Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 306 231

Количество 306 231

github логотип

GHSA-3h66-9xgh-v229

5 месяцев назад

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h66-68qg-wvwr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.

EPSS: Низкий
github логотип

GHSA-3h65-qjq4-488h

больше 2 лет назад

The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.8.5 via the dmm_export_donations() function which is called via the admin_post_dmm_export hook due to missing capability checks. This can allow authenticated attackers to extract a CSV file that contains sensitive information about the donors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h65-3mjq-qqj8

больше 3 лет назад

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h64-fx5v-2f3q

7 дней назад

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server via the 'current_user_avatar' parameter in a two-stage attack which can make remote code execution possible. This only affects sites with the custom avatar setting enabled.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3h64-ff22-jvm6

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: media: amphion: Set video drvdata before register video device The video drvdata should be set before the video device is registered, otherwise video_drvdata() may return NULL in the open() file ops, and led to oops.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h64-25x5-v8wv

больше 3 лет назад

Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php, (7) categoriesblogs_list.php, (8) chosen_authors_list.php, (9) chosen_blogs_list.php, (10) chosen_comments_list.php, and (11) help_list.php in blogs/.

EPSS: Низкий
github логотип

GHSA-3h63-pxm6-2x4m

больше 3 лет назад

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3h63-p63p-w54v

6 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Images Gallery allows SQL Injection. This issue affects iFrame Images Gallery: from n/a through 9.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3h62-xc6m-rwqv

больше 3 лет назад

Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.

EPSS: Высокий
github логотип

GHSA-3h5w-8f3f-63f2

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in addlink.php in AXScripts AxsLinks 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) title parameter.

EPSS: Низкий
github логотип

GHSA-3h5v-q93c-6h6q

больше 1 года назад

ws affected by a DoS when handling a request with many HTTP headers

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h5v-53qj-h7p2

11 месяцев назад

Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h5r-qj9r-h77r

около 1 года назад

The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the nm_vistior page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h5r-928v-mxhh

больше 4 лет назад

Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-3h5q-gg6w-2g7p

больше 3 лет назад

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

EPSS: Низкий
github логотип

GHSA-3h5q-3j8q-4rm9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

EPSS: Средний
github логотип

GHSA-3h5p-pg4g-m6gv

больше 1 года назад

A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the CsrRequestView class. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of a10user. Was ZDI-CAN-22517.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h5p-hx2f-x27c

больше 1 года назад

Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h5p-423v-vjw8

больше 3 лет назад

Directory traversal vulnerability in download.cgi in EZFactory KDDI Download CGI 1.x allows remote attackers to read and download arbitrary files via a .. (dot dot) in the name parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h66-9xgh-v229

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3h66-68qg-wvwr

Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h65-qjq4-488h

The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.8.5 via the dmm_export_donations() function which is called via the admin_post_dmm_export hook due to missing capability checks. This can allow authenticated attackers to extract a CSV file that contains sensitive information about the donors.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3h65-3mjq-qqj8

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h64-fx5v-2f3q

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server via the 'current_user_avatar' parameter in a two-stage attack which can make remote code execution possible. This only affects sites with the custom avatar setting enabled.

CVSS3: 6.8
0%
Низкий
7 дней назад
github логотип
GHSA-3h64-ff22-jvm6

In the Linux kernel, the following vulnerability has been resolved: media: amphion: Set video drvdata before register video device The video drvdata should be set before the video device is registered, otherwise video_drvdata() may return NULL in the open() file ops, and led to oops.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3h64-25x5-v8wv

Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQL commands via the SearchField parameter in a search action to (1) _authors_list.php, (2) _blogs_list.php, (3) _category_list.php, (4) _comments_list.php, (5) _policy_list.php, (6) _rate_list.php, (7) categoriesblogs_list.php, (8) chosen_authors_list.php, (9) chosen_blogs_list.php, (10) chosen_comments_list.php, and (11) help_list.php in blogs/.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3h63-pxm6-2x4m

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

CVSS3: 5.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h63-p63p-w54v

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Images Gallery allows SQL Injection. This issue affects iFrame Images Gallery: from n/a through 9.0.

CVSS3: 8.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3h62-xc6m-rwqv

Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.

75%
Высокий
больше 3 лет назад
github логотип
GHSA-3h5w-8f3f-63f2

Multiple cross-site scripting (XSS) vulnerabilities in addlink.php in AXScripts AxsLinks 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) title parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h5v-q93c-6h6q

ws affected by a DoS when handling a request with many HTTP headers

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3h5v-53qj-h7p2

Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.

CVSS3: 4.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-3h5r-qj9r-h77r

The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the nm_vistior page.

CVSS3: 7.2
1%
Низкий
около 1 года назад
github логотип
GHSA-3h5r-928v-mxhh

Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11

CVSS3: 2.6
больше 4 лет назад
github логотип
GHSA-3h5q-gg6w-2g7p

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h5q-3j8q-4rm9

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

37%
Средний
больше 3 лет назад
github логотип
GHSA-3h5p-pg4g-m6gv

A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the CsrRequestView class. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of a10user. Was ZDI-CAN-22517.

CVSS3: 7.2
5%
Низкий
больше 1 года назад
github логотип
GHSA-3h5p-hx2f-x27c

Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3h5p-423v-vjw8

Directory traversal vulnerability in download.cgi in EZFactory KDDI Download CGI 1.x allows remote attackers to read and download arbitrary files via a .. (dot dot) in the name parameter.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу