Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-xv5x-v758-wfgm

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.18.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv5x-m38x-3h28

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv5x-6w3r-qqm9

больше 4 лет назад

Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.

EPSS: Низкий
github логотип

GHSA-xv5w-q9qp-mpg2

9 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-xv5w-q5wq-r3c3

10 месяцев назад

Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv5w-cw7x-72gj

3 месяца назад

id: pretty-print uses effective GID instead of effective UID for name lookup

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xv5v-c2mf-pc43

почти 3 года назад

A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv5v-4g23-pxj9

больше 4 лет назад

Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.

EPSS: Низкий
github логотип

GHSA-xv5r-jf97-8xjm

почти 5 лет назад

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

EPSS: Низкий
github логотип

GHSA-xv5r-44m2-6q3g

больше 2 лет назад

An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted malicious links to the EDR XConsole end user.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-xv5q-xvvq-gvcm

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xv5q-r8xx-69mw

больше 4 лет назад

Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv5p-prx7-chgr

больше 4 лет назад

Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xv5p-fjw5-vrj6

10 месяцев назад

Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv5j-xw3x-cwr6

около 4 лет назад

Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv5j-gfm8-3c7j

больше 4 лет назад

BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xv5h-v7jh-p2qh

больше 5 лет назад

Authentication bypass for specific endpoint

EPSS: Средний
github логотип

GHSA-xv5h-ppvh-6vp3

около 1 месяца назад

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xv5h-j798-x927

больше 3 лет назад

Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv5g-r83r-j2g9

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv5x-v758-wfgm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrocoBlock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.18.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-xv5x-m38x-3h28

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv5x-6w3r-qqm9

Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv5w-q9qp-mpg2

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

9 месяцев назад
github логотип
GHSA-xv5w-q5wq-r3c3

Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client

CVSS3: 7.5
1%
Низкий
10 месяцев назад
github логотип
GHSA-xv5w-cw7x-72gj

id: pretty-print uses effective GID instead of effective UID for name lookup

CVSS3: 3.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xv5v-c2mf-pc43

A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xv5v-4g23-pxj9

Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-xv5r-jf97-8xjm

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-xv5r-44m2-6q3g

An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A malicious threat actor could execute commands on the victim's browser for sending carefully crafted malicious links to the EDR XConsole end user.

CVSS3: 4.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv5q-xvvq-gvcm

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-xv5q-r8xx-69mw

Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-xv5p-prx7-chgr

Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv5p-fjw5-vrj6

Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer

CVSS3: 8.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-xv5j-xw3x-cwr6

Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xv5j-gfm8-3c7j

BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI.

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv5h-v7jh-p2qh

Authentication bypass for specific endpoint

67%
Средний
больше 5 лет назад
github логотип
GHSA-xv5h-ppvh-6vp3

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xv5h-j798-x927

Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xv5g-r83r-j2g9

Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу