Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-xrxv-pj5w-gmxx

около 4 лет назад

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions notification, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xrxr-xwxg-4g42

около 1 года назад

A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an unknown function of the file /contact.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xrxr-x757-5v8c

около 1 года назад

The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action in all versions up to, and including, 1.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrxr-vcvh-gm7h

больше 4 лет назад

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xrxr-87wr-8j4m

почти 3 года назад

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xrxr-6vrf-4m23

больше 3 лет назад

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="webLocationMessage_text" name="webLocationMessage_text"

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrxq-x8xp-9x7h

около 1 года назад

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version details of the affected system. This vulnerability has low impact on confidentiality, with no effect on integrity and availability of the application.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xrxq-r6x5-h4vf

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uri Weil WP Order By allows Reflected XSS.This issue affects WP Order By: from n/a through 1.4.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrxq-p636-j73q

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts() Commit 8f394da36a36 ("scsi: qla2xxx: Drop TARGET_SCF_LOOKUP_LUN_FROM_TAG") made the __qlt_24xx_handle_abts() function return early if tcm_qla2xxx_find_cmd_by_tag() didn't find a command, but it missed to clean up the allocated memory for the management command.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xrxq-fc9m-fg9v

около 4 лет назад

The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.1.

EPSS: Низкий
github логотип

GHSA-xrxp-wj2g-wrxj

больше 3 лет назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrxm-mvqm-r553

около 4 лет назад

Helm Path Traversal

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrxm-gfhq-gw84

около 4 лет назад

The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download searchable text from the embedded Solr service, bypassing DocuWare's access control features of the DocuWare user interfaces and API. An attacker can also gain privileges by modifying text. The default installation is unsafe because the server listens on the network interface, not the localhost interface.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrxm-cp7j-8xf6

около 2 месяцев назад

@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xrxm-c9j3-54pp

больше 4 лет назад

IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.

EPSS: Низкий
github логотип

GHSA-xrxj-jg56-83p4

больше 3 лет назад

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xrxj-9pf4-9w4r

около 4 лет назад

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrxj-2pv2-mppf

больше 3 лет назад

The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrxh-pcqg-5r4x

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix double free in user_cluster_connect() user_cluster_disconnect() frees "conn->cc_private" which is "lc" but then the error handling frees "lc" a second time. Set "lc" to NULL on this path to avoid a double free.

EPSS: Низкий
github логотип

GHSA-xrxh-g8jf-mf2m

около 4 лет назад

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrxv-pj5w-gmxx

Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions notification, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xrxr-xwxg-4g42

A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an unknown function of the file /contact.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xrxr-x757-5v8c

The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action in all versions up to, and including, 1.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xrxr-vcvh-gm7h

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xrxr-87wr-8j4m

Microsoft Word Remote Code Execution Vulnerability

CVSS3: 7.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-xrxr-6vrf-4m23

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="webLocationMessage_text" name="webLocationMessage_text"

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrxq-x8xp-9x7h

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version details of the affected system. This vulnerability has low impact on confidentiality, with no effect on integrity and availability of the application.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xrxq-r6x5-h4vf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uri Weil WP Order By allows Reflected XSS.This issue affects WP Order By: from n/a through 1.4.2.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrxq-p636-j73q

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts() Commit 8f394da36a36 ("scsi: qla2xxx: Drop TARGET_SCF_LOOKUP_LUN_FROM_TAG") made the __qlt_24xx_handle_abts() function return early if tcm_qla2xxx_find_cmd_by_tag() didn't find a command, but it missed to clean up the allocated memory for the management command.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrxq-fc9m-fg9v

The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.1.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xrxp-wj2g-wrxj

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrxm-mvqm-r553

Helm Path Traversal

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrxm-gfhq-gw84

The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download searchable text from the embedded Solr service, bypassing DocuWare's access control features of the DocuWare user interfaces and API. An attacker can also gain privileges by modifying text. The default installation is unsafe because the server listens on the network interface, not the localhost interface.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xrxm-cp7j-8xf6

@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xrxm-c9j3-54pp

IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xrxj-jg56-83p4

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xrxj-9pf4-9w4r

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrxj-2pv2-mppf

The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrxh-pcqg-5r4x

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix double free in user_cluster_connect() user_cluster_disconnect() frees "conn->cc_private" which is "lc" but then the error handling frees "lc" a second time. Set "lc" to NULL on this path to avoid a double free.

0%
Низкий
9 месяцев назад
github логотип
GHSA-xrxh-g8jf-mf2m

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.

CVSS3: 7.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу