Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-xw98-5q62-jx94

5 месяцев назад

Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw98-5fp3-v7vg

1 день назад

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xw97-pjh6-x5h5

больше 4 лет назад

Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

EPSS: Низкий
github логотип

GHSA-xw97-mfvw-wc3w

около 2 лет назад

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw97-6734-68pm

около 4 лет назад

IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.

EPSS: Низкий
github логотип

GHSA-xw96-xcrg-p8w2

около 4 лет назад

Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xw96-874r-24gc

почти 4 года назад

The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xw96-5rq6-6334

больше 4 лет назад

A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xw96-38mm-h5jg

больше 1 года назад

Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX allows Object Injection. This issue affects Flexmls® IDX: from n/a through 3.14.27.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xw95-hgq7-7c3x

почти 3 года назад

A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense before 23.7 allows attackers to inject arbitrary JavaScript via the URL path.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xw95-7cvj-w924

около 4 лет назад

Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw95-4grr-rmhm

около 4 лет назад

The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HTML.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw94-m5qr-wj9w

1 день назад

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.

EPSS: Низкий
github логотип

GHSA-xw94-4rmp-7qw5

больше 4 лет назад

A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xw94-39m9-7c49

около 4 лет назад

An issue was discovered in the size of the default stack guard page on PAX Linux (originally from GRSecurity but shipped by other Linux vendors), specifically the default stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects PAX Linux Kernel versions as of June 19, 2017 (specific version information is not available at this time).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xw93-v57j-fcgh

около 5 лет назад

Division by 0 in `SparseMatMul`

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-xw93-h7ff-35ff

больше 4 лет назад

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘desc_filter’ parameter.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xw92-6mmh-8cmv

около 3 лет назад

The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xw92-3hmf-rcw6

около 4 лет назад

Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xw8x-r2rg-vmq9

больше 2 лет назад

HPE OneView may have a missing passphrase during restore.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw98-5q62-jx94

Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)

CVSS3: 7.5
1%
Низкий
5 месяцев назад
github логотип
GHSA-xw98-5fp3-v7vg

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.

CVSS3: 9.1
1 день назад
github логотип
GHSA-xw97-pjh6-x5h5

Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw97-mfvw-wc3w

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-xw97-6734-68pm

IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xw96-xcrg-p8w2

Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw96-874r-24gc

The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xw96-5rq6-6334

A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw96-38mm-h5jg

Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX allows Object Injection. This issue affects Flexmls® IDX: from n/a through 3.14.27.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xw95-hgq7-7c3x

A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense before 23.7 allows attackers to inject arbitrary JavaScript via the URL path.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-xw95-7cvj-w924

Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw95-4grr-rmhm

The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HTML.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw94-m5qr-wj9w

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.

1 день назад
github логотип
GHSA-xw94-4rmp-7qw5

A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files.

CVSS3: 7.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw94-39m9-7c49

An issue was discovered in the size of the default stack guard page on PAX Linux (originally from GRSecurity but shipped by other Linux vendors), specifically the default stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects PAX Linux Kernel versions as of June 19, 2017 (specific version information is not available at this time).

CVSS3: 5.9
0%
Низкий
около 4 лет назад
github логотип
GHSA-xw93-v57j-fcgh

Division by 0 in `SparseMatMul`

CVSS3: 2.5
0%
Низкий
около 5 лет назад
github логотип
GHSA-xw93-h7ff-35ff

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘desc_filter’ parameter.

CVSS3: 8.8
20%
Средний
больше 4 лет назад
github логотип
GHSA-xw92-6mmh-8cmv

The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xw92-3hmf-rcw6

Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xw8x-r2rg-vmq9

HPE OneView may have a missing passphrase during restore.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу