Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 528

Количество 373 528

github логотип

GHSA-xxr3-85vr-f7wf

больше 4 лет назад

In Sony Catalyst Production Suite through 2019.1 (1.1.0.21) and Catalyst Browse through 2019.1 (1.1.0.21), an unprivileged user can obtain admin privileges, and execute a program as admin, after DLL hijacking of a DLL that is loaded during setup (installation).

EPSS: Низкий
github логотип

GHSA-xxr2-w49x-7xv2

больше 2 лет назад

PDF-XChange Editor EMF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20921.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xxr2-6rqw-cjfr

больше 2 лет назад

The Gutenberg Block Editor Toolkit – EditorsKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'editorskit' shortcode in all versions up to, and including, 1.40.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xxqx-j272-mwp6

больше 4 лет назад

WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files.

EPSS: Низкий
github логотип

GHSA-xxqx-377j-rrqc

больше 4 лет назад

In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WriteOneJNGImage in coders/png.c, which allows attackers to cause a denial of service (WriteJNGImage memory consumption) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxqw-xrxq-2h73

4 месяца назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxqw-w7gr-7fqf

больше 4 лет назад

Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xxqw-qwfj-97rc

больше 4 лет назад

A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in /cloud_config/cloud_device/info interface, which allows a malicious user to executee arbitrary code on the system via a crafted post request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxqw-83c7-r24r

около 2 лет назад

FeehiCMS file upload vulnerability

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxqv-jc35-w8cj

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: nixge: fix NULL dereference In function nixge_hw_dma_bd_release() dereference of NULL pointer priv->rx_bd_v is possible for the case of its allocation failure in nixge_hw_dma_bd_init(). Move for() loop with priv->rx_bd_v dereference under the check for its validity. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxqv-2w2h-3m7c

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the Description field in a file upload. NOTE: this issue was originally incorrectly mapped to CVE-2014-1155; see CVE-2014-1155 for more information.

EPSS: Низкий
github логотип

GHSA-xxqr-pj6w-cvwh

больше 4 лет назад

Uncaught exception in firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.1.0 may allow a privileged attacker to potentially enable denial of service via local access.

EPSS: Низкий
github логотип

GHSA-xxqr-hj46-74ww

больше 4 лет назад

SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.

EPSS: Низкий
github логотип

GHSA-xxqr-h45r-xgm7

больше 4 лет назад

Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

EPSS: Средний
github логотип

GHSA-xxqq-qccx-3r89

больше 4 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxqq-pg5g-cgqm

9 месяцев назад

Rejected reason: Voluntarily withdrawn

EPSS: Низкий
github логотип

GHSA-xxqq-477x-j22x

больше 1 года назад

An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-supplied queries containing deeply nested expressions.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-xxqp-r9x6-3h94

больше 4 лет назад

JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxqp-4rfr-9px7

больше 1 года назад

A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument how leads to improper validation of array index.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xxqm-xpq7-prvx

больше 4 лет назад

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0758, CVE-2018-0762, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0772, CVE-2018-0773, CVE-2018-0774, CVE-2018-0775, CVE-2018-0776, CVE-2018-0778, and CVE-2018-0781.

CVSS3: 7.5
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxr3-85vr-f7wf

In Sony Catalyst Production Suite through 2019.1 (1.1.0.21) and Catalyst Browse through 2019.1 (1.1.0.21), an unprivileged user can obtain admin privileges, and execute a program as admin, after DLL hijacking of a DLL that is loaded during setup (installation).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxr2-w49x-7xv2

PDF-XChange Editor EMF File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20921.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxr2-6rqw-cjfr

The Gutenberg Block Editor Toolkit – EditorsKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'editorskit' shortcode in all versions up to, and including, 1.40.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxqx-j272-mwp6

WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxqx-377j-rrqc

In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WriteOneJNGImage in coders/png.c, which allows attackers to cause a denial of service (WriteJNGImage memory consumption) via a crafted file.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxqw-xrxq-2h73

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xxqw-w7gr-7fqf

Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxqw-qwfj-97rc

A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in /cloud_config/cloud_device/info interface, which allows a malicious user to executee arbitrary code on the system via a crafted post request.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxqw-83c7-r24r

FeehiCMS file upload vulnerability

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-xxqv-jc35-w8cj

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: nixge: fix NULL dereference In function nixge_hw_dma_bd_release() dereference of NULL pointer priv->rx_bd_v is possible for the case of its allocation failure in nixge_hw_dma_bd_init(). Move for() loop with priv->rx_bd_v dereference under the check for its validity. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxqv-2w2h-3m7c

Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary web script or HTML via the Description field in a file upload. NOTE: this issue was originally incorrectly mapped to CVE-2014-1155; see CVE-2014-1155 for more information.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xxqr-pj6w-cvwh

Uncaught exception in firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.1.0 may allow a privileged attacker to potentially enable denial of service via local access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxqr-hj46-74ww

SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxqr-h45r-xgm7

Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

53%
Средний
больше 4 лет назад
github логотип
GHSA-xxqq-qccx-3r89

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-xxqq-pg5g-cgqm

Rejected reason: Voluntarily withdrawn

9 месяцев назад
github логотип
GHSA-xxqq-477x-j22x

An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-supplied queries containing deeply nested expressions.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxqp-r9x6-3h94

JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxqp-4rfr-9px7

A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument how leads to improper validation of array index.

CVSS3: 8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xxqm-xpq7-prvx

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0758, CVE-2018-0762, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0772, CVE-2018-0773, CVE-2018-0774, CVE-2018-0775, CVE-2018-0776, CVE-2018-0778, and CVE-2018-0781.

CVSS3: 7.5
78%
Высокий
больше 4 лет назад

Уязвимостей на страницу