Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 351 897

Количество 351 897

github логотип

GHSA-xxxc-2fjg-mprw

около 1 года назад

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxx9-8q88-3qrf

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: from n/a through 3.1.40.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxx9-446j-m3xj

около 4 лет назад

Unspecified vulnerability in Kismet before 2005-08-R1 allows remote attackers to have an unknown impact via unprintable characters in the SSID.

EPSS: Низкий
github логотип

GHSA-xxx9-3xcr-gjj3

больше 4 лет назад

XML Injection in Xerces Java affects Nokogiri

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxx8-w7mj-hmgq

около 4 лет назад

hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxx7-j74c-5xrg

5 месяцев назад

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxx6-g6jv-xq96

около 1 месяца назад

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may result in the disclosure of process memory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxx6-f4cg-v662

больше 3 лет назад

Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxx5-wj7r-x3hv

больше 4 лет назад

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xxx5-7c7q-rc45

больше 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxx4-cx36-38r5

около 4 лет назад

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxx4-63qf-8v87

почти 4 года назад

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xxx4-4fcv-w56c

около 4 лет назад

The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) via a crafted application, aka a "semaphore deadlock issue."

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxx3-q2f4-59h7

около 4 лет назад

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

EPSS: Низкий
github логотип

GHSA-xxx3-p74m-7mjp

9 месяцев назад

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxx2-77cj-f65h

около 4 лет назад

Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."

EPSS: Низкий
github логотип

GHSA-xxwx-xvv4-fvjw

около 4 лет назад

Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.

EPSS: Низкий
github логотип

GHSA-xxwx-qg6p-mx7w

больше 1 года назад

PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxww-hv47-2ppx

около 4 лет назад

Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

EPSS: Низкий
github логотип

GHSA-xxww-73xw-x3fj

около 3 лет назад

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxxc-2fjg-mprw

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xxx9-8q88-3qrf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: from n/a through 3.1.40.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxx9-446j-m3xj

Unspecified vulnerability in Kismet before 2005-08-R1 allows remote attackers to have an unknown impact via unprintable characters in the SSID.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xxx9-3xcr-gjj3

XML Injection in Xerces Java affects Nokogiri

CVSS3: 6.5
больше 4 лет назад
github логотип
GHSA-xxx8-w7mj-hmgq

hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xxx7-j74c-5xrg

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xxx6-g6jv-xq96

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may result in the disclosure of process memory.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xxx6-f4cg-v662

Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt that are hardcoded into a DLL or EXE file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxx5-wj7r-x3hv

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS3: 9.8
54%
Средний
больше 4 лет назад
github логотип
GHSA-xxx5-7c7q-rc45

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xxx4-cx36-38r5

Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE since version 11.3 allows an attacker to bypass CODEOWNERS Merge Request approval requirement under rare circumstances

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxx4-63qf-8v87

The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxx4-4fcv-w56c

The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) via a crafted application, aka a "semaphore deadlock issue."

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxx3-q2f4-59h7

The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxx3-p74m-7mjp

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xxx2-77cj-f65h

Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rules, allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack."

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxwx-xvv4-fvjw

Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxwx-qg6p-mx7w

PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xxww-hv47-2ppx

Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxww-73xw-x3fj

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

CVSS3: 3.1
0%
Низкий
около 3 лет назад

Уязвимостей на страницу