Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-xv86-79r9-q5jh

больше 4 лет назад

An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xv86-3hxg-hv4r

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal allow remote attackers to inject arbitrary web script or HTML via unknown vectors involving creating or editing (1) comments, (2) taxonomy terms, or (3) nodes.

EPSS: Низкий
github логотип

GHSA-xv85-h7cp-9wff

7 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xv84-c645-853v

больше 4 лет назад

The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv84-3fv6-rp2r

больше 4 лет назад

ims_ex is a vendor system service used to manage VoLTE in unisoc devices?But it does not verify the caller's permissions?so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid ID: A-206492634

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xv83-x443-7rmw

больше 3 лет назад

HTML injection in search results via plaintext message highlighting

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xv83-vfqj-3xg9

больше 4 лет назад

Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xv82-mgrr-4j2f

9 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery.This issue affects WP Email Capture: from n/a through <= 3.12.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv82-93gj-h8jq

больше 4 лет назад

Possibility of double free issue while running multiple instances of smp2p test because of proper protection is missing while using global variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv7x-x6wr-xx7g

почти 8 лет назад

Apache Ranger policy engine incorrectly matches paths in certain conditions

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xv7x-vj5h-3pqq

почти 2 года назад

A vulnerability was found in LUNAD3v AreaLoad up to 1a1103182ed63a06dde63d1712f3262eda19c3ec. It has been rated as critical. This issue affects some unknown processing of the file request.php. The manipulation of the argument phone leads to sql injection. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is named 264813c546dba03989ac0fc365f2022bf65e3be2. It is recommended to apply a patch to fix this issue.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv7x-v825-68c4

больше 1 года назад

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv7x-qjw2-9399

больше 4 лет назад

SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.

EPSS: Низкий
github логотип

GHSA-xv7x-q4ch-37fx

больше 4 лет назад

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

EPSS: Низкий
github логотип

GHSA-xv7v-rr53-498m

больше 4 лет назад

A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.

EPSS: Низкий
github логотип

GHSA-xv7v-rf6g-xwrc

почти 5 лет назад

Directory Traversal in typo3/phar-stream-wrapper

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv7v-hw45-9jgw

около 2 месяцев назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-xv7r-9vq4-9wrq

около 4 лет назад

Project Wonder WebObjects vulnerable to Arbitrary HTTP Header Injection and Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xv7r-5ggj-8grr

больше 2 лет назад

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xv7r-59fx-748w

11 месяцев назад

Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.37.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv86-79r9-q5jh

An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv86-3hxg-hv4r

Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal allow remote attackers to inject arbitrary web script or HTML via unknown vectors involving creating or editing (1) comments, (2) taxonomy terms, or (3) nodes.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv85-h7cp-9wff

Rejected reason: Not used

7 месяцев назад
github логотип
GHSA-xv84-c645-853v

The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xv84-3fv6-rp2r

ims_ex is a vendor system service used to manage VoLTE in unisoc devices?But it does not verify the caller's permissions?so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid ID: A-206492634

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv83-x443-7rmw

HTML injection in search results via plaintext message highlighting

CVSS3: 8.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xv83-vfqj-3xg9

Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv82-mgrr-4j2f

Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery.This issue affects WP Email Capture: from n/a through <= 3.12.5.

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xv82-93gj-h8jq

Possibility of double free issue while running multiple instances of smp2p test because of proper protection is missing while using global variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xv7x-x6wr-xx7g

Apache Ranger policy engine incorrectly matches paths in certain conditions

CVSS3: 5.9
3%
Низкий
почти 8 лет назад
github логотип
GHSA-xv7x-vj5h-3pqq

A vulnerability was found in LUNAD3v AreaLoad up to 1a1103182ed63a06dde63d1712f3262eda19c3ec. It has been rated as critical. This issue affects some unknown processing of the file request.php. The manipulation of the argument phone leads to sql injection. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is named 264813c546dba03989ac0fc365f2022bf65e3be2. It is recommended to apply a patch to fix this issue.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv7x-v825-68c4

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xv7x-qjw2-9399

SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv7x-q4ch-37fx

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv7v-rr53-498m

A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xv7v-rf6g-xwrc

Directory Traversal in typo3/phar-stream-wrapper

CVSS3: 9.8
5%
Низкий
почти 5 лет назад
github логотип
GHSA-xv7v-hw45-9jgw

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

CVSS3: 2.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xv7r-9vq4-9wrq

Project Wonder WebObjects vulnerable to Arbitrary HTTP Header Injection and Cross-site Scripting

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xv7r-5ggj-8grr

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv7r-59fx-748w

Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.37.

CVSS3: 8.8
0%
Низкий
11 месяцев назад

Уязвимостей на страницу