Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-xv7x-v825-68c4

больше 1 года назад

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv7x-qjw2-9399

больше 4 лет назад

SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.

EPSS: Низкий
github логотип

GHSA-xv7x-q4ch-37fx

около 4 лет назад

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

EPSS: Низкий
github логотип

GHSA-xv7v-rr53-498m

около 4 лет назад

A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.

EPSS: Низкий
github логотип

GHSA-xv7v-rf6g-xwrc

почти 5 лет назад

Directory Traversal in typo3/phar-stream-wrapper

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv7v-hw45-9jgw

около 19 часов назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

EPSS: Низкий
github логотип

GHSA-xv7r-9vq4-9wrq

почти 4 года назад

Project Wonder WebObjects vulnerable to Arbitrary HTTP Header Injection and Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xv7r-5ggj-8grr

больше 2 лет назад

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xv7r-59fx-748w

9 месяцев назад

Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.37.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv7q-j96c-5r6v

около 1 года назад

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv7q-66p6-r28c

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv7q-36g9-3jc5

больше 2 лет назад

The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv7p-vwj6-p73h

почти 4 года назад

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv7p-mvh6-j6cp

около 4 лет назад

A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv7p-mcp9-w898

около 4 лет назад

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv7p-jw46-8r85

больше 2 лет назад

Cross-site Scripting in JFinalcms

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv7j-wg82-2r7g

около 2 лет назад

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv7j-v722-h5vx

больше 2 лет назад

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv7j-qvp8-927h

больше 4 лет назад

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-xv7j-jr8q-mhmm

около 4 лет назад

Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv7x-v825-68c4

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xv7x-qjw2-9399

SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv7x-q4ch-37fx

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xv7v-rr53-498m

A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xv7v-rf6g-xwrc

Directory Traversal in typo3/phar-stream-wrapper

CVSS3: 9.8
6%
Низкий
почти 5 лет назад
github логотип
GHSA-xv7v-hw45-9jgw

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

около 19 часов назад
github логотип
GHSA-xv7r-9vq4-9wrq

Project Wonder WebObjects vulnerable to Arbitrary HTTP Header Injection and Cross-site Scripting

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xv7r-5ggj-8grr

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv7r-59fx-748w

Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.37.

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xv7q-j96c-5r6v

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xv7q-66p6-r28c

Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv7q-36g9-3jc5

The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv7p-vwj6-p73h

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xv7p-mvh6-j6cp

A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xv7p-mcp9-w898

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xv7p-jw46-8r85

Cross-site Scripting in JFinalcms

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv7j-wg82-2r7g

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xv7j-v722-h5vx

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xv7j-qvp8-927h

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv7j-jr8q-mhmm

Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

5%
Низкий
около 4 лет назад

Уязвимостей на страницу