Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 360

Количество 324 360

github логотип

GHSA-xv56-c9px-vg88

больше 2 лет назад

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a user's web browser.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv56-7cfh-4v8j

почти 4 года назад

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

EPSS: Низкий
github логотип

GHSA-xv56-54j2-wf98

почти 4 года назад

Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.

EPSS: Низкий
github логотип

GHSA-xv56-4f6g-pxh9

почти 4 года назад

Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."

EPSS: Средний
github логотип

GHSA-xv56-3wq5-9997

3 месяца назад

Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xv53-g6mx-pxpf

почти 4 года назад

Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via crafted MPEG-4 data, a different vulnerability than CVE-2015-8045, CVE-2015-8047, CVE-2015-8060, CVE-2015-8408, CVE-2015-8416, CVE-2015-8417, CVE-2015-8418, CVE-2015-8419, CVE-2015-8443, CVE-2015-8444, CVE-2015-8451, CVE-2015-8455, CVE-2015-8652, CVE-2015-8654, CVE-2015-8657, CVE-2015-8658, and CVE-2015-8820.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv52-8ff7-g4jf

почти 4 года назад

The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.

EPSS: Низкий
github логотип

GHSA-xv52-32q3-qg5c

больше 1 года назад

A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. HTML markup could be added to comments of tickets, which when submitted will render in the emails sent to all users on that ticket.

EPSS: Низкий
github логотип

GHSA-xv4x-hccf-2g5r

почти 4 года назад

search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter.

EPSS: Низкий
github логотип

GHSA-xv4w-vgqg-qwrq

12 месяцев назад

The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4.21. This is due to missing or incorrect nonce validation on the 'woffice_handle_user_approval_actions' function. This makes it possible for unauthenticated attackers to approve registration for any user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv4w-832x-qgcj

около 3 лет назад

In isp, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494449; Issue ID: ALPS07494449.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xv4v-gr2p-pmw7

почти 4 года назад

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JavaScript engine, related to string manipulation. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv4v-4779-783g

почти 4 года назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in the GLink kernel driver, a Use After Free condition can potentially occur.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xv4r-xrmj-c649

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: s390/stacktrace: Use break instead of return statement arch_stack_walk_user_common() contains a return statement instead of a break statement in case store_ip() fails while trying to store a callchain entry of a user space process. This may lead to a missing pagefault_enable() call. If this happens any subsequent page fault of the process won't be resolved by the page fault handler and this in turn will lead to the process being killed. Use a break instead of a return statement to fix this.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv4r-vccv-mg4w

почти 5 лет назад

MinIO Admin API security issue

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xv4r-r9fj-hh6h

почти 4 года назад

file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv4r-prr7-qwvx

почти 4 года назад

In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system.

EPSS: Низкий
github логотип

GHSA-xv4r-44qp-78wm

около 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

CVSS3: 9.9
EPSS: Критический
github логотип

GHSA-xv4p-rc8w-pq62

почти 4 года назад

PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter.

EPSS: Высокий
github логотип

GHSA-xv4p-9g9m-3h7x

почти 3 года назад

The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv56-c9px-vg88

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a user's web browser.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv56-7cfh-4v8j

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xv56-54j2-wf98

Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv56-4f6g-pxh9

Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."

24%
Средний
почти 4 года назад
github логотип
GHSA-xv56-3wq5-9997

Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository

CVSS3: 6.7
3 месяца назад
github логотип
GHSA-xv53-g6mx-pxpf

Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via crafted MPEG-4 data, a different vulnerability than CVE-2015-8045, CVE-2015-8047, CVE-2015-8060, CVE-2015-8408, CVE-2015-8416, CVE-2015-8417, CVE-2015-8418, CVE-2015-8419, CVE-2015-8443, CVE-2015-8444, CVE-2015-8451, CVE-2015-8455, CVE-2015-8652, CVE-2015-8654, CVE-2015-8657, CVE-2015-8658, and CVE-2015-8820.

CVSS3: 8.8
7%
Низкий
почти 4 года назад
github логотип
GHSA-xv52-8ff7-g4jf

The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv52-32q3-qg5c

A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. HTML markup could be added to comments of tickets, which when submitted will render in the emails sent to all users on that ticket.

0%
Низкий
больше 1 года назад
github логотип
GHSA-xv4x-hccf-2g5r

search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter.

7%
Низкий
почти 4 года назад
github логотип
GHSA-xv4w-vgqg-qwrq

The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4.21. This is due to missing or incorrect nonce validation on the 'woffice_handle_user_approval_actions' function. This makes it possible for unauthenticated attackers to approve registration for any user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 5.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-xv4w-832x-qgcj

In isp, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494449; Issue ID: ALPS07494449.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-xv4v-gr2p-pmw7

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the JavaScript engine, related to string manipulation. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-xv4v-4779-783g

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in the GLink kernel driver, a Use After Free condition can potentially occur.

CVSS3: 7
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv4r-xrmj-c649

In the Linux kernel, the following vulnerability has been resolved: s390/stacktrace: Use break instead of return statement arch_stack_walk_user_common() contains a return statement instead of a break statement in case store_ip() fails while trying to store a callchain entry of a user space process. This may lead to a missing pagefault_enable() call. If this happens any subsequent page fault of the process won't be resolved by the page fault handler and this in turn will lead to the process being killed. Use a break instead of a return statement to fix this.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xv4r-vccv-mg4w

MinIO Admin API security issue

CVSS3: 7.1
0%
Низкий
почти 5 лет назад
github логотип
GHSA-xv4r-r9fj-hh6h

file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv4r-prr7-qwvx

In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv4r-44qp-78wm

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

CVSS3: 9.9
94%
Критический
около 2 лет назад
github логотип
GHSA-xv4p-rc8w-pq62

PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter.

86%
Высокий
почти 4 года назад
github логотип
GHSA-xv4p-9g9m-3h7x

The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them.

CVSS3: 6.1
0%
Низкий
почти 3 года назад

Уязвимостей на страницу