripting via p Parameter
CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.
CVSS 6.1
FURUNO FELCOM 250 and 500 - Improper Authentication via Client-Side JavaScript
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.
CVSS 9.8
FURUNO FELCOM 250 and 500 - Unauthenticated Password Change via sm_changepassword.cgi and sm_sms_changepasswd.cgi
FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.
CVSS 9.8
FURUNO FELCOM 250-500 - Info Disclosure
FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts and their unsalted MD5 hashes, as well as the SMS server password in cleartext.
CVSS 9.8
InfluxDB < 0.9.5 - Reflected Cross-Site Scripting in Write Data Module
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
CVSS 4.8
jQuery 2.2.2 - Cross-Site Scripting via IMG onerror Attribute
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry
CVSS 6.1
mysql-binuuid-rails < 1.1.0 - SQL Injection via Default String Escaping Removal
mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.
CVSS 9.8
ZyXEL VMG3312-B10B 1.00(AAPP.7) - Insufficiently Protected Credentials
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
CVSS 9.8
Zyxel VMG1312-B10D <5.13(AAXA.8)C0 - Path Traversal
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.
CVSS 7.5
Cobham Satcom Sailor 250 and 500 Firmware < 1.25 - Unauthenticated Stored Cross-Site Scripting via Phone Book Name Field
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor via the /index.lua?pageID=Phone%20book name field.
CVSS 6.1
Cobham Satcom Sailor 250/500 <1.25 - Unauthenticated RCE
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), without prior knowledge of their password. All that is required is knowledge of the username and attack vector (/index.lua?pageID=Administration usernameAdmChange, passwordAdmChange1, and passwordAdmChange2 fields).
CVSS 9.8
Cobham Satcom Sailor 800/900 - Privilege Escalation
Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. This was exploitable via multiple attack vectors depending on the device's configuration. Further analysis also indicated this vulnerability could be leveraged to achieve a Denial of Service (DoS) condition, where the device would require a factory reset to return to normal operation.
CVSS 7.5
Cobham Satcom Sailor 800 and 900 Firmware - Authenticated Stored Cross-Site Scripting via Configuration File Restore
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.
CVSS 4.8
Neon app <1.6.14 iOS - Info Disclosure
The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVSS 5.9
Rubrik CDM <4.0.4-p2 - Info Disclosure
A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.
CVSS 8.1
Citrix NetScaler VPX through NS12.0 53.13.nc - Authenticated Server-Side Request Forgery via /rapi/read_url URI
Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.
CVSS 8.8
Foxconn femtocell FEMTO AP-FC4064-T - Privilege Escalation
One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UART pins without any restrictions, which leads to full system compromise and disclosure of user communications.
CVSS 6.8
Foxconn femtocell FEMTO AP-FC4064-T - Weak Default Password
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any password. This vulnerability will lead to full system compromise and disclosure of user communications. The foxconn account with an 8-character lowercase alphabetic password can be used.
CVSS 7.2
iBall iB-WRB302N Firmware 1.0.1 - Unauthenticated Stored Cross-Site Scripting via lang Parameter
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter.
CVSS 6.1
By Source