Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-xv7r-59fx-748w

4 месяца назад

Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.37.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv7q-j96c-5r6v

9 месяцев назад

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv7q-66p6-r28c

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv7q-36g9-3jc5

почти 2 года назад

The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv7p-vwj6-p73h

больше 3 лет назад

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv7p-mvh6-j6cp

больше 3 лет назад

A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv7p-mcp9-w898

больше 3 лет назад

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv7p-jw46-8r85

около 2 лет назад

Cross-site Scripting in JFinalcms

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv7j-wg82-2r7g

больше 1 года назад

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv7j-v722-h5vx

почти 2 года назад

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv7j-qvp8-927h

почти 4 года назад

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-xv7j-jr8q-mhmm

больше 3 лет назад

Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

EPSS: Средний
github логотип

GHSA-xv7j-8v8v-h429

больше 3 лет назад

The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

EPSS: Низкий
github логотип

GHSA-xv7j-2v4w-cjvh

почти 4 года назад

OpenStack Glance logs user name and password in cleartext

EPSS: Низкий
github логотип

GHSA-xv7h-qpjm-g3jp

больше 3 лет назад

In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111

EPSS: Низкий
github логотип

GHSA-xv7h-95r7-595j

больше 3 лет назад

Incorrect implementation of lockout feature in Keycloak

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv7h-8h3f-m34f

больше 3 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote attackers to affect integrity via unknown vectors related to Fluid Core.

EPSS: Низкий
github логотип

GHSA-xv7h-524v-h227

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is guest.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv7g-x679-jf4c

больше 3 лет назад

A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).

EPSS: Низкий
github логотип

GHSA-xv7f-hrp6-5mhh

больше 3 лет назад

Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv7r-59fx-748w

Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.37.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xv7q-j96c-5r6v

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xv7q-66p6-r28c

Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xv7q-36g9-3jc5

The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv7p-vwj6-p73h

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xv7p-mvh6-j6cp

A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv7p-mcp9-w898

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv7p-jw46-8r85

Cross-site Scripting in JFinalcms

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-xv7j-wg82-2r7g

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xv7j-v722-h5vx

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv7j-qvp8-927h

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv7j-jr8q-mhmm

Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

11%
Средний
больше 3 лет назад
github логотип
GHSA-xv7j-8v8v-h429

The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv7j-2v4w-cjvh

OpenStack Glance logs user name and password in cleartext

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv7h-qpjm-g3jp

In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv7h-95r7-595j

Incorrect implementation of lockout feature in Keycloak

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv7h-8h3f-m34f

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote attackers to affect integrity via unknown vectors related to Fluid Core.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv7h-524v-h227

In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is guest.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xv7g-x679-jf4c

A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv7f-hrp6-5mhh

Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.

CVSS3: 8.4
7%
Низкий
больше 3 лет назад

Уязвимостей на страницу