Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-44xq-f3xg-xf6q

больше 1 года назад

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-44xq-533g-gj79

больше 2 лет назад

Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44xp-wj24-9xxj

больше 3 лет назад

Moodle allows attackers to delete files

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-44xp-hxfq-7fh9

около 2 месяцев назад

A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability affects the function _sg_pipeline_common_init in the library sokol_gfx.h. Performing manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be exploited. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 33e2271c431bf21de001e972f72da17a984da932. It is suggested to install a patch to address this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-44xp-g462-97fp

больше 3 лет назад

ping.php on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in the ip_dominio parameter.

EPSS: Низкий
github логотип

GHSA-44xp-496v-cvw6

почти 4 года назад

PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter.

EPSS: Низкий
github логотип

GHSA-44xm-468v-w3hq

около 2 лет назад

A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file /general/attendance/manage/ask_duty/delete.php. The manipulation of the argument ASK_DUTY_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-252991.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-44xj-fwgh-mjw6

больше 3 лет назад

The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-44xj-f97g-hv56

почти 4 года назад

getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.

EPSS: Низкий
github логотип

GHSA-44xh-w98h-vq6q

больше 1 года назад

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensitive information from password protected posts.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-44xg-wcj6-rg4h

больше 3 лет назад

Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and control partial module functions via a crafted app.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44xg-hr3w-5m39

больше 3 лет назад

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-44xf-m62f-7h7r

больше 3 лет назад

The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-44xc-fr4f-4f38

больше 3 лет назад

libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7116.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-44xc-f95p-5vmh

почти 3 года назад

The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-44xc-4fwm-mjj9

больше 3 лет назад

resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by the software (e.g., concatenate `&|;\r\ commands) and inject arbitrary system commands with the privileges of the application user.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44xc-2pmv-465w

почти 4 года назад

Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files.

EPSS: Низкий
github логотип

GHSA-44x9-p5gj-h8x2

больше 3 лет назад

net/ipv4/ip_gre.c in the Linux kernel before 2.6.34, when ip_gre is configured as a module, allows remote attackers to cause a denial of service (OOPS) by sending a packet during module loading.

EPSS: Низкий
github логотип

GHSA-44x9-mhh2-9wm8

почти 4 года назад

Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

EPSS: Низкий
github логотип

GHSA-44x9-g356-qcmm

около 3 лет назад

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242702935

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-44xq-f3xg-xf6q

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-44xq-533g-gj79

Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-44xp-wj24-9xxj

Moodle allows attackers to delete files

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44xp-hxfq-7fh9

A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability affects the function _sg_pipeline_common_init in the library sokol_gfx.h. Performing manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be exploited. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 33e2271c431bf21de001e972f72da17a984da932. It is suggested to install a patch to address this issue.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-44xp-g462-97fp

ping.php on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in the ip_dominio parameter.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-44xp-496v-cvw6

PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter.

5%
Низкий
почти 4 года назад
github логотип
GHSA-44xm-468v-w3hq

A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file /general/attendance/manage/ask_duty/delete.php. The manipulation of the argument ASK_DUTY_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-252991.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-44xj-fwgh-mjw6

The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-44xj-f97g-hv56

getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.

1%
Низкий
почти 4 года назад
github логотип
GHSA-44xh-w98h-vq6q

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensitive information from password protected posts.

CVSS3: 5.3
2%
Низкий
больше 1 года назад
github логотип
GHSA-44xg-wcj6-rg4h

Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and control partial module functions via a crafted app.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44xg-hr3w-5m39

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

CVSS3: 8.8
72%
Высокий
больше 3 лет назад
github логотип
GHSA-44xf-m62f-7h7r

The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-44xc-fr4f-4f38

libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7116.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-44xc-f95p-5vmh

The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-44xc-4fwm-mjj9

resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by the software (e.g., concatenate `&|;\r\ commands) and inject arbitrary system commands with the privileges of the application user.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-44xc-2pmv-465w

Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files.

1%
Низкий
почти 4 года назад
github логотип
GHSA-44x9-p5gj-h8x2

net/ipv4/ip_gre.c in the Linux kernel before 2.6.34, when ip_gre is configured as a module, allows remote attackers to cause a denial of service (OOPS) by sending a packet during module loading.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-44x9-mhh2-9wm8

Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

1%
Низкий
почти 4 года назад
github логотип
GHSA-44x9-g356-qcmm

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242702935

CVSS3: 7.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу