Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 648

Количество 324 648

github логотип

GHSA-xrf5-2fh4-5hqj

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrf4-hw94-x283

больше 1 года назад

The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the mfcf7_zl_custom_handle_deactivation_plugin_form_submission() function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate the plugin and send a custom reason from the site.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrf4-39fm-j5f2

больше 3 лет назад

Fava time and filter parameters vulnerable to reflected Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xrf3-35rj-g634

около 1 года назад

Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrf2-cmw5-8q98

5 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrf2-5r3p-5wgj

10 дней назад

libcrux: Panic in Signature Hint Decoding During Verification

EPSS: Низкий
github логотип

GHSA-xrcx-gwrh-qw6x

6 месяцев назад

The MPWizard – Create Mercado Pago Payment Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation in the '/includes/admin/class-mpwizard-table.php' file. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrcw-mf6x-47h4

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nurul Amin, Mohammad Saiful Islam WP Smart Tooltip allows Stored XSS. This issue affects WP Smart Tooltip: from n/a through 1.0.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrcw-cgg9-mj7c

почти 4 года назад

functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preference files. NOTE: this issue exists because of an incorrect fix for CVE-2010-2813.

EPSS: Низкий
github логотип

GHSA-xrcw-9q57-9frw

больше 1 года назад

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not impacted. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.9.17, 3.10.14, 3.11.12, 3.12.6, 3.13.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xrcv-f9gm-v42c

около 4 лет назад

Out-of-bounds Read in Pillow

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrcv-7q63-99hc

почти 4 года назад

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

EPSS: Низкий
github логотип

GHSA-xrcr-w67r-mpp3

почти 4 года назад

writtercontrol in cdcontrol 1.90 allows local users to overwrite arbitrary files via a symlink attack on /tmp/v-recorder*-out temporary files.

EPSS: Низкий
github логотип

GHSA-xrcr-vp89-pv9v

больше 1 года назад

In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrcr-v699-vfjr

почти 4 года назад

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xrcr-j9jp-xv96

почти 4 года назад

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.

EPSS: Низкий
github логотип

GHSA-xrcr-gmf5-2r8j

около 1 месяца назад

Gogs: Stored XSS via data URI in issue comments

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-xrcq-mfw4-37wc

почти 4 года назад

Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.

EPSS: Средний
github логотип

GHSA-xrcq-533q-8rxw

7 месяцев назад

TYPO3 Bookmark Toolbar vulnerable to denial of service

EPSS: Низкий
github логотип

GHSA-xrcm-jr5x-65vm

больше 2 лет назад

A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrf5-2fh4-5hqj

Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrf4-hw94-x283

The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the mfcf7_zl_custom_handle_deactivation_plugin_form_submission() function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate the plugin and send a custom reason from the site.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrf4-39fm-j5f2

Fava time and filter parameters vulnerable to reflected Cross-site Scripting

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrf3-35rj-g634

Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.

CVSS3: 6.5
2%
Низкий
около 1 года назад
github логотип
GHSA-xrf2-cmw5-8q98

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xrf2-5r3p-5wgj

libcrux: Panic in Signature Hint Decoding During Verification

10 дней назад
github логотип
GHSA-xrcx-gwrh-qw6x

The MPWizard – Create Mercado Pago Payment Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation in the '/includes/admin/class-mpwizard-table.php' file. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xrcw-mf6x-47h4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nurul Amin, Mohammad Saiful Islam WP Smart Tooltip allows Stored XSS. This issue affects WP Smart Tooltip: from n/a through 1.0.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xrcw-cgg9-mj7c

functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preference files. NOTE: this issue exists because of an incorrect fix for CVE-2010-2813.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xrcw-9q57-9frw

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not impacted. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in versions 3.9.17, 3.10.14, 3.11.12, 3.12.6, 3.13.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xrcv-f9gm-v42c

Out-of-bounds Read in Pillow

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xrcv-7q63-99hc

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xrcr-w67r-mpp3

writtercontrol in cdcontrol 1.90 allows local users to overwrite arbitrary files via a symlink attack on /tmp/v-recorder*-out temporary files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrcr-vp89-pv9v

In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrcr-v699-vfjr

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.

CVSS3: 5.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrcr-j9jp-xv96

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xrcr-gmf5-2r8j

Gogs: Stored XSS via data URI in issue comments

CVSS3: 8.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xrcq-mfw4-37wc

Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.

53%
Средний
почти 4 года назад
github логотип
GHSA-xrcq-533q-8rxw

TYPO3 Bookmark Toolbar vulnerable to denial of service

0%
Низкий
7 месяцев назад
github логотип
GHSA-xrcm-jr5x-65vm

A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу